The identity and technical contract details declared by the specification.
load-balancing_schemas-enabled
boolean
Whether to enable (the default) this origin within the pool. Disabled origins will not receive traffic and are excluded from health checks. The origin will onl…
access_response_collection
object
addressing_modified_at_nullable
stringnull
Last time the advertisement status was changed. This field is only not 'null' if on demand is enabled.
rulesets_RulesResponse
array
The list of rules in the ruleset.
registrar-api_contacts
object
zero-trust-gateway_filters
array
The protocol or layer to evaluate the traffic, identity, and device posture expressions.
magic-visibility_pcaps_request_simple
object
5 properties
4 required
aaa_mechanisms
object
List of IDs that will be used when dispatching a notification. IDs for email type will be the email address.
stream_clipping_created
string
The date and time the clip was created.
legacy-jhs_response_collection
access_schemas-single_response
zero-trust-gateway_ips
array
A list of CIDRs to restrict ingress connections.
tls-certificates-and-hostnames_certificateObjectPost
object
10 properties
addressing_schemas-advertised
boolean
Enablement of prefix advertisement to the Internet.
intel_url_param
object
1 property
images_image_variant_simple_response
magic-visibility_pcaps_status
string
The status of the packet capture request.
cloudforce-one_request-message-item
object
6 properties
5 required
access_seat_uid
The unique API identifier for the Zero Trust seat.
tls-certificates-and-hostnames_associationObject
object
2 properties
lists_list-response-collection
object
digital-experience-monitoring_aggregate_time_slot
object
2 properties
2 required
lists_list-delete-response-collection
object
stream_input_rtmps_url
string
The RTMPS URL you provide to the broadcaster, which they stream live video to.
registrar-api_address
string
Address.
teams-devices_manufacturer
string
The device manufacturer name.
zero-trust-gateway_subcategory
object
5 properties
dns_dns_analytics_api_data
array
Array with one row per combination of dimension values.
dns-custom-nameservers_messages
array
workers_max_wait_time_ms
number
workers_placement_config
object
1 property
zero-trust-gateway_block-page-settings
object
Block page layout settings.
9 properties
load-balancing_expected_codes
string
The expected HTTP response code or code range of the health check. This parameter is only valid for HTTP and HTTPS monitors.
vectorize_identifier
string
Identifier
workers-kv_list_metadata
object
Arbitrary JSON that is associated with a key.
access_api-response-collection
object
rum_api-response-common
object
3 properties
3 required
workers_consumer_updated
object
6 properties
dns-custom-nameservers_ns_name
string
The FQDN of the name server.
magic-visibility_rule_identifier
load-balancing_address
string
The IP address (IPv4 or IPv6) of the origin, or its publicly addressable hostname. Hostnames entered here should resolve directly to the origin, and not be a h…
tls-certificates-and-hostnames_mtls-management_components-schemas-certificate_response_single
workers_batch_size
number
tunnel_vnet_name
string
A user-friendly name for the virtual network.
stream_listAudioTrackResponse
magic-transit_target_summary
object
Aggregated statistics from all hops about the target.
load-balancing_method
string
The method to use for the health check. This defaults to 'GET' for HTTP/HTTPS based checks and 'connectionestablished' for TCP based health checks.
magic-transit_options
object
5 properties
stream_downloadedFrom
string
The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null.
magic-transit_api-response-collection
object
tls-certificates-and-hostnames_schemas-issuer
string
The certificate authority that issued the certificate.
magic-visibility_mnm_config_default_sampling
number
Fallback sampling rate of flow messages being sent in packets per second. This should match the packet sampling rate configured on the router.
tunnel_per_page
number
Number of results to display.
aaa_components-schemas-type
string
Type of webhook endpoint.
zero-trust-gateway_app-types_components-schemas-response_collection
teams-devices_api-response-collection-common
object
access_components-schemas-response_collection
registrar-api_domain_name
string
Domain name.
intel_id
integer
The unique identifier for the indicator feed
workers_namespace_identifier
string
Namespace identifier tag.
bill-subs-api_state
string
The state that the subscription is in.
intel_identifier
string
Identifier
legacy-jhs_cidr_configuration
object
2 properties
images_images_stats_response
workers-kv_api-response-collection
object
teams-devices_device-dex-test-schemas-name
string
The name of the DEX test. Must be unique.
magic_interface_address
string
A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–1…
load-balancing_monitor-response-single
stream_input
object
2 properties
teams-devices_split_tunnel_include_response_collection
cloudforce-one_request-type
string
Requested information from request
registrar-api_domain_properties
object
12 properties
access_users_components-schemas-response_collection
images_image_variant_response
object
1 property
tunnel_remote_config
boolean
If true, the tunnel can be configured remotely from the Zero Trust dashboard. If false, the tunnel must be configured locally on the origin machine.
cloudforce-one_request-edit
object
5 properties
stream_start_time_seconds
integer
Specifies the start time for the video clip in seconds.
load-balancing_minimum_origins
integer
The minimum number of origins that must be healthy for this pool to serve traffic. If the number of healthy origins falls below this number, the pool will be m…
workers_r2_binding
object
3 properties
3 required
workers_dispatch_namespace_name
string
Name of the Workers for Platforms dispatch namespace.
teams-devices_id_response
magic_multiple_route_delete_response
load-balancing_schemas-single_response
dlp_create_custom_profiles
object
1 property
1 required
dlp_api-response-common-failure
object
4 properties
4 required
teams-devices_created
string
When the device was created.
images_image_variant_patch_request
object
2 properties
1 required
dns_dns_analytics_api_sort
string
A comma-separated list of dimensions to sort by, where each dimension may be prefixed by - (descending) or + (ascending).
workers-kv_api-response-common-failure
object
4 properties
4 required
access_allowed_methods
array
Allowed HTTP request methods.
load-balancing_type
string
The protocol to use for the health check. Currently supported protocols are 'HTTP','HTTPS', 'TCP', 'ICMP-PING', 'UDP-ICMP', and 'SMTP'.
teams-devices_os_distro_revision
string
The Linux distro revision.
intel_whois
object
9 properties
stream_captions
object
2 properties
workers_identifier
string
Identifier
turnstile_clearance_level
string
If Turnstile is embedded on a Cloudflare site and the widget should grant challenge clearance, this setting can determine the clearance level to be set
images_image_keys_response
object
1 property
teams-devices_split_tunnel
object
3 properties
2 required
email_verified
string
The date and time the destination address has been verified. Null means not verified yet.
access_ip_rule
object
Matches an IP address block.
1 property
1 required
teams-devices_api-response-collection
object
stream_end_time_seconds
integer
Specifies the end time for the video clip in seconds.
stream_watermark_basic_upload
object
6 properties
1 required
images_image_variant_options
object
Allows you to define image resizing sizes for different use cases.
4 properties
4 required
tls-certificates-and-hostnames_ca
boolean
Indicates whether the certificate is a CA or leaf certificate.
dns-firewall_result_info
object
4 properties
security-center_count
integer
Total number of results
secondary-dns_messages
array
bill-subs-api_api-response-common-failure
object
4 properties
4 required
legacy-jhs_account_identifier
magic_schemas-tunnel_single_response
dns-firewall_schemas-dns-firewall
object
magic_site-name
string
The name of the site.
magic-visibility_mnm_rule_duration
string
The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values…
secondary-dns_components-schemas-single_response
email_api-response-single
object
zero-trust-gateway_provider_name
string
The name of the provider. Usually Cloudflare.
magic-visibility_pcaps_ownership_request
object
1 property
1 required
magic_acl_modified_response
teams-devices_intune_input_request
object
2 properties
2 required
addressing_ip_address
string
An IPv4 or IPv6 address.
teams-devices_auto_connect
number
The amount of time in minutes to reconnect after having been disabled.
lists_api-response-common
object
4 properties
4 required
tunnel_result_info
object
4 properties
stream_input_srt_stream_id
string
The identifier of the live input to use when streaming via SRT.
access_feature_app_props
object
6 properties
1 required
aaa_api-response-common-failure
object
4 properties
4 required
lists_operation_id
string
The unique operation ID of the asynchronous action.
tls-certificates-and-hostnames_api-response-collection
object
tls-certificates-and-hostnames_schemas-updated_at
string
This is the time the certificate was updated.
access_allow_credentials
boolean
When set to true, includes credentials (cookies, authorization headers, or TLS client certificates) with requests.
dlp_custom_profile
object
9 properties
dlp_DatasetUploadStatus
string
r2_bucket_location
string
Location of the bucket
workers_script_name
string
Name of the script, used in URLs and route configuration.
dlp_api-response-common
object
4 properties
4 required
dns-firewall_name
string
DNS Firewall Cluster Name.
magic_acl_single_response
stream_uploaded
string
The date and time the media item was uploaded.
stream_preview
string
The video's preview page URI. This field is omitted until encoding is complete.
load-balancing_weight
number
The weight of this origin relative to other origins in the pool. Based on the configured weight the total traffic is distributed among origins within the pool.…
load-balancing_schemas-preview_id
stream_playback_rtmps_url
string
The URL used to play live video over RTMPS.
stream_live_input_created
string
The date and time the live input was created.
digital-experience-monitoring_fleet_status_devices_response
images_image_filename
string
Image file name.
magic-visibility_api-response-common-failure
object
4 properties
4 required
turnstile_region
string
Region where this widget can be used.
access_bookmark_props
object
6 properties
addressing_single_response_bgp
custom-pages_api-response-collection
object
access_organizations
object
13 properties
intel_url_id_param
object
1 property
magic-visibility_pcaps_single_response
stream_created
string
The date and time the media item was created.
teams-devices_sentinelone_input_request
object
4 properties
2 required
workers_schemas-service
string
Worker service associated with the zone and hostname.
zero-trust-gateway_categories_components-schemas-name
string
The name of the category.
stream_end
string
Lists videos created before the specified date.
bill-subs-api_currency
string
The monetary unit in which pricing information is displayed.
stream_webhook_response_single
zero-trust-gateway_schemas-uuid
access_basic_app_response_props
object
4 properties
iam_components-schemas-account
images_image_variants
array
Object specifying available variants for an image.
lists_operation
object
4 properties
2 required
stream_thumbnail_url
string
The media item's thumbnail URI. This field is omitted until encoding is complete.
aaa_last_failure
string
Timestamp of the last time an attempt to dispatch a notification to this webhook failed.
stream_input_webrtc
object
Details for streaming to a live input using WebRTC.
1 property
request-tracer_api-response-common
object
4 properties
4 required
stream_language_response_collection
dns_dns_analytics_api_report_bytime
cloudforce-one_messages
array
dlp_predefined_profile_response
stream_caption_basic_upload
object
1 property
1 required
aaa_history_components-schemas-response_collection
stream_live_input_modified
string
The date and time the live input was last modified.
workers_api-response-single
object
registrar-api_telephone
stringnull
User's telephone number
access_string_key_map_device_session
object
zero-trust-gateway_schemas-identifier
string
Identifier
images_image_original_url
string
URI to original variant for an image.
load-balancing_consecutive_down
integer
To be marked unhealthy the monitored origin must fail this healthcheck N consecutive times.
access_components-schemas-session_duration
string
The amount of time that tokens issued for the application will be valid. Must be in the format 300ms or 2h45m. Valid time units are: ns, us (or µs), ms, s, m,…
vectorize_api-response-single
object
magic_cidr
string
A valid CIDR notation representing an IP range.
aaa_integration-token
string
The token integration key
intel_resolves_to_refs
array
Specifies a list of references to one or more IP addresses or domain names that the domain name currently resolves to.
hyperdrive_messages
array
workers_script_identifier
string
hyperdrive_hyperdrive-name
string
workers_cursor
string
Opaque token indicating the position from which to continue when requesting the next set of records. A valid value for the cursor can be obtained from the curs…
digital-experience-monitoring_test_stat_over_time
object
4 properties
1 required
logpush_name
stringnull
Optional human readable job name. Not unique. Cloudflare suggests that you set this to a meaningful string, like the domain name, to make it easier to identify…
workers_script-response
object
9 properties
stream_watermark_at_upload
object
1 property
logpush_logpull_options
stringnull
This field is deprecated. Use outputoptions instead. Configuration string. It specifies things like requested fields and timestamp formats. If migrating from t…
teams-devices_device-managed-networks
object
4 properties
teams-devices_firewall_input_request
object
2 properties
2 required
iam_api-response-common
object
4 properties
4 required
aaa_result_info
object
4 properties
addressing_address-maps
object
8 properties
load-balancing_api-response-common
object
4 properties
4 required
images_image_direct_upload_response_v2
secondary-dns_ip
string
IPv4/IPv6 address of primary or secondary nameserver, depending on what zone this peer is linked to. For primary zones this IP defines the IP of the secondary…
iam_single_member_response_with_code
load-balancing_monitor_id
The ID of the Monitor to use for checking the health of origins within this pool.
tunnel_metadata
object
Metadata associated with the tunnel.
magic-transit_colo
object
2 properties
magic_customer_gre_endpoint
string
The IP address assigned to the customer side of the GRE tunnel.
digital-experience-monitoring_status
string
Network status
access_ip
string
The IP address of the authenticating user.
magic_ipsec-tunnel
object
12 properties
3 required
email_destination_addresses_response_collection
load-balancing_timestamp
string
addressing_default_sni
stringnull
If you have legacy TLS clients which do not send the TLS server name indicator, then you can specify one default SNI on the map. If Cloudflare receives a TLS h…
access_ray_id
string
The unique identifier for the request to Cloudflare.
teams-devices_sentinelone_s2s_input_request
object
6 properties
1 required
teams-devices_description
string
The description of the device posture rule.
access_skip_interstitial
boolean
Enables automatic authentication through cloudflared.
magic_api-response-common-failure
object
4 properties
4 required
load-balancing_references_response
access_response_collection_hostnames
logpush_validate_response
magic_schemas-modified_on
string
The date and time the tunnel was last modified.
teams-devices_allow_updates
boolean
Whether to receive update notifications when a new version of the client is available.
registrar-api_first_name
stringnull
User's first name
access_api-response-single
object
workers_usage-model-response
r2_sippy
object
3 properties
stream_api-response-common
object
4 properties
4 required
secondary-dns_schemas-single_response
secondary-dns_account_identifier
access_external_evaluation_rule
object
Create Allow or Block policies which evaluate the user based on custom criteria.
