The identity and technical contract details declared by the specification.
bill-subs-api_components-schemas-name
The unique component.
tls-certificates-and-hostnames_hosts
array
zones_tls_1_2_only
Only allows TLS1.2.
zones_rocket_loader_value
string
Value of the zone setting.
rulesets_RulesResponse
array
The list of rules in the ruleset.
zones_tls_1_3_value
string
Value of the zone setting. Notes: Default value depends on the zone's plan level.
zaraz_zaraz-workflow-response
tls-certificates-and-hostnames_schemas-enabled
boolean
Disabling Universal SSL removes any currently active Universal SSL certificates for your zone from the edge and prevents any future Universal SSL certificates…
tls-certificates-and-hostnames_name
string
The keyless SSL name.
observatory_schedule
object
The test schedule.
3 properties
zaraz_api-response-common
object
3 properties
4 required
speed_base
object
4 properties
2 required
cache-purge_api-response-single-id
object
healthchecks_timestamp
string
rulesets_response_model
object
3 properties
zones_development_mode_value
string
Value of the zone setting.
dnssec_modified_on
stringnull
When DNSSEC was last modified.
email_email_setting_enabled
boolean
State of the zone settings for Email Routing.
bill-subs-api_schemas-component_values
array
Array of available components values for the plan.
dns-records_tag_match
string
Whether to match all tag search requirements or at least one (any). If set to all, acts like a logical AND between tag filters. If set to any, acts like a logi…
legacy-jhs_bypass
array
Criteria specifying when the current rate limit should be bypassed. You can specify that the rate limit should not apply to one or more URLs.
waitingroom_update_rules
array
email_rule_tag
string
Routing rule tag. (Deprecated, replaced by routing rule identifier)
legacy-jhs_schemas-url
string
The URL pattern to match, composed of a host and a path such as example.org/path. Normalization is applied before the pattern is matched. wildcards are expande…
legacy-jhs_timestamp
string
tls-certificates-and-hostnames_enabled_response
legacy-jhs_period
number
The time in seconds (an integer value) to count matching traffic. If the count exceeds the configured threshold within this period, Cloudflare will perform the…
dns_dns_analytics_api_data
array
Array with one row per combination of dimension values.
dns-records_SRVRecord
3 required
dns-custom-nameservers_messages
array
email_email_setting_skip-wizard
boolean
Flag to check if the user skipped the configuration wizard.
tls-certificates-and-hostnames_schemas-private_key
string
The hostname certificate's private key.
zones_zone_settings_response_collection
bill-subs-api_default
number
The default amount allocated.
waitingroom_name
string
A unique name to identify the waiting room. Only alphanumeric characters, hyphens and underscores are allowed.
load-balancing_adaptive_routing
object
Controls features that modify the routing of requests to pools and origins in response to dynamic conditions, such as during the interval between active health…
1 property
access_api-response-collection
object
legacy-jhs_schemas-until
string
End of time interval to query, defaults to current time. Timestamp must be in RFC3339 format and uses UTC unless otherwise specified.
api-shield_messages
array
data-zone-analytics-api_pageviews
object
Breakdown of totals for pageviews.
2 properties
cache-purge_api-response-common-failure
object
4 properties
4 required
zones_security_header_value
object
1 property
workers_filters
object
3 properties
3 required
api-shield_api-response-common
object
4 properties
4 required
waitingroom_status_response
secondary-dns_single_request_outgoing
object
3 properties
3 required
tls-certificates-and-hostnames_issued_on
string
Date that the Client Certificate was issued by the Certificate Authority
tls-certificates-and-hostnames_certificateObject
object
7 properties
legacy-jhs_filter-rules-single-response-delete
tls-certificates-and-hostnames_keyless_vnet_id
string
Cloudflare Tunnel Virtual Network ID
waf-managed-rules_rule_group_response_collection
page-shield_script
object
13 properties
page-shield_api-response-single
object
waitingroom_event_details_response
api-shield_schema_response_discovery
load-balancing_rules
array
BETA Field Not General Access: A list of rules for this load balancer to execute.
waf-managed-rules_priority
string
The order in which the individual WAF rule is executed within its rule group.
tls-certificates-and-hostnames_components-schemas-certificate_authority
string
The Certificate Authority that Total TLS certificates will be issued through.
tls-certificates-and-hostnames_cloudflare_branding
boolean
Whether or not to add Cloudflare Branding for the order. This will add sni.cloudflaressl.com as the Common Name if set true.