1 property
1 required
workers_deployments-list-response
magic_wan_single_response
access_allowed_origins
array
Allowed origins.
registrar-api_city
string
City.
magic_priority
integer
Priority of the static route.
access_authentication_method_rule
object
Enforce different MFA options
1 property
1 required
zero-trust-gateway_schemas-single_response
registrar-api_registrant_contact
Shows contact information for domain registrant.
addressing_response_collection_bgp
aaa_components-schemas-description
string
Description of the notification policy (if present).
teams-devices_switch_locked
boolean
Whether to allow the user to turn off the WARP switch and disconnect the client.
zero-trust-gateway_action
string
The action to preform when the associated traffic, identity, and device posture expressions are either absent or evaluate to true.
turnstile_bot_fight_mode
boolean
If botfightmode is set to true, Cloudflare issues computationally expensive challenges in response to malicious bots (ENT only).
zero-trust-gateway_uuid
string
API Resource UUID tag.
secondary-dns_components-schemas-identifier
aaa_token
string
token in form of UUID
access_schemas-require
array
Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.
workers_queue
object
8 properties
teams-devices_zero-trust-account-device-settings
object
4 properties
magic-visibility_pcaps_response_full
object
11 properties
zero-trust-gateway_api-response-common
object
4 properties
4 required
zero-trust-gateway_locations
object
9 properties
pages_identifier
string
Identifier
addressing_identifier
string
Identifier
request-tracer_messages
array
magic_vlan_tag
integer
VLAN port number.
magic-transit_traceroute_response_collection
addressing_schemas-can_delete
boolean
Controls whether the membership can be deleted via the API or not.
rum_create-site-request
object
3 properties
load-balancing_resource_reference
object
A reference to a load balancer resource.
5 properties
teams-devices_revoke_devices_request
array
A list of device ids to revoke.
aaa_schemas-name
string
Name of the policy.
magic_multiple_route_modified_response
access_identity-provider
object
5 properties
3 required
tunnel_tunnel_name
string
A user-friendly name for the tunnel.
magic-visibility_pcaps_submitted
string
The RFC 3339 timestamp when the packet capture was created.
zero-trust-gateway_gateway-account-settings
object
account settings.
1 property
zero-trust-gateway_browser-isolation-settings
object
Browser isolation settings.
2 properties
access_schemas-auto_redirect_to_identity
boolean
When set to true, users skip the identity provider selection step during login. You must specify only one identity provider in allowedidps.
magic-transit_packets_ttl
integer
The time to live (TTL).
magic_sites_collection_response
zero-trust-gateway_schedule
object
The schedule for activating DNS policies. This does not apply to HTTP or network policies.
8 properties
teams-devices_single_response
images_signing_key_identifier
teams-devices_support_url
string
The URL to launch when the Send Feedback button is clicked.
intel_api-response-common
object
4 properties
4 required
magic_created_on
string
When the route was created.
pages_api-response-single
object
teams-devices_components-schemas-name
string
The name of the device posture integration.
access_failed_login_response
images_api-response-common-failure
object
4 properties
4 required
workers_api-response-collection
object
stream_oneTimeUploadExpiry
string
The date and time when the video upload URL is no longer valid for direct user uploads.
magic_schemas-tunnels_collection_response
pages_api-response-common-failure
object
4 properties
4 required
cloudforce-one_request-readable-id
string
Readable Request ID
logpush_ownership_challenge
string
Ownership challenge token to prove destination ownership.
secondary-dns_components-schemas-name
string
The name of the peer.
tunnel_vnet_response_single
zero-trust-gateway_components-schemas-name
string
The name of the rule.
rum_identifier
string
Identifier
teams-devices_device-dex-test-schemas-data
object
The configuration object which contains the details for the WARP client to conduct the test.
3 properties
images_image_variant_neverRequireSignedURLs
boolean
Indicates whether the variant can access an image without a signature, regardless of image access control.
load-balancing_preview_result
object
Resulting health data from a preview operation.
access_access-requests
object
9 properties
lists_modified_on
string
The RFC 3339 timestamp of when the list was last modified.
zero-trust-gateway_enabled_upload_phase
boolean
Enable anti-virus scanning on uploads.
tunnel_api-response-common
object
4 properties
4 required
rum_rule-id-response-single
images_api-response-collection-v2
object
bill-subs-api_result_info
object
4 properties
stream_video_response_collection
access_policies_components-schemas-name
string
The name of the Access policy.
images_image_variant_schemas_metadata
string
What EXIF data should be preserved in the output image.
cloudforce-one_priority-list
object
2 properties
2 required
magic-visibility_pcaps_ownership_single_response
stream_media_metadata
object
A user modifiable key-value store used to reference other systems of record for managing videos.
access_components-schemas-single_response
workers_account-settings-response
access_schemas-domain
string
The domain of the Bookmark application.
aaa_policies
object
9 properties
legacy-jhs_api-response-single-id
object
vectorize_index-delete-vectors-by-id-response
object
2 properties
zero-trust-gateway_settings
object
4 properties
digital-experience-monitoring_aggregate_time_period
object
2 properties
2 required
intel_description
string
The description of the example test
security-center_issueClasses
array
tunnel_existed_at
string
If provided, include only tunnels that were created (and not deleted) before this time.
dns-custom-nameservers_api-response-single
object
lists_item_comment
string
An informative summary of the list item.
stream_signing_key_created
string
The date and time a signing key was created.
load-balancing_latitude
number
The latitude of the data center containing the origins used in this pool in decimal degrees. If this is set, longitude must also be set.
zero-trust-gateway_notification_settings
object
Configure a message to display on the user's device when an antivirus search is performed.
3 properties
teams-devices_schemas-config_response
object
The configuration object containing information for the WARP client to detect the managed network.
magic_schemas-tunnel_modified_response
zero-trust-gateway_anti-virus-settings
object
Anti-virus settings.
4 properties
tunnel_connection_id
string
UUID of the Cloudflare Tunnel connection.
turnstile_modified_on
string
When the widget was modified.
dns_dns_analytics_api_result
object
7 properties
7 required
access_tags_components-schemas-name
string
The name of the tag
access_action
string
The event that occurred, such as a login attempt.
dns-firewall_dns_firewall_response_collection
intel_permissions_response
dlp_V4Response
object
4 properties
3 required
access_aud
string
The Application Audience (AUD) tag. Identifies the application associated with the CA.
stream_playback_srt
object
Details for playback from an live input using SRT.
3 properties
custom-pages_api-response-common
object
4 properties
4 required
access_certificate_rule
object
Matches any valid client certificate.
1 property
1 required
workers_result_info
object
4 properties
d1_create-database-response
object
4 properties
magic-transit_max_ttl
integer
Max TTL.
hyperdrive_hyperdrive-origin
object
5 properties
5 required
dns_dns_analytics_api_report
hyperdrive_create-update-hyperdrive-config
object
1 property
2 required
dlp_V4ResponsePagination
object
4 properties
4 required
magic-transit_std_dev_rtt_ms
number
Standard deviation of the RTTs in ms.
dns_dns_analytics_api_metrics
string
A comma-separated list of metrics to query.
dns-firewall_api-response-common
object
4 properties
4 required
load-balancing_monitor-response-collection
load-balancing_path
string
The endpoint path you want to conduct a health check against. This parameter is only valid for HTTP and HTTPS monitors.
security-center_severityQueryParam
array
teams-devices_schemas-match
string
The wirefilter expression to match devices.
magic-visibility_pcaps_id
string
The ID for the packet capture.
stream_key_generation_response
zero-trust-gateway_list_item_response_collection
workers-kv_bulk_write
array
2 required
intel_permissions_update
object
1 property
teams-devices_email
string
The contact email address of the user.
teams-devices_captive_portal
number
Turn on the captive portal after the specified amount of time.
access_ca_components-schemas-single_response
workers_deployments-single-response
teams-devices_result_info
object
4 properties
zero-trust-gateway_app-types_components-schemas-name
string
The name of the application or application type.
dns-custom-nameservers_availability_response
calls_app_response_collection
access_tag
object
A tag
4 properties
1 required
addressing_provisioning
object
Status of a Service Binding's deployment to the Cloudflare network
1 property
magic-visibility_messages
array
workers_renamed_name
string
intel_api-response-single
object
digital-experience-monitoring_unique_devices_response
object
1 property
1 required
pages_domain_name
string
Name of the domain.
legacy-jhs_api-response-collection
object
lists_item_id
string
The unique ID of the item in the List.
magic_lans_collection_response
intel_indicator_feed_response
stream_watermark_size
number
The size of the image in bytes.
digital-experience-monitoring_account_identifier
string
cloudforce-one_api-response-common
object
4 properties
4 required
stream_requireSignedURLs
boolean
Indicates whether the video can be a accessed using the UID. When set to true, a signed token must be generated with a signing key to view the video.
workers-kv_key_name
string
A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL.
tunnel_legacy-tunnel-response-single
stream_upload_metadata
string
Comma-separated key-value pairs following the TUS protocol specification. Values are Base-64 encoded. Supported keys: name, requiresignedurls, allowedorigins,…
legacy-jhs_schemas-mode
string
The action to apply to a matched request.
intel_components-schemas-response
teams-devices_match
array
The conditions that the client must match to run the rule.
bill-subs-api_name
string
The domain name
access_is_ui_read_only
boolean
Lock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled.
stream_maxDurationSeconds
integer
The maximum duration in seconds for a video upload. Can be set for a video that is not yet uploaded to limit its duration. Uploads that exceed the specified du…
r2_enable_sippy_aws
object
2 properties
zero-trust-gateway_audit_ssh_settings_components-schemas-uuid
string
Seed ID
zero-trust-gateway_proxy-endpoints_components-schemas-name
string
The name of the proxy endpoint.
workers_pipeline_hash
string
Deprecated. Deployment metadata for internal usage.
access_active_device_count
number
The number of active devices registered to the user.
magic-visibility_mnm_config
object
3 properties
3 required
teams-devices_intune_config_request
object
3 properties
3 required
calls_app_with_secret
object
5 properties
magic-transit_packets_per_ttl
integer
Number of packets sent at each TTL.
stream_modified
string
The date and time the media item was last modified.
security-center_issueClass
string
access_policies_components-schemas-response_collection
logpush_api-response-common
object
4 properties
4 required
teams-devices_components-schemas-response_collection
workers_zone_name
string
Name of the zone.
magic-transit_targets
array
access_geo
object
1 property
digital-experience-monitoring_version
string
WARP client version
magic_route_deleted_response
tunnel_icmp_proxy_enabled
boolean
A flag to enable the ICMP proxy for the account network.
tls-certificates-and-hostnames_mtls-management_components-schemas-expires_on
string
When the certificate expires.
tunnel_api-response-common-failure
object
4 properties
4 required
iam_api-response-single-id
object
teams-devices_checkDisks
array
List of volume names to be checked for encryption.
calls_api-response-common
object
4 properties
4 required
registrar-api_domains
object
access_associated_hostnames
array
The hostnames of the applications that will use this certificate.
zero-trust-gateway_identity
string
The wirefilter expression used for identity matching.
tunnel_run_at
string
Timestamp of when the tunnel connection was started.
zero-trust-gateway_components-schemas-description
string
A short summary of domains in the category.
registrar-api_can_register
boolean
Indicates if the domain can be registered as a new domain.
rulesets_Rule
object
11 properties
2 required
logpush_identifier
string
Identifier
teams-devices_allowed_to_leave
boolean
Whether to allow devices to leave the organization.
images_image_uploaded
string
When the media item was uploaded.
access_http_only_cookie_attribute
boolean
Enables the HttpOnly cookie attribute, which increases security against XSS attacks.
zero-trust-gateway_dns_resolver_settings
object
4 properties
1 required
custom-pages_api-response-common-failure
object
4 properties
4 required
tls-certificates-and-hostnames_certificate_response_single_post
calls_api-response-common-failure
object
4 properties
4 required
access_self_hosted_props
object
22 properties
2 required
load-balancing_search
object
1 property
cloudforce-one_priority
string
load-balancing_preview_response
lists_list_id
string
The unique ID of the list.
teams-devices_os_version
string
The operating system version.
lists_num_items
number
The number of items in the list.
registrar-api_updated_at
string
Last updated.
digital-experience-monitoring_result_info
object
4 properties
iam_create
object
3 properties
2 required
magic_tunnel_deleted_response
tunnel_route
object
7 properties
legacy-jhs_rule
object
7 properties
4 required
zero-trust-gateway_schemas-response_collection
rulesets_CreateRulesetRequest
vectorize_index-description
string
Specifies the description of the index.
addressing_description
string
Description of the prefix.
intel_additional_information
object
Additional information related to the host name.
1 property
tunnel_schemas-comment
string
Optional remark describing the virtual network.
tunnel_schemas-connection
object
8 properties
zero-trust-gateway_proxy-endpoints_components-schemas-single_response
stream_watermark_created
string
The date and a time a watermark profile was created.
workers_placement_mode
string
Specifies the placement mode for the Worker (e.g. 'smart').
intel_create_feed_response
tunnel_is_default_network
boolean
If true, this virtual network is the default for the account.
intel_categories_with_super_category_ids_example_empty
array
d1_file-size
number
The D1 database's size, in bytes.
dns-custom-nameservers_schemas-identifier
string
Identifier
magic_schemas-tunnel_update_request
magic_sites_add_single_request
object
1 property
stream_identifier
string
A Cloudflare-generated unique identifier for a media item.
workers-kv_namespace
object
3 properties
2 required
magic_tunnel_add_single_request
object
8 properties
4 required
magic-visibility_pcaps_packet_limit
number
The limit of packets contained in a packet capture.
tunnel_colo_name
string
The Cloudflare data center used for this connection.
stream_update_output_request
object
1 property
1 required
turnstile_secret
string
Secret key for this widget.
access_settings
object
3 properties
3 required
dlp_shared_entry_update_predefined
object
Properties of a predefined entry in a custom profile
2 properties
addressing_schemas-ips
array
The set of IPs on the Address Map.
aaa_sent
string
Timestamp of when the notification was dispatched in ISO 8601 format.
access_ip_list_rule
object
Matches an IP address from a list.