access_components-schemas-response_collection
cache_regional_tiered_cache_response_value
object
1 property
workers_namespace_identifier
string
Namespace identifier tag.
bill-subs-api_state
string
The state that the subscription is in.
legacy-jhs_cidr_configuration
object
2 properties
tls-certificates-and-hostnames_ssl_verification_response_collection
zones_brotli
When the client requesting an asset supports the Brotli compression algorithm, Cloudflare will serve a Brotli compressed version of the asset.
tls-certificates-and-hostnames_custom_metadata
object
These are per-hostname (customer) settings.
secondary-dns_disable_transfer_response
bot-management_api-response-common-failure
object
4 properties
4 required
legacy-jhs_zonelockdown_response_single
secondary-dns_schemas-force_result
string
When forcenotify query parameter is set to true, the response is a simple string
workers_schemas-script-response-single
dns_dns_analytics_api_sort
string
A comma-separated list of dimensions to sort by, where each dimension may be prefixed by - (descending) or + (ascending).
tls-certificates-and-hostnames_client-certificates_components-schemas-certificate
string
The Client Certificate PEM
access_allowed_methods
array
Allowed HTTP request methods.
tls-certificates-and-hostnames_components-schemas-enabled
boolean
If enabled, Total TLS will order a hostname specific TLS certificate for any proxied A, AAAA, or CNAME record in your zone.
waf-managed-rules_components-schemas-identifier
string
The unique identifier of the rule group.
zones_opportunistic_encryption_value
string
Value of the zone setting. Notes: Default value depends on the zone's plan level.
workers_identifier
string
Identifier
legacy-jhs_analytics-aggregate_components-schemas-response_collection
bot-management_sbfm_likely_automated
string
Super Bot Fight Mode (SBFM) action to take on likely automated requests.
tls-certificates-and-hostnames_verification
object
8 properties
1 required
access_ip_rule
object
Matches an IP address block.
1 property
1 required
zones_http2_value
string
Value of the HTTP2 setting.
access_schemas-azureAD
object
dns-records_identifier
string
Identifier
secondary-dns_messages
array
waf-managed-rules_schemas-description
string
The public description of the WAF rule.
dns-records_PTRRecord
3 required
bill-subs-api_api-response-common-failure
object
4 properties
4 required
api-shield_schema_response_with_thresholds
waitingroom_rule_version
string
The version of the rule.
email_api-response-single
object
legacy-jhs_groups
object
An object that allows you to enable or disable WAF rule groups for the current WAF override. Each key of this object must be the ID of a WAF rule group, and ea…
legacy-jhs_filters_components-schemas-id
string
The unique identifier of the filter.
dweb-config_content_list_entry_create_request
object
3 properties
2 required
bill-subs-api_rate-plan_components-schemas-identifier
string
Plan identifier tag.
api-shield_api_discovery_state_patch
string
Mark state of operation in API Discovery review - Mark operation as for review ignored - Mark operation as ignored
argo-config_identifier
string
Identifier
tls-certificates-and-hostnames_api-response-collection
object
access_allow_credentials
boolean
When set to true, includes credentials (cookies, authorization headers, or TLS client certificates) with requests.
legacy-jhs_ratelimit
object
8 properties
email_email_setting_name
string
Domain of your zone.
workers_script_name
string
Name of the script, used in URLs and route configuration.
page-shield_get-zone-policy-response
speed_api-response-common
object
3 properties
3 required
waitingroom_rule_result
object
7 properties
zone-activation_messages
array
secondary-dns_soa_serial
number
The serial number of the SOA for the given zone.
healthchecks_http_config
objectnull
Parameters specific to an HTTP or HTTPS health check.
8 properties
access_schemas-google
object
custom-pages_api-response-collection
object
zones_http3
HTTP3 enabled for this zone.
access_policies_components-schemas-single_response-2
zones_waf_value
string
Value of the zone setting.
waitingroom_custom_page_html
string
Only available for the Waiting Room Advanced subscription. This is a template html file that will be rendered at the edge. If no custompagehtml is provided, th…
tls-certificates-and-hostnames_verification_status
boolean
Status of the required verification information, omitted if verification status is unknown.
tls-certificates-and-hostnames_organizational_unit
string
Organizational Unit, provided by the CSR
bill-subs-api_currency
string
The monetary unit in which pricing information is displayed.
zones_ciphers_value
array
Value of the zone setting.
access_basic_app_response_props
object
4 properties
zones_pagerule_response_single
bot-management_bot_fight_mode_config
access_schemas-identity-provider
object
5 properties
3 required
tls-certificates-and-hostnames_hostname-authenticated-origin-pull_components-schemas-expires_on
string
The date when the certificate expires.
email_email_settings_properties
object
8 properties
dns-records_CAARecord
3 required
data-zone-analytics-api_end
Sets the (exclusive) end of the requested time frame. This can be a unix timestamp (in seconds or nanoseconds), or an absolute timestamp that conforms to RFC 3…
tls-certificates-and-hostnames_cert_pack_uuid
string
Certificate Pack UUID.
waitingroom_rule_description
string
The description of the rule.
waitingroom_suspended
boolean
Suspends or allows traffic going to the waiting room. If set to true, the traffic will not go to the waiting room.
dns_dns_analytics_api_report_bytime
dns-custom-nameservers_get_response
dns-records_per_page
number
Number of DNS records per page.
workers_api-response-single
object
zones_tls_client_auth_value
string
value of the zone setting.
email_rule_matchers
array
Matching patterns to forward to your actions.
load-balancing_random_steering
object
Configures pool weights. - steeringpolicy="random": A random pool is selected with probability proportional to pool weights. - steeringpolicy="leastoutstanding…
2 properties
legacy-jhs_ua-rules_components-schemas-mode
The action to apply to a matched request.
dns-records_type
string
Record type.
tls-certificates-and-hostnames_certificate_status
string
Current status of certificate.
api-shield_identifier
string
Identifier
api-shield_validation_default_mitigation_action
string
The default mitigation action used when there is no mitigation action defined on the operation Mitigation actions are as follows: log - log request when reques…
cache_regional_tiered_cache
Instructs Cloudflare to check a regional hub data center on the way to your upper tier. This can help improve performance for smart and custom tiered cache top…
data-zone-analytics-api_fields_response
object
1 property
tls-certificates-and-hostnames_hostname-tls-settings_components-schemas-status
string
Deployment status for the given tls setting.
page-shield_version
object
The version of the analyzed script.
3 properties
waitingroom_queue_all
boolean
If queueall is true, all the traffic that is coming to a route will be sent to the waiting room. No new traffic can get to the route once this field is set and…
cache_cache_reserve_clear_start_ts
string
The time that the latest Cache Reserve Clear operation started.
waf-managed-rules_rule_response_single
zone-activation_api-response-common
object
4 properties
4 required
legacy-jhs_created_on
string
The timestamp of when the rule was created.
waitingroom_host
string
The host name to which the waiting room will be applied (no wildcards). Please do not include the scheme (http:// or https://). The host and path combination m…
legacy-jhs_components-schemas-response_collection
logpush_name
stringnull
Optional human readable job name. Not unique. Cloudflare suggests that you set this to a meaningful string, like the domain name, to make it easier to identify…
logpush_logpull_options
stringnull
This field is deprecated. Use outputoptions instead. Configuration string. It specifies things like requested fields and timestamp formats. If migrating from t…
load-balancing_fallback_pool
The pool ID to use when all other pools are detected as unhealthy.
waitingroom_api-response-common
object
4 required
dweb-config_content_list_action
string
Behavior of the content list.
load-balancing_api-response-common
object
4 properties
4 required
argo-config_api-response-common
object
4 properties
4 required
tls-certificates-and-hostnames_certificate_analyze_response
cache_identifier
string
Identifier
snippets-api_api-response-common
object
4 properties
4 required
waitingroom_estimated_total_active_users
integer
cache_origin_max_http_version
Origin Max HTTP Setting Version sets the highest HTTP version Cloudflare will attempt to use with your origin. This setting allows Cloudflare to make HTTP/2 re…
zones_cname_flattening_value
string
Value of the cname flattening setting.
legacy-jhs_anomaly_package
7 required
zones_advanced_ddos_value
string
Value of the zone setting. Notes: Defaults to on for Business+ plans
load-balancing_timestamp
string
dns-records_direction
string
Direction to order DNS records in.
email_catch_all_rule_response_single
access_skip_interstitial
boolean
Enables automatic authentication through cloudflared.
access_response_collection_hostnames
logpush_validate_response
argo-config_response_single
bot-management_using_latest_model
boolean
A read-only field that indicates whether the zone currently is running the latest ML model.
access_api-response-single
object
api-shield_operation_schema_validation_settings
object
1 property
dweb-config_collection_response
dns-records_TXTRecord
3 required
cache_api-response-single
object
api-shield_operation_feature_parameter_schemas
object
1 property
2 required
waf-managed-rules_traditional_deny_rule
When triggered, traditional WAF rules cause the firewall to immediately act upon the request based on the configuration of the rule. A 'deny' rule will immedia…
8 required
access_external_evaluation_rule
object
Create Allow or Block policies which evaluate the user based on custom criteria.