1 property
1 required
teams-devices_ip
string
IPv4 or IPv6 address.
dlp_DatasetUpdate
object
2 properties
teams-devices_device-dex-test-schemas-description
string
Additional details about the test.
rum_auto_install
boolean
If enabled, the JavaScript snippet is automatically injected for orange-clouded sites.
tls-certificates-and-hostnames_api-response-common
object
4 properties
4 required
email_destination_address_properties
object
6 properties
access_tags_components-schemas-single_response
legacy-jhs_result_info
object
4 properties
security-center_api-response-common-failure
object
4 properties
4 required
rulesets_Response
object
A response object.
4 properties
4 required
access_identity-providers
load-balancing_identifier
string
zero-trust-gateway_audit_ssh_settings_components-schemas-single_response
stream_type
string
Specifies whether the video is vod or live.
pages_deployment-new-deployment
teams-devices_domain_joined_input_request
object
2 properties
1 required
access_schemas-exclude
array
Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.
registrar-api_current_registrar
string
Shows name of current registrar.
teams-devices_workspace_one_input_request
object
2 properties
2 required
magic-visibility_pcaps_type
string
The type of packet capture. Simple captures sampled packets, and full captures entire payloads and non-sampled packets.
stream_playback
object
2 properties
load-balancing_components-schemas-identifier
string
Identifier
custom-pages_messages
array
zero-trust-gateway_rule-settings
object
Additional settings that modify the rule's action.
20 properties
stream_live_input_recording_deletion
number
Indicates the number of days after which the live inputs recordings will be deleted. When a stream completes and the recording is ready, the value is used to c…
dns-firewall_api-response-common-failure
object
4 properties
4 required
rum_modify-rules-request
object
2 properties
load-balancing_filter_options
objectnull
Filter options for a particular resource type (pool or origin). Use null to reset.
2 properties
logpush_last_error
stringnull
Records the last time the job failed. If not null, the job is currently failing. If null, the job has either never failed or has run successfully at least once…
teams-devices_disk_encryption_input_request
object
2 properties
teams-devices_crowdstrike_config_request
object
4 properties
4 required
intel_indicator_feed_metadata
object
6 properties
teams-devices_type
string
The type of device posture rule.
load-balancing_interval
integer
The interval between each health check. Shorter intervals may improve failover time, but will increase load on the origins as we check from multiple locations.
magic-transit_target
string
The target hostname, IPv6, or IPv6 address.
calls_app_editable_fields
object
1 property
access_email
string
The email address of the authenticating user.
zero-trust-gateway_type
string
The type of list.
cloudforce-one_priority-item
object
7 properties
7 required
iam_role_components-schemas-identifier
string
Role identifier tag.
pages_domain-response-collection
teams-devices_device_response
pages_domain-response-single
rum_zone_tag
string
The zone identifier.
teams-devices_device_settings_response
pages_stage
object
The status of the deployment.
4 properties
stream_storage_use_response
stream_name
string
A short description of the watermark profile.
intel_phishing-url-info_components-schemas-single_response
access_seats_components-schemas-response_collection
zero-trust-gateway_network
object
1 property
1 required
magic-transit_mean_rtt_ms
number
Mean RTT in ms.
workers_queue_updated
object
4 properties
zero-trust-gateway_application_type
object
4 properties
magic_gre-tunnel
object
11 properties
4 required
addressing_create_binding_request
object
2 properties
magic-visibility_api-response-single
object
magic_customer_ipsec_endpoint
string
The IP address assigned to the customer side of the IPsec tunnel.
access_schemas-app_launcher_visible
boolean
Displays the application in the App Launcher.
vectorize_index-query-response
object
2 properties
tunnel_config_response_single
tunnel_tunnel_secret
string
Sets the password required to run a locally-managed tunnel. Must be at least 32 bytes and encoded as a base64 string.
digital-experience-monitoring_per_page
number
Number of items per page
iam_account
object
4 properties
2 required
tls-certificates-and-hostnames_components-schemas-certificateObject
object
9 properties
dns-firewall_identifier
string
Identifier
stream_liveInput
string
The live input ID used to upload a video with Stream Live.
access_okta_group_rule
object
Matches an Okta group. Requires an Okta identity provider.
1 property
1 required
zero-trust-gateway_enabled
boolean
True if the rule is enabled.
turnstile_result_info
object
4 properties
4 required
secondary-dns_response_collection
tunnel_tunnel_response_token
stream_scale
number
The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. 0.0 indicates no sc…
vectorize_api-response-common-failure
object
4 properties
4 required
access_policies_components-schemas-single_response
dns-firewall_deprecate_any_requests
boolean
Deprecate the response to ANY requests.
logpush_get_ownership_response
intel_inherited_from
string
Domain from which inheritedcontentcategories and inheritedrisktypes are inherited, if applicable.
digital-experience-monitoring_personEmail
string
User contact email address
bill-subs-api_api-response-common
object
4 properties
4 required
workers_etag
string
Hashed script content, can be used in a If-None-Match header when updating.
addressing_api-response-single
object
magic-transit_colo_name
string
Source colo name.
dns-firewall_attack_mitigation
objectnull
Attack mitigation settings.
3 properties
teams-devices_device-dex-test-schemas-http
object
5 properties
4 required
teams-devices_client_certificate_input_request
object
2 properties
2 required
zero-trust-gateway_lists
object
7 properties
tunnel_connection
object
3 properties
lists_api-response-common-failure
object
4 properties
4 required
addressing_service_binding
object
5 properties
lists_kind
The type of the list. Each type supports specific list items (IP addresses, ASNs, hostnames or redirects).
workers_queue_created
object
4 properties
hyperdrive_api-response-common
object
4 properties
4 required
tunnel_offramp_warp_enabled
boolean
A flag to enable WARP to WARP traffic.
addressing_ipam-bgp-prefixes
object
7 properties
intel_content_categories
Current content categories.
aaa_pagerduty
object
2 properties
images_image_patch_request
object
2 properties
access_type
string
The application type.
dlp_DatasetCreationResponse
registrar-api_state
string
State.
security-center_issueType
string
teams-devices_devices_response
magic-visibility_pcaps_collection_response
magic_name
string
The name of the tunnel. The name cannot contain spaces or special characters, must be 15 characters or less, and cannot share a name with another GRE tunnel.
aaa_api-response-collection
object
stream_input_rtmps
object
Details for streaming to an live input using RTMPS.
2 properties
intel_ip-list
object
3 properties
teams-devices_input
object
The value to be checked against.
digital-experience-monitoring_device
object
7 properties
7 required
access_apps_components-schemas-response_collection
access_saml_group_rule
object
Matches a SAML group. Requires a SAML identity provider.
1 property
1 required
teams-devices_dex-single_response
workers_mtls_cert_binding
object
3 properties
3 required
dns_dns_analytics_api_since
string
Start date and time of requesting data period in ISO 8601 format.
r2_bucket_name
string
Name of the bucket
magic_components-schemas-name
string
The name of the interconnect. The name cannot share a name with other tunnels.
tunnel_config
object
The tunnel configuration and ingress rules.
3 properties
teams-devices_carbonblack_input_request
object
4 properties
2 required
aaa_api-response-single
object
email_api-response-collection
object
stream_audio_identifier
string
The unique identifier for an additional audio track.
teams-devices_schemas-id_response
legacy-jhs_api-response-common
object
4 properties
4 required
magic-visibility_mnm_rule_advertisement_single_response
rulesets_RulesetKind
string
The kind of the ruleset.
security-center_api-response-single
object
stream_start
string
Lists videos created after the specified date.
rulesets_RuleId
string
The unique ID of the rule.
logpush_error_message
stringnull
If not null, the job is currently failing. Failures are usually repetitive (example: no permissions to write to destination bucket). Only the last failure is r…
hyperdrive_patch-hyperdrive-config
object
1 property
digital-experience-monitoring_api-response-single
object
registrar-api_supported_tld
boolean
Whether a particular TLD is currently supported by Cloudflare Registrar. Refer to [TLD Policies](https://www.cloudflare.com/tld-policies/) for a list of suppor…
access_api-response-common-failure
object
4 properties
4 required
registrar-api_privacy
boolean
Privacy option controls redacting WHOIS information.
cloudforce-one_request-content
string
Request content
digital-experience-monitoring_fleet_status_live_response
load-balancing_port
integer
The port number to connect to for the health check. Required for TCP, UDP, and SMTP checks. HTTP and HTTPS checks should only define the port when using a non-…
iam_single_member_response
access_custom_non_identity_deny_url
string
The custom URL a user is redirected to when they are denied access to the application when failing non-identity rules.
access_custom-pages_components-schemas-response_collection
access_max_age
number
The maximum number of seconds the results of a preflight request can be cached.
stream_watermarkAtUpload
object
1 property
access_auto_redirect_to_identity
boolean
When set to true, users skip the identity provider selection step during login.
teams-devices_tanium_config_request
object
4 properties
2 required
access_api-response-common
object
4 properties
4 required
magic_nat
object
1 property
dns-custom-nameservers_acns_response_collection
magic_lan
object
9 properties
iam_api-response-single
object
stream_tus_resumable
string
Specifies the TUS protocol version. This value must be included in every upload request. Notes: The only supported version of TUS protocol is 1.0.0.
tls-certificates-and-hostnames_signature
string
The type of hash used for the certificate.
stream_height
integer
The height of the image in pixels.
digital-experience-monitoring_uniqueDevicesTotal
number
Number of unique devices
rulesets_RuleAction
string
The action to perform when the rule matches.
load-balancing_timeout
integer
The timeout (in seconds) before marking the health check as failed.
stream_watermarks
object
11 properties
tunnel_route_virtual_network_id
UUID of the Tunnel Virtual Network this route belongs to. If no virtual networks are configured, the route is assigned to the default virtual network of the ac…
tunnel_ip_network_encoded
string
IP/CIDR range in URL-encoded format
stream_jwk
string
The signing key in JWK format.
tunnel_api-response-collection
object
access_custom_deny_message
string
The custom error message shown to a user when they are denied access to the application.
teams-devices_schedule
string
Polling frequency for the WARP client posture check. Default: 5m (poll every five minutes). Minimum: 1m.
workers_api-response-common
object
4 properties
4 required
magic_components-schemas-tunnels_collection_response
bill-subs-api_price
number
The price of the subscription that will be billed, in US dollars.
zero-trust-gateway_name
string
The name of the list.
zero-trust-gateway_subdomain
string
The DNS over HTTPS domain to send DNS requests to. This field is auto-generated by Gateway.
vectorize_index-name
string
d1_api-response-common
object
4 properties
4 required
calls_account_identifier
string
The account identifier tag.
turnstile_name
string
Human readable widget name. Not unique. Cloudflare suggests that you set this to a meaningful string to make it easier to identify your widget, and where it is…
zero-trust-gateway_tls-settings
object
TLS interception settings.
1 property
bill-subs-api_account_subscription_response_single
rulesets_RulePosition
object
An object configuring where the rule will be placed.
bill-subs-api_current_period_end
string
The end of the current period and also when the next billing is due.
teams-devices_devices
object
20 properties
access_cors_headers
object
8 properties
custom-pages_custom_pages_response_single
magic-transit_traceroute_time_ms
integer
Total time of traceroute in ms.
workers-kv_identifier
string
Identifier
teams-devices_device_settings_policy
object
23 properties
magic-transit_port
integer
For UDP and TCP, specifies the destination port. For ICMP, specifies the initial ICMP sequence value. Default value 0 will choose the best value to use for eac…
access_gsuite_group_rule
object
Matches a group in Google Workspace. Requires a Google Workspace identity provider.
1 property
1 required
bill-subs-api_install_id
string
app install id.
secondary-dns_port
number
DNS port of primary or secondary nameserver, depending on what zone this peer is linked to.
rulesets_RulesRequest
array
The list of rules in the ruleset.
registrar-api_api-response-common
object
4 properties
4 required
dlp_create_custom_profile_response
magic_schemas-tunnel_add_single_request
object
8 properties
3 required
addressing_ip
string
An IPv4 or IPv6 address.
security-center_api-response-common
object
4 properties
4 required
dns-custom-nameservers_empty_response
addressing_cidr
string
IP Prefix in Classless Inter-Domain Routing format.
access_allow_authenticate_via_warp
boolean
When set to true, users can authenticate via WARP for any application in your organization. Application settings will take precedence over this value.
access_include
array
Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.
secondary-dns_peer
object
6 properties
2 required
hyperdrive_hyperdrive-with-identifier
object
1 property
access_schemas-id_response
teams-devices_components-schemas-type
string
The type of device managed network.
magic-visibility_pcaps_request_full
object
8 properties
5 required
load-balancing_monitor-editable
object
16 properties
teams-devices_os_version_input_request
object
6 properties
3 required
aaa_schemas-single_response
rulesets_RuleCategory
string
A category of the rule.
intel_domain
object
11 properties
intel_phishing-url-submit_components-schemas-single_response
stream_create_input_request
object
4 properties
vectorize_index-configuration
Specifies the type of configuration to use for the index.
bill-subs-api_api-response-single
object
stream_schemas-identifier
string
Identifier
stream_padding
number
The whitespace between the adjacent edges (determined by position) of the video and the image. 0.0 indicates no padding, and 1.0 indicates a fully padded video…
secondary-dns_components-schemas-id_response
zero-trust-gateway_cf_account_id
string
Cloudflare account ID.
load-balancing_id_response
access_last_successful_login
string
The time at which the user last successfully logged in.
access_device_posture_rule
object
Enforces a device posture rule has run successfully
1 property
1 required
load-balancing_components-schemas-single_response
tunnel_created_at
string
Timestamp of when the tunnel was created.
email_email
string
The contact email address of the user.
workers_compatibility_date
string
Opt your Worker into changes after this date
magic_tunnel_modified_response
dns-custom-nameservers_api-response-collection
object
dlp_integration_entry
object
An entry derived from an integration
6 properties
dns-firewall_messages
array
teams-devices_default
boolean
Whether the policy is the default policy for an account.
zero-trust-gateway_components-schemas-single_response
access_schemas-gateway_seat
boolean
True if the user has logged into the WARP client.
digital-experience-monitoring_since_minutes
number
Number of minutes before current time
workers_stepped_migrations
magic_colo_region
string
Scope colo region.
stream_live_input_recording_timeoutSeconds
integer
Determines the amount of time a live input configured in automatic mode should wait before a recording transitions from live to on-demand. 0 is recommended for…
load-balancing_api-response-single
object
magic-transit_node_result
object
9 properties
access_groups
object
8 properties
images_images_list_continuation_token
stringnull
Continuation token to fetch next page. Passed as a query param when requesting List V2 api endpoint.
tunnel_virtual-network
object
6 properties
5 required
magic_schemas-created_on
string
The date and time the tunnel was created.
zero-trust-gateway_timestamp
string
access_schemas-response_collection
legacy-jhs_email
string
The contact email address of the user.
r2_account_identifier
string
Account ID
cloudforce-one_quota
object
4 properties
dns-firewall_api-response-collection
object
security-center_dismissed
boolean
teams-devices_key
string
The device's public key.
workers_api-response-common-failure
object
4 properties
4 required
magic-transit_error
string
Errors resulting from collecting traceroute from colo to target.
access_id
string
The ID of the CA.
stream_video_copy_request
object
8 properties
1 required
aaa_created_at
string
Timestamp of when the webhook destination was created.
addressing_bgp_signal_opts
object
2 properties
magic-transit_messages
array
secondary-dns_api-response-common-failure
object
4 properties
4 required
digital-experience-monitoring_colo
string
Cloudflare colo
magic-visibility_mnm_rule_ip_prefixes
array
rum_rule
object
7 properties
workers_zone_identifier
Identifier of the zone.
logpush_dataset
stringnull
Name of the dataset.
addressing_schemas-description
stringnull
An optional description field which may be used to describe the types of IPs or zones on the map.
zero-trust-gateway_class
string
Which account types are allowed to create policies based on this category. blocked categories are blocked unconditionally for all accounts. removalPending cate…
registrar-api_api-response-common-failure
object
4 properties
4 required
teams-devices_schemas-config_request
object
The configuration object containing information for the WARP client to detect the managed network.
registrar-api_available
boolean
Shows if a domain is available for transferring into Cloudflare Registrar.
images_image_key_response_collection
magic-visibility_pcaps_destination_conf
string
The full URI for the bucket. This field only applies to full packet captures.
workers-kv_query
object
For specifying result metrics.
7 properties
access_custom_page_without_html
object
6 properties
2 required
stream_accessRules
object
Defines rules for fine-grained control over content than signed URL tokens alone. Access rules primarily make tokens conditionally valid based on user informat…
4 properties
rum_rule_identifier
string
The Web Analytics rule identifier.
iam_member
object
4 properties
4 required
teams-devices_default_device_settings_response
stream_input_rtmps_stream_key
string
The secret key to use when streaming via RTMPS to a live input.
tunnel_config_version
integer
The version of the remote tunnel configuration. Used internally to sync cloudflared with the Zero Trust dashboard.
workers-kv_messages
array
magic-transit_api-response-common-failure
object
4 properties
4 required
iam_collection_member_response
stream_output_response_single
magic_schemas-tunnel_add_request
workers-kv_expiration
number
The time, measured in number of seconds since the UNIX epoch, at which the key should expire.
magic_colo_name
string
Scope colo name.
teams-devices_last_seen
string
When the device last connected to Cloudflare services.
teams-devices_updated
string
When the device was updated.
access_any_valid_service_token_rule
object
Matches any valid Access Service Token
1 property
1 required
dns_dns_analytics_api_api-response-common-failure
object
4 properties
4 required
r2_v4_response
object
4 properties
4 required
magic_lan_single_response
access_seats
object
5 properties
addressing_result_info
object
4 properties
security-center_valueCountsResponse
intel_per_page
number
Number of results per page of results.
secondary-dns_acl_components-schemas-name
string
The name of the acl.
stream_output_identifier
string
A unique identifier for the output.
magic-visibility_pcaps_response_simple
object
7 properties
magic-transit_wait_time
integer
Set the time (in seconds) to wait for a response to a probe.
addressing_single_response
tunnel_tunnel_connections_response
teams-devices_disable_for_time
object
5 properties
zero-trust-gateway_app_type_id
integer
The identifier for the type of this application. There can be many applications with the same type. This refers to the id of a returned application type.
zero-trust-gateway_single_response
dlp_profile_id
The ID for this profile
access_active_session_response
magic-transit_result_info
object
4 properties
dlp_api-response-collection
object
magic-visibility_api-response-collection
object
digital-experience-monitoring_messages
array
turnstile_identifier
string
Identifier
cloudforce-one_request-summary
string
Brief description of the request
rulesets_RulesetId
string
The unique ID of the ruleset.
addressing_address-maps-membership
object
4 properties
hyperdrive_api-response-common-failure
object
4 properties
4 required
magic_route_update_single_request
teams-devices_uptycs_config_request
object
4 properties
4 required
teams-devices_schemas-type
string
The type of device posture integration.
workers_consumer
object
5 properties
dns_dns_analytics_api_dimensions
string
A comma-separated list of dimensions to group results by.
security-center_perPage
integer
Number of results per page of results
magic_route_modified_response
request-tracer_identifier
string
Identifier
cloudforce-one_request-item
object
13 properties
8 required
aaa_alert_type
string
Refers to which event will trigger a Notification dispatch. You can use the endpoint to get available alert types which then will give you a list of possible v…
cloudforce-one_labels
array
List of labels
teams-devices_schemas-response_collection
magic_nexthop
string
The next-hop IP Address for the static route.
tunnel_tunnel_id
string
UUID of the tunnel.
turnstile_offlabel
boolean
Do not show any Cloudflare branding on the widget (ENT only).
load-balancing_origin
object
7 properties
teams-devices_response_collection
iam_api-response-collection
object
access_service-tokens_components-schemas-name
string
The name of the service token.
workers-kv_value
string
A byte sequence to be stored, up to 25 MiB in length.
access_users
object
11 properties
addressing_bgp_on_demand
object
4 properties
intel-sinkholes_get_sinkholes_response
tunnel_route_id
string
UUID of the route.
intel-sinkholes_api-response-common
object
4 properties
4 required
teams-devices_messages
array
addressing_api-response-collection
object
aaa_audit-logs
object
10 properties
teams-devices_zero-trust-account-device-settings-response
object
load-balancing_virtual_network_id
string
The virtual network subnet ID the origin belongs in. Virtual network must also belong to the account.
magic_tunnel_single_response
access_ui_read_only_toggle_reason
string
A description of the reason why the UI read only field is being toggled.
teams-devices_application_input_request
object
4 properties
2 required
dns-firewall_dns_firewall_ips
array
load-balancing_load_shedding
object
Configures load shedding policies and percentages for the pool.
4 properties
workers_namespace
object
4 properties
rulesets_Messages
array
A list of warning messages.
dns_dns_analytics_api_messages
array
calls_modified
string
The date and time the item was last modified.
magic_modified_tunnels_collection_response
magic_wan_static_addressing
object
(optional) if omitted, use DHCP. Submit secondaryaddress when site is in high availability mode.
3 properties
2 required
workers_schemas-id
string
ID of the namespace.
teams-devices_kolide_input_request
object
3 properties
3 required
iam_description
string
Description of role's permissions.
access_login_design
object
5 properties
teams-devices_os_version_extra
string
The operating system version extra parameter.
aaa_last_success
string
Timestamp of the last time Cloudflare was able to successfully dispatch a notification using this webhook.
addressing_bgp_prefix_update_advertisement
object
1 property
logpush_logpush_job_response_collection
legacy-jhs_egs-pagination
object
2 properties
lists_num_referencing_filters
number
The number of [filters](/operations/filters-list-filters) referencing the list.
access_custom_deny_url
string
The custom URL a user is redirected to when they are denied access to the application when failing identity-based rules.
workers_migration_tag_conditions
object
2 properties
magic_site_single_response
iam_two_factor_authentication_enabled
boolean
Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication.
lists_items-update-request-collection
array
aaa_secret
string
Optional secret that will be passed in the cf-webhook-auth header when dispatching generic webhook notifications or formatted for supported destinations. Secre…
stream_errorReasonText
string
Specifies why the video failed to encode using a human readable error message in English. This field is empty if the video is not in an error state.
access_allow_all_origins
boolean
Allows all origins.
workers_namespace-delete-response
tunnel_management-resources
string
Management resources the token will have access to.
logpush_destination_exists_response
zero-trust-gateway_schemas-name
string
The name of the location.
workers-kv_cursor
string
Opaque token indicating the position from which to continue when requesting the next set of records if the amount of list results was limited by the limit para…
access_seat
object
3 properties
3 required
dlp_entry_id
The ID for this entry
tunnel_ip_network
string
The private IPv4 or IPv6 range connected by the route, in CIDR notation.
workers_binding
object
A binding to allow the Worker to communicate with resources
pages_deployment_configs
object
Configs for deployments in a project.
2 properties
access_ca
object
3 properties
magic_wans_collection_response
workers-kv_schemas-result
lists_item-response-collection
zero-trust-gateway_client-default
boolean
True if the location is the default location.
stream_thumbnailTimestampPct
number
The timestamp for a thumbnail image calculated as a percentage value of the video's duration. To convert from a second-wise timestamp to a percentage, divide t…
rulesets_UpdateRulesetRequest
r2_result_info
object
2 properties
teams-devices_exclude
array
teams-devices_api-response-common
object
4 properties
4 required
dlp_custom_entry
object
A custom entry that matches a profile
7 properties
lists_lists-response-collection
object
logcontrol_identifier
string
Identifier
registrar-api_domain_response_single
registrar-api_messages
array
stream_playback_srt_stream_passphrase
string
The secret key to use for playback via SRT.
access_schemas-identifier
tls-certificates-and-hostnames_messages
array
registrar-api_domain_identifier
string
Domain identifier.
zero-trust-gateway_gateway_tag
string
Gateway internal ID.
lists_bulk-operation-response-collection
aaa_history
object
9 properties
access_connection
string
The IdP used to authenticate.
dns-firewall_ratelimit
numbernull
Ratelimit in queries per second per datacenter (applies to DNS queries sent to the upstream nameservers configured on the cluster).
workers_service_binding
object
4 properties
4 required
magic-visibility_mnm_rule_ip_prefix
string
The IP prefixes that are monitored for this rule. Must be a CIDR range like 203.0.113.0/24. Max 5000 different CIDR ranges.
stream_input_webrtc_url
string
The WebRTC URL you provide to the broadcaster, which they stream live video to.
magic-visibility_pcaps_byte_limit
number
The maximum number of bytes to capture. This field only applies to full packet captures.
rum_sites-response-collection
digital-experience-monitoring_api-response-common
object
4 properties
4 required
zero-trust-gateway_custom-certificate-settings
object
Custom certificate settings for BYO-PKI.
4 properties
1 required
magic-transit_name
string
Host name of the address, this may be the same as the IP address.
access_schemas-custom_pages
array
The custom pages that will be displayed when applicable for this application
calls_app
object
4 properties
dns-firewall_dns-firewall
object
14 properties
9 required
zero-trust-gateway_api-response-single
object
tunnel_warp_connector_tunnel
object
A Warp Connector Tunnel that connects your origin to Cloudflare's edge.
11 properties
tunnel_identifier
string
Identifier
magic-visibility_mnm_rule_automatic_advertisement
booleannull
Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available…
dlp_identifier
string
Identifier
magic-visibility_mnm_config_router_ips
array
images_image_variants_response
object
1 property
magic-transit_api-response-common
object
4 properties
4 required
vectorize_index-preset-configuration
object
1 property
1 required
registrar-api_contact_identifier
string
Contact Identifier.
tls-certificates-and-hostnames_schemas-serial_number
string
The certificate serial number.
workers_script-response-single
access_oidc_saas_app
object
11 properties
magic_wan
object
7 properties
magic_interconnect
object
10 properties
rum_result_info
object
5 properties
zero-trust-gateway_app-types
object
magic_allow_null_cipher
boolean
When true, the tunnel can use a null-cipher (ENCRNULL) in the ESP tunnel (Phase 2).
digital-experience-monitoring_http_details_percentiles_response
object
3 properties
stream_pctComplete
string
Indicates the size of the entire upload in bytes. The value must be a non-negative integer.
access_duration
string
The duration for how long the service token will be valid. Must be in the format 300ms or 2h45m. Valid time units are: ns, us (or µs), ms, s, m, h. The default…
lists_item
object
8 properties
dlp_SkipConfig
object
Content types to exclude from context analysis and return all matches.
1 property
1 required
access_public_key
string
The public key to add to your SSH server configuration.
dlp_NewDataset
object
3 properties
1 required
stream_upload_length
integer
Indicates the size of the entire upload in bytes. The value must be a non-negative integer.
access_custom_pages
object
2 properties
dlp_update_predefined_profile
object
3 properties
registrar-api_last_name
stringnull
User's last name
registrar-api_email
string
The contact email address of the user.
stream_input_srt_stream_passphrase
string
The secret key to use when streaming via SRT to a live input.
security-center_page
integer
Current page within paginated list of results
access_bookmarks_components-schemas-name
string
The name of the Bookmark application.
load-balancing_region_code
string
A list of Cloudflare regions. WNAM: Western North America, ENAM: Eastern North America, WEU: Western Europe, EEU: Eastern Europe, NSAM: Northern South America,…
logcontrol_api-response-common
object
4 properties
4 required
zero-trust-gateway_items
array
The items in the list.
magic-transit_min_rtt_ms
number
Minimum RTT in ms.
magic-visibility_pcaps_system
string
The system used to collect packet captures.
teams-devices_kolide_config_request
object
2 properties
2 required
stream_update_input_request
object
4 properties
iam_role
object
4 properties
4 required
dlp_Dataset
object
9 properties
8 required
images_api-response-common
object
4 properties
4 required
load-balancing_schemas-description
string
A human-readable description of the pool.
tls-certificates-and-hostnames_mtls-management_components-schemas-uploaded_on
string
This is the time the certificate was uploaded.
email_result_info
object
4 properties
addressing_on_demand_enabled
boolean
Whether advertisement of the prefix to the Internet may be dynamically enabled or disabled.
workers_compatibility_flags
array
Opt your Worker into specific changes
access_self_hosted_domains
array
List of domains that Access will secure.
aaa_account-id
string
The account id
addressing_components-schemas-response_collection
registrar-api_contact_properties
object
13 properties
9 required
zero-trust-gateway_components-schemas-uuid
string
The API resource UUID.
stream_live_input_identifier
string
A unique identifier for a live input.
intel_permissions-request
object
2 properties
workers-kv_metadata
string
Arbitrary JSON to be associated with a key/value pair.
images_image_variant_width
number
Maximum width in image pixels.
magic-visibility_api-response-common
object
4 properties
4 required
tunnel_teamnet_response_collection
vectorize_index-get-vectors-by-id-response
array
Array of vectors with matching ids.
access_seats_definition
array
3 required
legacy-jhs_schemas-rule
object
5 required
lists_identifier
string
Identifier
stream_editAudioTrack
object
2 properties
intel_update_feed_response
workers_tags
array
Tags to help you manage your Workers
access_allowed_idps
array
The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.
zero-trust-gateway_extended-email-matching
object
Extended e-mail matching settings.
1 property
addressing_ipam-delegations
object
6 properties
access_schemas-name
string
The name of the identity provider, shown to users on the login page.
custom-pages_api-response-single
object
addressing_loa_document_identifier
stringnull
Identifier for the uploaded LOA document.
rum_ruleset_identifier
string
The Web Analytics ruleset identifier.
vectorize_create-index-request
object
3 properties
2 required
registrar-api_domain_response_collection
stream_media_status
object
Specifies a detailed status for a video. If the state is inprogress or error, the step field returns encoding or manifest. If the state is inprogress, pctCompl…
4 properties
tls-certificates-and-hostnames_result_info
object
4 properties
aaa_audit_logs_response_collection
magic_acls_add_single_request
object
Bidirectional ACL policy for local network traffic within a site.
1 property
addressing_bgp_signaling_enabled
boolean
Whether control of advertisement of the prefix to the Internet is enabled to be performed via BGP signal
r2_v4_response_failure
object
4 properties
4 required
magic-transit_max_rtt_ms
number
Maximum RTT in ms.
registrar-api_registry_statuses
string
A comma-separated list of registry status codes. A full list of status codes can be found at [EPP Status Codes](https://www.icann.org/resources/pages/epp-statu…
logcontrol_api-response-common-failure
object
4 properties
4 required
workers-kv_result
object
Metrics on Workers KV requests.
7 properties
7 required
bill-subs-api_rate_plan
object
The rate plan applied to the subscription.
7 properties
load-balancing_follow_redirects
boolean
Follow redirects if returned by the origin. This parameter is only valid for HTTP and HTTPS monitors.
stream_api-response-common-failure
object
4 properties
4 required
teams-devices_schemas-name
string
The device name.
access_app_launcher_visible
boolean
Displays the application in the App Launcher.
stream_playback_srt_url
string
The URL used to play live video over SRT.
magic_lan_static_addressing
object
If the site is not configured in high availability mode, this configuration is optional (if omitted, use DHCP). However, if in high availability mode, staticad…
5 properties
1 required
teams-devices_split_tunnel_include
object
3 properties
2 required
digital-experience-monitoring_timestamp
string
Timestamp in ISO format
access_auth_domain
string
The unique subdomain assigned to your Zero Trust organization.
rum_site_token
string
The Web Analytics site token.
aaa_api-response-common
object
4 properties
4 required
iam_common_components-schemas-identifier
string
Identifier
tls-certificates-and-hostnames_schemas-name
string
Optional unique name for the certificate. Only used for human readability.
cloudforce-one_time
string
secondary-dns_tsig
object
4 properties
4 required
tunnel_connections
array
The Cloudflare Tunnel connections between your origin and Cloudflare's edge.
workers_modified_on
string
When the script was last modified.
aaa_mechanism_type
string
The type of mechanism to which the notification has been dispatched. This can be email/pagerduty/webhook based on the mechanism configured.
cloudforce-one_request-message-edit
object
1 property
access_require
array
Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.
security-center_messages
array
dlp_predefined_profile
object
6 properties
load-balancing_api-response-common-failure
object
4 properties
4 required
stream_output_response_collection
load-balancing_longitude
number
The longitude of the data center containing the origins used in this pool in decimal degrees. If this is set, latitude must also be set.
magic-visibility_pcaps_ownership_response
object
6 properties
5 required
access_approval_required
boolean
Requires the user to request access from an administrator at the start of each session.
dlp_V4ResponseMessage
object
2 properties
2 required
secondary-dns_tsig_id
string
TSIG authentication will be used for zone transfer if configured.
intel_count
number
Total results returned based on your search parameters.
load-balancing_schemas-disabled_at
string
This field shows up only if the pool is disabled. This field is set with the time the pool was disabled at.
tls-certificates-and-hostnames_components-schemas-private_key
string
The private key for the certificate
access_schemas-email
string
The email of the user.
intel_components-schemas-single_response
d1_api-response-common-failure
object
4 properties
4 required
dlp_DatasetNewVersion
object
3 properties
2 required
images_api-response-single
object
addressing_components-schemas-single_response
stream_output_enabled
boolean
When enabled, live video streamed to the associated live input will be sent to the output URL. When disabled, live video will not be sent to the output URL, ev…
rum_site_tag
string
The Web Analytics site identifier.
magic_site
object
7 properties
dns-custom-nameservers_api-response-common-failure
object
4 properties
4 required
request-tracer_trace
array
bill-subs-api_component_values
array
The list of add-ons subscribed to.
teams-devices_os_distro_name
string
The Linux distro name.
access_schemas-aud
string
Audience tag.
secondary-dns_schemas-name
string
TSIG key name.
secondary-dns_single_response
magic_schemas-description
string
An optional description of the GRE tunnel.
stream_readyToStream
boolean
Indicates whether the video is playable. The field is empty if the video is not ready for viewing or the live stream is still in progress.
dlp_update_settings_response
magic_lan_update_request
object
1 property
images_image_keys
object
2 properties
images_images_stats_current
number
Cloudflare Images current usage.
bill-subs-api_api-response-collection
object
stream_watermark_response_single
access_domain_rule
object
Match an entire email domain.
1 property
1 required
images_image_thumbnail_url
string
URI to thumbnail variant for an image.
access_uid
The unique API identifier for the user.
tunnel_api-response-single
stream_direct_upload_response
rum_order_by
string
The property used to sort the list of results.
magic_wan_modified_response
aaa_webhooks_components-schemas-response_collection
rulesets_Errors
array
A list of error messages.
images_images_stats_allowed
number
Cloudflare Images allowed usage.
workers_kv_namespace_binding
object
3 properties
3 required
zero-trust-gateway_gateway_account
object
dlp_result_info
object
4 properties
legacy-jhs_ip_configuration
object
2 properties
zero-trust-gateway_device_posture
string
The wirefilter expression used for device posture check matching.
bill-subs-api_schemas-identifier
string
Subscription identifier tag.
registrar-api_api-response-single
object
load-balancing_schemas-response_collection
magic-transit_ip
string
IP address of the node.
bill-subs-api_account_subscription_response_collection
teams-devices_gateway_unique_id
string
request-tracer_api-response-common-failure
object
4 properties
4 required
digital-experience-monitoring_api-response-common-failure
object
4 properties
4 required
rum_create-rule-request
object
4 properties
magic_tunnel_update_request
stream_signed_token_response
workers-kv_result_info
object
4 properties
teams-devices_default_device_settings_policy
object
16 properties
stream_live_input_default_creator
string
Sets the creator ID asssociated with this live input.
teams-devices_workspace_one_config_response
object
The Workspace One Config Response.
3 properties
3 required
addressing_loa_upload_response
vectorize_index-upsert-response
object
2 properties
intel-sinkholes_identifier
string
Identifier
legacy-jhs_asn_configuration
object
2 properties
tunnel_client_id
string
UUID of the Cloudflare Tunnel client.
bill-subs-api_frequency
string
How often the subscription is renewed automatically.
intel_resolves_to_ref
object
2 properties
workers_uuid
string
API Resource UUID tag.
iam_membership_components-schemas-identifier
string
Membership identifier tag.
dlp_validate_pattern
object
A request to validate a pattern
1 property
1 required
intel_indicator_feed_metadata_response
load-balancing_Host
array
The 'Host' header allows to override the hostname set in the HTTP request. Current support is 1 'Host' header override per origin.
pages_deployments
object
16 properties
teams-devices_mac_address
string
The device mac address.
workers_domain-response-single
stream_playback_webrtc
object
Details for playback from a live input using WebRTC.
1 property
stream_live_input_recording_requireSignedURLs
boolean
Indicates if a video using the live input has the requireSignedURLs property set. Also enforces access controls on any video recording of the livestream with t…
images_image_variant_height
number
Maximum height in image pixels.
teams-devices_include
array
zero-trust-gateway_activity-log-settings
object
Activity log settings.
1 property
rulesets_RulesetPhase
string
The phase of the ruleset.
teams-devices_config_request
object
The configuration object containing third-party integration information.
load-balancing_preview_result_response
addressing_messages
array
intel-sinkholes_sinkhole_item
object
7 properties
addressing_service_name
string
Name of a service running on the Cloudflare network
magic-visibility_identifier
string
Identifier
addressing_advertised
booleannull
Prefix advertisement status to the Internet. This field is only not 'null' if on demand is enabled.
dns_dns_analytics_api_api-response-common
object
4 properties
4 required
access_users_components-schemas-name
string
The name of the user.
dlp_predefined_entry
object
A predefined entry that matches a profile
4 properties
secondary-dns_api-response-collection
object
tunnel_config_src
string
Indicates if this is a locally or remotely configured tunnel. If local, manage the tunnel using a YAML file on the origin machine. If cloudflare, manage the tu…
digital-experience-monitoring_aggregate_stat
object
3 properties
1 required
teams-devices_unrevoke_devices_request
array
A list of device ids to unrevoke.
logpush_output_options
objectnull
The structured replacement for logpulloptions. When including this field, the logpulloption field will be ignored.
12 properties
access_access-requests_components-schemas-response_collection
secondary-dns_api-response-common
object
4 properties
4 required
workers-kv_bulk_delete
array
stream_video_update
object
8 properties
email_created
string
The date and time the destination address has been created.
stream_watermark_response_collection
zero-trust-gateway_body-scanning-settings
object
DLP body scanning settings.
1 property
images_image_direct_upload_request_v2
object
4 properties
vectorize_api-response-common
object
4 properties
4 required
images_image_metadata
object
User modifiable key-value store. Can be used for keeping references to another system of record for managing images. Metadata must not exceed 1024 bytes.
access_tag_without_app_count
object
A tag
3 properties
1 required
teams-devices_platform
string
magic-transit_labels
array
Field appears if there is an additional annotation printed when the probe returns. Field also appears when running a GRE+ICMP traceroute to denote which tracer…
addressing_address-maps-ip
object
2 properties
zero-trust-gateway_application
object
4 properties
magic_lan_modified_response
workers-kv_namespace_identifier
string
Namespace identifier tag.
dns-firewall_upstream_ips
array
email_destination_address_response_single
access_days_until_next_rotation
number
The number of days until the next key rotation.
teams-devices_requireAll
boolean
Whether to check all disks for encryption.
tls-certificates-and-hostnames_service
string
The service using the certificate.
magic-visibility_mnm_config_router_ip
string
IPv4 CIDR of the router sourcing flow data. Only /32 addresses are currently supported.
iam_member_components-schemas-name
stringnull
Member Name.
zero-trust-gateway_beta
boolean
True if the category is in beta and subject to change.
teams-devices_tls_config_response
object
The Managed Network TLS Config Response.
2 properties
1 required
access_app_launcher_props
teams-devices_deleted
boolean
True if the device was deleted.
magic_connector-id
string
Magic WAN Connector identifier tag.
rum_site
object
7 properties
workers_namespace-script-response
object
Details about a worker uploaded to a Workers for Platforms namespace.
4 properties
images_image_variant_identifier
logpush_enabled
boolean
Flag that indicates if the job is enabled.
iam_collection_role_response
magic-transit_colos
array
If no source colo names specified, all colos will be used. China colos are unavailable for traceroutes.
tunnel_tunnel_type
string
The type of tunnel.
dlp_custom_profile_response
teams-devices_device-dex-test-schemas-interval
string
How often the test will run.
d1_database-identifier
string
magic-visibility_mnm_rule_name
string
The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (), dash (-), period (.), and tilde (~). You can’t have a space in the rule…
workers_do_binding
object
6 properties
3 required
teams-devices_schemas-uuid
string
Device ID.
vectorize_index-delete-vectors-by-id-request
object
1 property
magic-visibility_result_info
object
4 properties
dlp_integration_profile
object
7 properties
registrar-api_organization
string
Name of organization.
vectorize_index-insert-response
object
2 properties
aaa_name
string
The name of the pagerduty service.
workers-kv_api-response-common
object
4 properties
4 required
access_policies
object
15 properties
magic_schemas-tunnel_deleted_response
intel_feed_id
integer
Indicator feed ID
lists_item_redirect
object
The definition of the redirect.
7 properties
2 required
access_email_list_rule
object
Matches an email address from a list.
1 property
1 required
intel_miscategorization
object
7 properties
digital-experience-monitoring_test_stat_pct_over_time
object
4 properties
1 required
dlp_DatasetCreation
object
4 properties
3 required
vectorize_index-dimension-configuration
object
2 properties
2 required
workers_script-response-collection
access_allowed_headers
array
Allowed HTTP request headers.
legacy-jhs_ipv6_configuration
object
2 properties
stream_key_response_collection
digital-experience-monitoring_traceroute_details_percentiles_response
object
3 properties
legacy-jhs_country_configuration
object
2 properties
rulesets_RuleEnabled
boolean
Whether the rule should be executed.
dns-firewall_minimum_cache_ttl
number
Minimum DNS Cache TTL.
access_service-tokens
object
6 properties
addressing_api-response-common
object
4 properties
4 required
registrar-api_locked
boolean
Shows whether a registrar lock is in place for a domain.
stream_asc
boolean
Lists videos in ascending order of creation.
secondary-dns_result_info
object
4 properties
aaa_sensitive_id_response
aaa_enabled
boolean
Whether or not the Notification policy is enabled.
cloudforce-one_request-list-item
object
12 properties
7 required
addressing_asn
integernull
Autonomous System Number (ASN) the prefix will be advertised under.
tunnel_deleted_at
stringnull
Timestamp of when the tunnel was deleted. If null, the tunnel has not been deleted.
images_image_variant_fit
string
The fit property describes how the width and height dimensions should be interpreted.
workers_cron-trigger-response-collection
zero-trust-gateway_enabled_download_phase
boolean
Enable anti-virus scanning on downloads.
magic_acl_deleted_response
stream_live_input_response_single
stream_width
integer
The width of the image in pixels.
workers_namespace-response
object
6 properties
stream_live_input_object_without_url
object
5 properties
stream_audio_default
boolean
Denotes whether the audio track will be played by default in a player.
magic-visibility_mnm_rule_packet_threshold
number
The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum.
lists_list
object
8 properties
stream_live_input_recording_mode
string
Specifies the recording behavior for the live input. Set this value to off to prevent a recording. Set the value to automatic to begin a recording and transiti…
magic-transit_hop_result
object
4 properties
cloudforce-one_priority-edit
object
4 properties
4 required
access_components-schemas-id_response
legacy-jhs_schemas-configuration
object
The rule configuration.
access_warp_auth_session_duration
string
The amount of time that tokens issued for applications will be valid. Must be in the format 30m or 2h45m. Valid time units are: m, h.
teams-devices_lan_allow_subnet_size
number
The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset.
workers_deployment_identifier
string
zero-trust-gateway_identifier
aaa_before
string
Limit the returned results to history records older than the specified date. This must be a timestamp that conforms to RFC3339.
magic_components-schemas-tunnel_update_request
object
5 properties
secondary-dns_schemas-response_collection
teams-devices_lan_allow_minutes
number
The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a…
magic_lan_dhcp_server
object
4 properties
images_image_identifier
string
Image unique identifier.
workers_namespace-script-response-single
magic_components-schemas-description
string
An optional description forthe IPsec tunnel.
load-balancing_messages
array
rum_ruleset
object
4 properties
legacy-jhs_messages
array
zero-trust-gateway_precedence
integer
Precedence sets the order of your rules. Lower values indicate higher precedence. At each processing phase, applicable rules are evaluated in ascending order o…
registrar-api_expires_at
string
Shows when domain name registration expires.
images_images_list_response
magic_psk_generation_response
stream_playback_rtmps_stream_key
string
The secret key to use for playback via RTMPS.
dns-firewall_modified_on
string
Last modification of DNS Firewall cluster.
access_domain
string
The primary hostname and path that Access will secure. If the app is visible in the App Launcher dashboard, this is the domain that will be displayed.
stream_allowedOrigins
array
Lists the origins allowed to display the video. Enter allowed origin domains in an array and use for wildcard subdomains. Empty arrays allow the video to be vi…
dlp_update_custom_profile
object
6 properties
workers_service
string
Name of Worker to bind to
stream_readyToStreamAt
string
Indicates the time at which the video became playable. The field is empty if the video is not ready for viewing or the live stream is still in progress.
tls-certificates-and-hostnames_schemas-certificates
string
The uploaded root CA certificate.
images_image_variant_list_response
zero-trust-gateway_categories_components-schemas-response_collection
access_decision
string
The action Access will take if a user matches this policy.
logcontrol_cmb_config
objectnull
1 property
teams-devices_sentinelone_s2s_config_request
object
2 properties
2 required
load-balancing_probe_zone
string
Assign this monitor to emulate the specified zone while probing. This parameter is only valid for HTTP and HTTPS monitors.
email_destination_address_identifier
string
Destination address identifier.
cloudforce-one_message-content
string
Content of message
teams-devices_crowdstrike_input_request
object
9 properties
1 required
aaa_filters
object
Optional filters that allow you to be alerted only on a subset of events for that alert type based on some criteria. This is only available for select alert ty…
40 properties
tunnel_teamnet
object
10 properties
digital-experience-monitoring_traceroute_test_result_network_path_response
object
6 properties
3 required
access_app_domain
string
The URL of the Access application.
load-balancing_header
object
The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden. This para…
access_access_group_rule
object
Matches an Access group.
1 property
1 required
digital-experience-monitoring_colos_response
array
array of colos.
access_everyone_rule
object
Matches everyone.
1 property
1 required
iam_last_name
stringnull
User's last name
intel-sinkholes_messages
array
custom-pages_state
string
The custom page state.
intel_permission_list_item_response
intel-sinkholes_id
integer
The unique identifier for the sinkhole
tunnel_cf_account_id
string
Cloudflare account ID
access_tags
array
The tags you want assigned to an application. Tags are used to filter applications in the App Launcher dashboard.
stream_create_output_request
object
3 properties
2 required
dns-custom-nameservers_api-response-common
object
4 properties
4 required
aaa_schemas-response_collection
teams-devices_serial_number
string
The device serial number.
access_same_site_cookie_attribute
string
Sets the SameSite cookie setting, which provides increased security against CSRF attacks.
calls_app_response_single_with_secret
intel_permission_list_item
object
3 properties
digital-experience-monitoring_mode
string
The mode under which the WARP client is run
bill-subs-api_subscription
object
workers_migration_step
object
4 properties
access_is_default
boolean
Whether this is the default group
access_user_seat_expiration_inactive_time
string
The amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and…
security-center_issueTypes
array
load-balancing_patch_pools_notification_email
string
The email address to send health status notifications to. This field is now deprecated in favor of Cloudflare Notifications for Load Balancing, so only resetti…
intel_phishing-url-submit
object
3 properties
r2_bucket
object
A single R2 bucket
3 properties
iam_api-response-common-failure
object
4 properties
4 required
registrar-api_fax
string
Contact fax number.
addressing_response_collection
workers_single_step_migrations
A single set of migrations to apply.
access_approval_group
object
A group of email addresses that can approve a temporary authentication request.
3 properties
1 required
pages_deployment_configs_values
object
16 properties
d1_api-response-single
object
rulesets_RulesetsResponse
array
A list of rulesets. The returned information will not include the rules in each ruleset.
workers-kv_create_rename_namespace_body
object
1 property
1 required
rum_api-response-collection
object
hyperdrive_hyperdrive
object
3 properties
magic_health_check
object
5 properties
digital-experience-monitoring_device_id
string
Device-specific ID, given as UUID v4
registrar-api_result_info
object
4 properties
teams-devices_device_settings_response_collection
stream_video_response_single
tunnel_tunnel-response-single
tunnel_argo-tunnel
object
5 properties
4 required
digital-experience-monitoring_api-response-collection
object
access_service-tokens_components-schemas-single_response
custom-pages_identifier
string
Identifier
tunnel_vnet_id
string
UUID of the virtual network.
magic_acl
object
Bidirectional ACL policy for local network traffic within a site.
6 properties
intel_schemas-single_response
access_allow_all_methods
boolean
Allows all HTTP request methods.
magic_lans_add_single_request
object
1 property
workers_consumer_name
string
workers_consumer_created
object
6 properties
secondary-dns_secret
string
TSIG secret.
stream_position
string
The location of the image. Valid positions are: upperRight, upperLeft, lowerLeft, lowerRight, and center. Note that center ignores the padding parameter.
cloudforce-one_request-message-list
object
6 properties
2 required
workers_usage_model
string
Specifies the usage model for the Worker (e.g. 'bundled' or 'unbound').
magic_interconnect_components-schemas-description
string
An optional description of the interconnect.
zero-trust-gateway_app_id
integer
The identifier for this application. There is only one application per ID.
turnstile_sitekey
string
Widget item identifier tag.
teams-devices_device-dex-test-schemas-enabled
boolean
Determines whether or not the test is active.
load-balancing_allow_insecure
boolean
Do not validate the certificate when monitor use HTTPS. This parameter is currently only valid for HTTP and HTTPS monitors.
rulesets_Message
object
A message.
3 properties
1 required
magic-transit_packets_sent
integer
Number of packets sent with specified TTL.
access_identifier
string
Identifier
magic_route
object
9 properties
3 required
bill-subs-api_account_identifier
magic-transit_colo_result
object
5 properties
digital-experience-monitoring_page
number
Page number of paginated results
addressing_can_delete
boolean
If set to false, then the Address Map cannot be deleted via API. This is true for Cloudflare-managed maps.
zero-trust-gateway_gateway-account-logging-settings-response
object
access_last_key_rotation_at
string
The timestamp of the previous key rotation.
access_session_duration
string
The amount of time that tokens issued for applications will be valid. Must be in the format 300ms or 2h45m. Valid time units are: ns, us (or µs), ms, s, m, h.
load-balancing_search_params
object
2 properties
access_custom-pages_components-schemas-single_response
email_create_destination_address_properties
object
1 property
1 required
intel_create_feed
object
2 properties
rum_page
number
Current page within the paginated list of results.
stream_live_input_response_collection
teams-devices_api-response-common-failure
object
4 properties
4 required
workers_subdomain-response
load-balancing_check_regions
arraynull
A list of regions from which to run health checks. Null means every Cloudflare data center.
stream_copyAudioTrack
object
2 properties
1 required
access_ca_components-schemas-response_collection
magic_schemas-health_check
object
4 properties
custom-pages_url
string
The URL associated with the custom page.
zero-trust-gateway_components-schemas-response_collection
access_schemas-type
string
Custom page type.
iam_result_info
object
4 properties
dlp_DatasetUpload
object
3 properties
3 required
workers_tail_consumers_script
object
A reference to a script that will consume logs from the attached Worker.
3 properties
1 required
intel_category_with_super_category_id
object
3 properties
d1_database-version
string
intel_phishing-url-info
object
7 properties
stream_media_state
string
Specifies the processing status for all quality levels for a video.
digital-experience-monitoring_traceroute_details_response
object
6 properties
4 required
magic_lan-acl-configuration
object
4 properties
1 required
aaa_components-schemas-name
string
The name of the webhook destination. This will be included in the request body when you receive a webhook notification.
tls-certificates-and-hostnames_api-response-single
object
load-balancing_search_result
object
1 property
magic_secondary-connector-id
string
Magic WAN Connector identifier tag. Used when high availability mode is on.
images_image_upload_via_file
object
1 property
1 required
workers_id
string
Identifier for the tail.
access_allowed
boolean
The result of the authentication event.
cloudforce-one_identifier
string
Identifier
workers_script-settings-response
addressing_delegated_account_identifier
string
Account identifier for the account to which prefix is being delegated.
rulesets_RulesetVersion
string
The version of the ruleset.
calls_app_response_single
intel_schemas-ip
object
3 properties
dns_dns_analytics_api_api-response-single
object
teams-devices_api-response-single
object
images_image_hero_url
string
URI to hero variant for an image.
stream_search
string
Searches over the name key in the meta field. This field can be set with or after the upload request.
load-balancing_schemas-name
string
A human-identifiable name for the origin.
magic_components-schemas-tunnel_modified_response
dlp_get_settings_response
tls-certificates-and-hostnames_mtls-management_components-schemas-status
string
Certificate deployment status for the given service.
magic-transit_packets_lost
integer
Number of packets where no response was received.
access_fingerprint
string
The MD5 fingerprint of the certificate.
turnstile_widget_list
object
A Turnstile Widgets configuration as it appears in listings
10 properties
10 required
workers-kv_namespace_title
string
A human-readable string name for a Namespace.
load-balancing_schemas-references_response
images_images_stats
object
1 property
calls_identifier
string
A Cloudflare-generated unique identifier for a item.
tunnel_status
string
The status of the tunnel. Valid values are inactive (tunnel has never been run), degraded (tunnel is active and able to serve traffic but in an unhealthy state…
zero-trust-gateway_schemas-subdomain
string
The subdomain to be used as the destination in the proxy client.
magic_route_single_response
email_destination_address_tag
string
Destination address tag. (Deprecated, replaced by destination address identifier)
workers_binding_name
string
A JavaScript variable name for the binding.
bill-subs-api_zone
object
A simple zone object. May have null properties if not a zone subscription.
2 properties
magic_wans_add_single_request
object
1 property
images_image_requireSignedURLs
boolean
Indicates whether the image can be a accessed only using it's UID. If set to true, a signed token needs to be generated with a signing key to view the image.
registrar-api_zipcode
stringnull
The zipcode or postal code where the user lives.
pages_projects
object
11 properties
cloudforce-one_request-constants
object
3 properties
digital-experience-monitoring_tests_response
object
2 properties
2 required
load-balancing_name
string
A short name (tag) for the pool. Only alphanumeric characters, hyphens, and underscores are allowed.
access_certificates_components-schemas-name
string
The name of the certificate.
teams-devices_file_input_request
object
5 properties
2 required
addressing_delegation_identifier
string
Delegation identifier tag.
aaa_mechanism
string
The mechanism to which the notification has been dispatched.
magic_api-response-single
object
zero-trust-gateway_empty_response
registrar-api_transfer_in
object
Statuses for domain transfers into Cloudflare Registrar.
6 properties
access_bookmarks
object
7 properties
stream_keys
object
4 properties
secondary-dns_schemas-identifier
access_service_token_rule
object
Matches a specific Access Service Token
1 property
1 required
rulesets_CreateOrUpdateRuleRequest
intel_stix_identifier
string
STIX 2.1 identifier: https://docs.oasis-open.org/cti/stix/v2.1/cs02/stix-v2.1-cs02.html64yvzeku5a5c
addressing_on_demand_locked
boolean
Whether advertisement status of the prefix is locked, meaning it cannot be changed.
stream_scheduledDeletion
string
Indicates the date and time at which the video will be deleted. Omit the field to indicate no change, or include with a null value to remove an existing schedu…
access_keys_components-schemas-single_response
turnstile_mode
string
Widget Mode
addressing_kind
string
The type of the membership.
rulesets_AccountId
string
The unique ID of the account.
dns-firewall_maximum_cache_ttl
number
Maximum DNS Cache TTL.
digital-experience-monitoring_live_stat
object
2 properties
load-balancing_result_info
object
4 properties
magic_lan_dhcp_relay
object
1 property
digital-experience-monitoring_http_details_response
object
7 properties
magic_cloudflare_gre_endpoint
string
The IP address assigned to the Cloudflare side of the GRE tunnel.
access_bookmarks_components-schemas-response_collection
images_images_list_response_v2
zero-trust-gateway_protocol-detection
object
Protocol Detection settings.
1 property
dns_dns_analytics_api_query
object
7 properties
5 required
dlp_api-response-single
object
workers_max_retries
number
workers-kv_key_name_bulk
string
A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid.
aaa_alert_body
string
Message body included in the notification sent.
stream_live_input_status
stringnull
The connection status of a live input.
load-balancing_region_components-schemas-response_collection
access_precedence
integer
The order of execution for this policy. Must be unique for each policy.
magic-visibility_mnm_rules_collection_response
teams-devices_device-posture-rules
object
8 properties
dns_dns_analytics_api_until
string
End date and time of requesting data period in ISO 8601 format.
load-balancing_health_details
bill-subs-api_component_value
object
A component value for a subscription.
4 properties
iam_schemas-permissions
array
Access permissions for this User.
intel_passive-dns-by-ip
object
4 properties
images_image_response_blob
email_api-response-common
object
4 properties
4 required
rum_rules-response-collection
tunnel_route_tunnel_id
UUID of the Cloudflare Tunnel serving the route.
stream_output_url
string
The URL an output uses to restream.
stream_direct_upload_request
object
9 properties
1 required
zero-trust-gateway_public_key
string
SSH encryption public key
stream_errorReasonCode
string
Specifies why the video failed to encode. This field is empty if the video is not in an error state. Preferred for programmatic use.
access_azure_group_rule
object
Matches an Azure group. Requires an Azure identity provider.
1 property
1 required
load-balancing_description
string
Object description.
legacy-jhs_schemas-filters
object
5 properties
aaa_webhooks
object
8 properties
custom-pages_custom_pages_response_collection
pages_build_config
object
Configs for the project build process.
6 properties
magic_route_add_single_request
object
6 properties
3 required
tunnel_tunnel_types
string
The types of tunnels to filter separated by a comma.
pages_deployment-response-logs
access_logo_url
string
The image URL for the logo shown in the App Launcher dashboard.
legacy-jhs_common_components-schemas-identifier
string
Identifier
stream_output
object
4 properties
vectorize_index-dimensions
integer
Specifies the number of dimensions for the index
addressing_memberships
array
Zones and Accounts which will be assigned IPs on this Address Map. A zone membership will take priority over an account membership.
access_certificates_components-schemas-single_response
workers-kv_key
object
A name for a value. A value stored under a given key may be retrieved via the same key.
3 properties
1 required
magic_wan_update_request
object
1 property
load-balancing_retries
integer
The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately.
magic_acls_collection_response
intel_popularity_rank
integer
Global Cloudflare 100k ranking for the last 30 days, if available for the hostname. The top ranked domain is 1, the lowest ranked domain is 100,000.
magic-visibility_pcaps_filter_v1
object
The packet capture filter. When this field is empty, all packets are captured.
5 properties
registrar-api_auto_renew
boolean
Auto-renew controls whether subscription is automatically renewed upon domain expiration.
access_name
string
The name of your Zero Trust organization.
addressing_timestamp
string
intel_page
number
Current page within paginated list of results.
tunnel_zero_trust_connectivity_settings_response
access_service_auth_401_redirect
boolean
Returns a 401 status code when the request is blocked by a Service Auth policy.
bill-subs-api_messages
array
magic_schemas-mtu
integer
The Maximum Transmission Unit (MTU) in bytes for the interconnect. The minimum value is 576.
workers_domain-response-collection
aaa_webhook-id
string
The unique identifier of a webhook
calls_api-response-single
object
access_apps_components-schemas-name
string
The name of the application.
dlp_ContextAwareness
object
Scan the context of predefined entries to only return matches surrounded by keywords.
2 properties
2 required
stream_signed_token_request
object
6 properties
stream_creator
string
A user-defined identifier for the media creator.
access_result_info
object
4 properties
teams-devices_user
object
3 properties
logpush_destination_conf
string
Uniquely identifies a resource (such as an s3 bucket) where data will be pushed. Additional configuration parameters supported by the destination may be includ…
teams-devices_device-posture-integrations
object
5 properties
stream_addAudioTrackResponse
tls-certificates-and-hostnames_api-response-common-failure
object
4 properties
4 required
workers_tag
string
Tag to help you manage your Worker
magic_colo_names
array
List of colo names for the ECMP scope.
images_image_key_name
string
Key name.
access_key_config
object
3 properties
magic_scope
object
Used only for ECMP routes.
2 properties
magic_acl_update_request
object
1 property
turnstile_api-response-common
object
3 properties
3 required
workers_logpush
boolean
Whether Logpush is turned on for the Worker.
dlp_V4ResponseError
object
4 properties
3 required
secondary-dns_ip_range
string
Allowed IPv4/IPv6 address range of primary or secondary nameservers. This will be applied for the entire account. The IP range is used to allow additional NOTI…
tunnel_conns_active_at
stringnull
Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If null, the tunnel is inactive.
access_gateway_seat
boolean
True if the seat is part of Gateway.
logcontrol_api-response-single
object
addressing_schemas-response_collection
secondary-dns_schemas-id_response
rum_per_page
number
Number of items to return per page of results.
teams-devices_fallback_domain
object
3 properties
1 required
access_apps_components-schemas-single_response
pages_project_name
string
Name of the project.
magic_tunnel_health_check
object
4 properties
stream_clipResponseSingle
security-center_issue
object
11 properties
zero-trust-gateway_fail_closed
boolean
Block requests for files that cannot be scanned.
teams-devices_interval
string
The interval between each posture check with the third-party API. Use m for minutes (e.g. 5m) and h for hours (e.g. 12h).
addressing_service_identifier
string
Identifier
zero-trust-gateway_traffic
string
The wirefilter expression used for traffic matching.
zero-trust-gateway_gateway-account-logging-settings
object
2 properties
lists_created_on
string
The RFC 3339 timestamp of when the list was created.
dlp_either_profile_response
dns-custom-nameservers_identifier
string
Account identifier tag.
cloudforce-one_request-status
string
Request Status
d1_query-meta
object
7 properties
magic_schemas-name
string
The name of the IPsec tunnel. The name cannot share a name with other tunnels.
tunnel_version
string
The cloudflared version used to establish this connection.
zero-trust-gateway_api-response-common-failure
object
4 properties
4 required
workers_queue_binding
object
3 properties
3 required
digital-experience-monitoring_uuid
string
API Resource UUID tag.
logcontrol_cmb_config_response_single
load-balancing_pool
object
17 properties
access_purpose_justification_prompt
string
A custom message that will appear on the purpose justification screen.
rum_api-response-common-failure
object
4 properties
4 required
lists_items-list-response-collection
tunnel_is_pending_reconnect
boolean
Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting…
logcontrol_regions
string
Comma-separated list of regions.
registrar-api_domain_update_properties
object
3 properties
d1_account-identifier
string
Account identifier tag.
registrar-api_address2
string
Optional address line for unit, floor, suite, etc.
teams-devices_workspace_one_config_request
object
4 properties
4 required
dlp_shared_entry_update_integration
object
Properties of an integration entry in a custom profile
2 properties
stream_input_srt
object
Details for streaming to a live input using SRT.
3 properties
registrar-api_identifier
string
Identifier
intel_name
string
The name of the indicator feed
teams-devices_tanium_input_request
object
6 properties
1 required
dns_dns_analytics_api_limit
integer
Limit number of returned metrics.
intel_api-response-common-failure
object
4 properties
4 required
workers_tail_consumers
array
List of Workers that will consume logs from the attached Worker.
access_bookmarks_components-schemas-single_response
vectorize_index-preset
string
Specifies the preset to use for the index.
teams-devices_allow_mode_switch
boolean
Whether to allow the user to switch WARP between modes.
legacy-jhs_schemas-identifier
workers-kv_api-response-single
object
load-balancing_enabled
boolean
Whether to enable (the default) or disable this pool. Disabled pools will not receive traffic and are excluded from health checks. Disabling a pool will cause…
tls-certificates-and-hostnames_mtls-management_components-schemas-certificate_response_collection
calls_secret
string
Bearer token to use the Calls API.
access_purpose_justification_required
boolean
Require users to enter a justification when they log in to the application.
cloudforce-one_request-list
object
10 properties
2 required
magic_gre
object
The configuration specific to GRE interconnects.
1 property
magic-transit_target_result
object
2 properties
rum_site-tag-response-single
intel_indicator_feed_item
object
5 properties
logpush_api-response-common-failure
object
4 properties
4 required
zero-trust-gateway_messages
array
zero-trust-gateway_ip
string
IPV6 destination ip assigned to this location. DNS requests sent to this IP will counted as the request under this location. This field is auto-generated by Ga…
magic_routes_collection_response
stream_live_input_metadata
object
A user modifiable key-value store used to reference other systems of record for managing live inputs.
addressing_api-response-common-failure
object
4 properties
4 required
teams-devices_version
string
The WARP client version.
r2_enable_sippy_gcs
object
2 properties
aaa_per_page
number
Number of items per page.
vectorize_index-get-vectors-by-id-request
object
1 property
tunnel_originRequest
object
Configuration parameters of connection between cloudflared and origin server.
14 properties
access_saml_saas_app
object
12 properties
workers-kv_components-schemas-result
aaa_components-schemas-response_collection
dlp_new_custom_profile
object
5 properties
workers_account_identifier
logpush_logpush_job_response_single
teams-devices_components-schemas-uuid
string
UUID
zero-trust-gateway_fips-settings
object
FIPS settings.
1 property
secondary-dns_acl
object
3 properties
3 required
magic-visibility_mnm_config_name
string
The account name.
magic_weight
integer
Optional weight of the ECMP scope - if provided.
zero-trust-gateway_categories
object
6 properties
teams-devices_unique_client_id_input_request
object
2 properties
2 required
intel_inherited_content_categories
access_github_organization_rule
object
Matches a Github organization. Requires a Github identity provider.
1 property
1 required
tunnel_comment
string
Optional remark describing the route.
load-balancing_consecutive_up
integer
To be marked healthy the monitored origin must pass this healthcheck N consecutive times.
secondary-dns_components-schemas-response_collection
addressing_can_modify_ips
boolean
If set to false, then the IPs on the Address Map cannot be modified via the API. This is true for Cloudflare-managed maps.
access_custom-claims-support
object
2 properties
intel_update_feed
object
3 properties
zero-trust-gateway_deleted_at
stringnull
Date of deletion, if any.
rum_api-response-single
object
load-balancing_subdivision_code_a2
string
Two-letter subdivision code followed in ISO 3166-2.
access_enable_binding_cookie
boolean
Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.
load-balancing_disabled_at
string
This field shows up only if the origin is disabled. This field is set with the time the origin was disabled.
stream_language
string
The language tag in BCP 47 format.
magic-visibility_account_identifier
hyperdrive_hyperdrive-scheme
string
Specifies the URL scheme used to connect to your origin database.
rum_snippet
string
Encoded JavaScript snippet.
zero-trust-gateway_response_collection
cloudforce-one_tlp
string
The CISA defined Traffic Light Protocol (TLP)
workers_environment
string
Optional environment if the Worker utilizes one.
access_single_response_without_html
images_image_variant_public_request
object
1 property
stream_audio_label
string
A string to uniquely identify the track amongst other audio track labels for the specified video.
magic_api-response-common
object
4 properties
4 required
access_tags_components-schemas-response_collection
magic-visibility_pcaps_time_limit
number
The packet capture duration in seconds.
access_components-schemas-name
string
The name of the Access group.
images_account_identifier
string
Account identifier tag.
aaa_url
string
The POST endpoint to call when dispatching a notification.
load-balancing_schemas-id_response
addressing_approved
string
Approval state of the prefix (P = pending, V = active).
load-balancing_schemas-identifier
string
dlp_allowed_match_count
number
Related DLP policies will trigger when the match count exceeds the number set.
teams-devices_revoked_at
string
When the device was revoked.
teams-devices_schemas-description
string
A description of the policy.
pages_deployment-list-response
magic_components-schemas-tunnel_single_response
teams-devices_model
string
The device model name.
stream_downloads_response
stream_playback_webrtc_url
string
The URL used to play live video over WebRTC.
magic-transit_packet_count
integer
Number of packets with a response from this node.
lists_item_ip
string
An IPv4 address, an IPv4 CIDR, or an IPv6 CIDR. IPv6 CIDRs are limited to a maximum of /64.
logpush_validate_ownership_response
magic-transit_asn
string
AS number associated with the node object.
hyperdrive_api-response-single
object
addressing_advertised_response
magic_identifier
string
Identifier
addressing_enabled
booleannull
Whether the Address Map is enabled or not. Cloudflare's DNS will not respond with IP addresses on an Address Map until the map is enabled.
tunnel_features
array
Features enabled for the Cloudflare Tunnel.
access_identity
object
18 properties
tunnel_vnet_response_collection
stream_size
number
The size of the media item in bytes.
tunnel_tunnel-response-collection
magic-visibility_pcaps_colo_name
string
The name of the data center used for the packet capture. This can be a specific colo (ord02) or a multi-colo name (ORD). This field only applies to full packet…
magic_route_update_request
aaa_schemas-description
string
Optional description for the Notification policy.
magic-visibility_mnm_rules_single_response
images_images_stats_count
object
2 properties
stream_clipping
object
15 properties
dns-custom-nameservers_acns_response_single
dns-firewall_negative_cache_ttl
numbernull
Negative DNS Cache TTL.
tunnel_ingressRule
object
Public hostname
4 properties
2 required
teams-devices_split_tunnel_response_collection
intel_url
string
URL(s) to filter submissions results by
magic_schemas-identifier
string
Tunnel identifier tag.
teams-devices_uuid
string
API UUID.
d1_database-details-response
object
6 properties
access_custom_page
object
7 properties
3 required
zero-trust-gateway_gateway_account_config
object
hyperdrive_identifier
string
Identifier
teams-devices_components-schemas-single_response
turnstile_invalidate_immediately
boolean
If invalidateimmediately is set to false, the previous secret will remain valid for two hours. Otherwise, the secret is immediately invalidated, and requests u…
magic_route_update_many_request
object
1 property
1 required
dns-custom-nameservers_result_info
object
4 properties
teams-devices_disable_auto_fallback
boolean
If the dnsserver field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy op…
iam_code
string
The unique activation code for the account membership.
access_app_count
integer
Number of apps the custom page is assigned to.
magic-visibility_mnm_rule
objectnull
7 properties
4 required
iam_schemas-role
object
4 properties
4 required
email_identifier
string
Identifier
access_schemas-allow_authenticate_via_warp
boolean
When set to true, users can authenticate to this application using their WARP session. When set to false this application will always require direct IdP authen…
vectorize_index-query-request
object
4 properties
pages_deployment-response-details
magic-visibility_pcaps_ownership_collection
registrar-api_api-response-collection
object
legacy-jhs_response_single
magic_replay_protection
boolean
If true, then IPsec replay protection will be supported in the Cloudflare-to-customer direction.
stream_notificationUrl
string
The URL where webhooks will be sent.
cloudforce-one_request-types
array
access_country_rule
object
Matches a specific country
1 property
1 required
access_email_rule
object
Matches a specific email.
1 property
1 required
email_modified
string
The date and time the destination address was last modified.
dns-custom-nameservers_ns_set
number
The number of the set that this name server belongs to.
stream_audio_state
string
Specifies the processing status of the video.
workers_namespace-list-response
tls-certificates-and-hostnames_association_response_collection
load-balancing_origin_steering
object
Configures origin steering for the pool. Controls how origins are selected for new sessions and traffic without session affinity.
1 property
intel_url_id
integer
Submission ID(s) to filter submission results by.
access_generic-oauth-config
object
2 properties
magic_route_delete_many_request
object
1 property
1 required
tunnel_route_response_single
teams-devices_name
string
The name of the device posture rule.
magic_mtu
integer
Maximum Transmission Unit (MTU) in bytes for the GRE tunnel. The minimum value is 576.
stream_output_streamKey
string
The streamKey used to authenticate against an output's target.
d1_query-result-response
object
3 properties
tunnel_teamnet_response_single
magic_description
string
An optional human provided description of the static route.
tunnel_cfd_tunnel
object
A Cloudflare Tunnel that connects your origin to Cloudflare's edge.
12 properties
bill-subs-api_identifier
string
Identifier
zero-trust-gateway_proxy-endpoints
object
6 properties
workers_dispatch_namespace_binding
object
4 properties
3 required
zero-trust-gateway_schemas-description
string
The description of the rule.
magic_ttl
integer
Time To Live (TTL) in number of hops of the GRE tunnel.
secondary-dns_algo
string
TSIG algorithm.
dns-firewall_ecs_fallback
boolean
Forward client IP (resolver) subnet if no EDNS Client Subnet is sent.
workers_domain_identifier
Identifer of the Worker Domain.
dlp_update_settings
object
Payload log settings
1 property
1 required
teams-devices_override_codes_response
stream_watermark_identifier
string
The unique identifier for a watermark profile.
iam_email
string
The contact email address of the user.
images_image_upload_via_url
object
1 property
1 required
bill-subs-api_subscription-v2
object
11 properties
dlp_DatasetNewVersionResponse
magic-transit_packet_type
string
Type of packet sent.
legacy-jhs_rule_components-schemas-identifier
string
The unique identifier of the IP Access rule.
load-balancing_api-response-collection
object
stream_videos
object
23 properties
teams-devices_schemas-single_response
aaa_schemas-alert_type
string
Type of notification that has been dispatched.
teams-devices_expiration
string
Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client.
addressing_ipam-prefixes
object
13 properties
magic-visibility_pcaps_ownership_challenge
string
The ownership challenge filename stored in the bucket.
bill-subs-api_current_period_start
string
When the current billing period started. May match initialperiodstart if this is the first period.
dlp_new_custom_entry
object
A custom entry create payload
3 properties
3 required
stream_api-response-single
object
tunnel_route_tunnel_name
The user-friendly name of the Cloudflare Tunnel serving the route.
cloudforce-one_uuid
string
UUID
magic-visibility_mnm_rule_advertisable_response
objectnull
1 property
1 required
dns_dns_analytics_api_filters
string
Segmentation filter in 'attribute operator value' format.
digital-experience-monitoring_traceroute_test_network_path_response
object
7 properties
1 required
stream_videoClipStandard
object
9 properties
3 required
magic_ip-address
string
A valid IPv4 address.
teams-devices_service_mode_v2
object
2 properties
access_schemas-empty_response
security-center_identifier
string
Identifier
lists_item_hostname
object
Valid characters for hostnames are ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (), and the hyphen (-).
1 property
1 required
magic_modified_on
string
When the route was last modified.
magic-visibility_mnm_rule_bandwidth_threshold
number
The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum.
logpush_logpush_field_response_collection
access_key_rotation_interval_days
number
The number of days between key rotations.
zero-trust-gateway_ecs-support
boolean
True if the location needs to resolve EDNS queries.
turnstile_api-response-common-failure
object
4 properties
4 required
stream_duration
number
The duration of the video in seconds. A value of -1 means the duration is unknown. The duration becomes available after the upload and before the video is read…
images_image_key_value
string
Key value.
intel_domain-history
object
2 properties
access_saas_props
object
9 properties
access_allow_all_headers
boolean
Allows all HTTP request headers.
lists_name
string
An informative name for the list. Use this name in filter and rule expressions.
teams-devices_exclude_office_ips
boolean
Whether to add Microsoft IPs to Split Tunnel exclusions.
magic_wan_deleted_response
magic_site_modified_response
dlp_pattern
object
A pattern that matches an entry
2 properties
1 required
load-balancing_notification_email
string
This field is now deprecated. It has been moved to Cloudflare's Centralized Notification service https://developers.cloudflare.com/fundamentals/notifications/.…
intel_inherited_risk_types
magic_psk_metadata
object
The PSK metadata that includes when the PSK was generated.
1 property
addressing_bgp_signaling_modified_at
stringnull
Last time BGP signaling control was toggled. This field is null if BGP signaling has never been enabled.
dns-custom-nameservers_CustomNSInput
object
2 properties
1 required
secondary-dns_ixfr_enable
boolean
Enable IXFR transfer protocol, default is AXFR. Only applicable to secondary zones.
zero-trust-gateway_single_response_with_list_items
access_client_secret
string
The Client Secret for the service token. Access will check for this value in the CF-Access-Client-Secret request header.
magic_components-schemas-modified_tunnels_collection_response
lists_item_asn
integer
A non-negative 32 bit integer
teams-devices_match_item
object
1 property
access_schemas-access_seat
boolean
True if the user has authenticated with Cloudflare Access.
stream_webhook_request
object
1 property
1 required
digital-experience-monitoring_timing_aggregates
object
3 properties
1 required
stream_pem
string
The signing key in PEM format.
teams-devices_device-managed-networks_components-schemas-name
string
The name of the device managed network. This name must be unique.
dns-custom-nameservers_CustomNS
object
A single account custom nameserver.
5 properties
4 required
magic_schemas-modified_tunnels_collection_response
teams-devices_precedence
number
The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field.
magic_prefix
string
IP Prefix in Classless Inter-Domain Routing format.
iam_grants
object
2 properties
images_image_basic_upload
object
2 properties
zero-trust-gateway_networks
array
A list of network ranges that requests from this location would originate from.
cloudforce-one_api-response-common-failure
dns-firewall_dns_firewall_single_response
access_app_uid
The unique identifier for the Access application.
access_certificates
object
7 properties
magic_routed_subnet
object
3 properties
2 required
iam_components-schemas-name
string
Role Name.
zero-trust-gateway_rules
object
15 properties
pages_api-response-common
object
4 properties
4 required
tunnel_conns_inactive_at
stringnull
Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If null, the tunnel is active.
iam_components-schemas-member
object
5 properties
5 required
access_access_seat
boolean
True if the seat is part of Access.
legacy-jhs_notes
string
An informative summary of the rule, typically used as a reminder or explanation.
teams-devices_config_response
object
The configuration object containing third-party integration information.
iam_permissions
object
12 properties
addressing_schemas-single_response
stream_playback_rtmps
object
Details for playback from an live input using RTMPS.
2 properties
zero-trust-gateway_count
number
The number of items in the list.
intel_start_end_params
object
2 properties
security-center_subject
string
stream_label
string
The language label displayed in the native language to users.
secondary-dns_api-response-single
object
aaa_policies_components-schemas-response_collection
tunnel_tunnel_client_response
stream_include_counts
boolean
Includes the total number of videos associated with the submitted query parameters.
stream_additionalAudio
object
4 properties
workers_namespace-single-response
workers_domain
object
6 properties
workers_object
object
2 properties
stream_account_identifier
string
The account identifier tag.
magic-visibility_pcaps_ownership_validate_request
object
2 properties
2 required
access_isolation_required
boolean
Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use…
dns-firewall_api-response-single
object
aaa_identifier
string
Identifier
load-balancing_schemas-header
object
The request header is used to pass additional information with an HTTP request. Currently supported header is 'Host'.
1 property
workers_created_on
string
When the script was created.
teams-devices_fallback_domain_response_collection
registrar-api_country
stringnull
The country in which the user lives.
access_active_sessions_response
magic_psk
string
A randomly generated or provided string for use in the IPsec tunnel.
magic_tunnels_collection_response
stream_clipped_from_video_uid
string
The unique video identifier (UID).
calls_name
string
A short description of Calls app, not shown to end users.
digital-experience-monitoring_sort_by
string
Dimension to sort results by
zero-trust-gateway_api-response-collection
object
security-center_subjects
array
magic-transit_identifier
string
Identifier
workers_bindings
array
List of bindings attached to this Worker
magic-visibility_pcaps_error_message
string
An error message that describes why the packet capture failed. This field only applies to full packet captures.
images_image
object
6 properties
stream_playback_srt_stream_id
string
The identifier of the live input to use for playback via SRT.
stream_live_input_recording_allowedOrigins
array
Lists the origins allowed to display videos created with this input. Enter allowed origin domains in an array and use for wildcard subdomains. An empty array a…
custom-pages_result_info
object
4 properties
lists_lists-async-response
rum_rules
array
A list of rules.
iam_first_name
stringnull
User's first name
security-center_products
array
logpush_last_complete
stringnull
Records the last time for which logs have been successfully pushed. If the last successful push was for logs range 2018-07-23T10:00:00Z to 2018-07-23T10:01:00Z…
magic_site-location
object
Location of site in latitude and longitude.
2 properties
intel_collection_response
dns-firewall_retries
number
Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt).
bill-subs-api_billing_response_single
workers_d1_binding
object
4 properties
4 required
magic_lan_deleted_response
teams-devices_fallback_domains
array
stream_live_input_recording_settings
object
Records the input to a Cloudflare Stream video. Behavior depends on the mode. In most cases, the video will initially be viewable as a live video and transitio…
4 properties
tls-certificates-and-hostnames_identifier
string
Identifier
workers_schemas-environment
string
Worker environment associated with the zone and hostname.
rulesets_ExecuteSensitivityLevel
string
dns_dns_analytics_api_time_delta
string
Unit of time to group data by.
magic_site_update_request
object
1 property
magic_colo_regions
array
List of colo regions for the ECMP scope.
stream_input_srt_url
string
The SRT URL you provide to the broadcaster, which they stream live video to.
vectorize_index-metric
string
Specifies the type of metric to use calculating distance.
tunnel_arch
string
The cloudflared OS architecture used to establish this connection.
access_path_cookie_attribute
boolean
Enables cookie paths to scope an application's JWT to the application path. If disabled, the JWT will scope to the hostname by default
teams-devices_tls_config_request
object
2 properties
1 required
digital-experience-monitoring_platform
string
Operating system
intel_application
object
Application that the hostname belongs to.
2 properties
intel_risk_score
number
Hostname risk score, which is a value between 0 (lowest risk) to 1 (highest risk).
images_image_response_single
hyperdrive_hyperdrive-caching
object
3 properties
access_schemas-session_duration
string
The amount of time that tokens issued for this application will be valid. Must be in the format 300ms or 2h45m. Valid time units are: ns, us (or µs), ms, s, m,…
zero-trust-gateway_description
string
The description of the list.
logpush_id
integer
Unique id of the job.
access_google-apps
object
legacy-jhs_api-response-common-failure
object
4 properties
4 required
vectorize_create-index-response
object
5 properties
zero-trust-gateway_result_info
object
4 properties
registrar-api_created_at
string
Shows time of creation.
legacy-jhs_api-response-single
object
calls_created
string
The date and time the item was created.
dns_dns_analytics_api_identifier
string
Identifier
access_policy_check_response
magic-visibility_mnm_config_single_response
lists_api-response-collection
object
stream_opacity
number
The translucency of the image. A value of 0.0 makes the image completely transparent, and 1.0 makes the image completely opaque. Note that if the image is alre…
logpush_api-response-single
object
magic-visibility_pcaps_request_pcap
vectorize_update-index-request
object
1 property
1 required
magic_site_deleted_response
access_last_seen_identity_response
zero-trust-gateway_proxy-endpoints_components-schemas-response_collection
access_exclude
array
Rules evaluated with a NOT logical operator. To match a policy, a user cannot meet any of the Exclude rules.
aaa_policy-id
string
The unique identifier of a notification policy
intel-sinkholes_name
string
The name of the sinkhole
magic-transit_colo_city
string
Source colo city.
teams-devices_dex-response_collection
lists_description
string
An informative summary of the list.
intel_api-response-collection
object
workers-kv_expiration_ttl
number
The number of seconds for which the key should be visible before it expires. At least 60.
load-balancing_notification_filter
objectnull
Filter pool and origin health notifications by resource type or health status. Use null to reset.
2 properties
load-balancing_origins
array
The list of origins within this pool. Traffic directed at this pool is balanced across all currently healthy origins, provided the pool itself is healthy.
workers_compatibility_flag
string
A flag to opt into a specific change
images_image_variant_definition
object
3 properties
2 required
intel_asn_components-schemas-response
zero-trust-gateway_value
string
The value of the item in a list.
access_custom-pages_components-schemas-name
string
Custom page name.
logpush_logpush_job
objectnull
11 properties
stream_language_response_single
hyperdrive_hyperdrive-origin-with-password
object
1 property
1 required
zero-trust-gateway_id
integer
The identifier for this category. There is only one category per ID.
stream_live_input
object
Details about a live input.
13 properties
logpush_frequency
stringnull
The frequency at which Cloudflare sends batches of logs to your destination. Setting frequency to high sends your logs in larger quantities of smaller files. S…
access_certificates_components-schemas-response_collection
rulesets_Ruleset
object
A ruleset object.
7 properties
3 required
turnstile_widget_detail
object
A Turnstile widget's detailed configuration
11 properties
11 required
logcontrol_messages
array
digital-experience-monitoring_percentiles
object
4 properties
access_client_id
string
The Client ID for the service token. Access will check for this value in the CF-Access-Client-ID request header.
workers_hostname
string
Hostname of the Worker Domain.
load-balancing_expected_body
string
A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy. This parameter is only val…
turnstile_created_on
string
When the widget was created.
intel_result_info
object
4 properties
magic_cloudflare_ipsec_endpoint
string
The IP address assigned to the Cloudflare side of the IPsec tunnel.
rulesets_FailureResponse
object
A failure response object.
4 properties
4 required
tunnel_tunnel_client
object
A client (typically cloudflared) that maintains connections to a Cloudflare data center.
7 properties
access_approval_groups
array
Administrators who can approve a temporary authentication request.
pages_new-project-response
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Cloudflare publishes across the network.