1 property
1 required
observatory_lighthouse_state
string
The state of the Lighthouse report.
access_allowed_origins
array
Allowed origins.
secondary-dns_enable_transfer_response
legacy-jhs_products
array
access_authentication_method_rule
object
Enforce different MFA options
1 property
1 required
zones_mobile_redirect
Automatically redirect visitors on mobile devices to a mobile-optimized subdomain. Refer to [Understanding Cloudflare Mobile Redirect](https://support.cloudfla…
argo-config_api-response-single
object
bot-management_base_config
legacy-jhs_dimensions
array
Can be used to break down the data by given attributes. Options are: Dimension | Name | Example --||-- event | Connection Event | connect, progress, disconnect…
waitingroom_query_preview
object
1 property
1 required
api-shield_p99
integer
The p99 quantile of requests (in periodseconds).
observatory_api-response-single
object
access_schemas-require
array
Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.
api-shield_timestamp
string
zones_websockets
WebSockets are open connections sustained between the client and the origin server. Inside a WebSockets connection, the client and the origin can pass data bac…
page-shield_api-response-common-failure
object
4 properties
4 required
tls-certificates-and-hostnames_brand_check
boolean
Certificate Authority is manually reviewing the order.
waf-managed-rules_allowed_modes
array
The available states for the rule group.
email_rule_actions
array
List actions patterns.
email_rules_response_collection
access_schemas-auto_redirect_to_identity
boolean
When set to true, users skip the identity provider selection step during login. You must specify only one identity provider in allowedidps.
tls-certificates-and-hostnames_hostname_certid_input
object
3 properties
api-shield_p50
integer
The p50 quantile of requests (in periodseconds).
zones_rocket_loader
Rocket Loader is a general-purpose asynchronous JavaScript optimisation that prioritises rendering your content while loading your site's Javascript asynchrono…
zones_nel
Enable Network Error Logging reporting on your zone. (Beta)
speed_cloudflare_fonts
Enhance your website's font delivery with Cloudflare Fonts. Deliver Google Hosted fonts from your own domain, boost performance, and enhance user privacy. Refe…
dns-custom-nameservers_zone_metadata
object
2 properties
tls-certificates-and-hostnames_certificate-packs_components-schemas-status
string
Status of certificate pack.
email_rule_properties
object
7 properties
page-shield_use_connection_url_path
boolean
When true, the paths associated with connections URLs will also be analyzed.
legacy-jhs_filter-delete-response-collection
bot-management_sbfm_definitely_config
tls-certificates-and-hostnames_value
The tls setting value.
tls-certificates-and-hostnames_keyless_response_single_id
waf-managed-rules_mode
string
The state of the rules contained in the rule group. When on, the rules in the group are configurable/usable.
logpush_ownership_challenge
string
Ownership challenge token to prove destination ownership.
healthchecks_status
string
The current status of the origin server according to the health check.
waitingroom_event_result
object
16 properties
tls-certificates-and-hostnames_schemas-created_at
string
The time when the certificate was created.
api-shield_basic_operation
object
3 properties
3 required
legacy-jhs_zonelockdown_response_collection
tls-certificates-and-hostnames_hostname_associations_response
tls-certificates-and-hostnames_certificate_response_single
tls-certificates-and-hostnames_dcv_delegation_response
zones_pagerule_response_collection
bill-subs-api_result_info
object
4 properties
zaraz_zaraz-config-base
object
Zaraz configuration
8 properties
7 required
access_policies_components-schemas-name
string
The name of the Access policy.
dns-records_api-response-collection
object
api-shield_default_response
load-balancing_session_affinity_ttl
number
Time, in seconds, until a client's session expires after being created. Once the expiry time has been reached, subsequent requests may get sent to a different…
dweb-config_messages
array
data-zone-analytics-api_totals
object
Breakdown of totals by data type.
7 properties
page-shield_get-zone-settings-response
object
4 properties
api-shield_operation_schema_validation_settings_multiple_request
object
bill-subs-api_plan_response_collection
workers_wasm_module_binding
object
2 properties
2 required
dweb-config_modify_request
object
2 properties
legacy-jhs_components-schemas-priority
number
The relative priority of the current URI-based WAF override when multiple overrides match a single URL. A lower number indicates higher priority. Higher priori…
healthchecks_messages
array
load-balancing_ttl
number
Time to live (TTL) of the DNS entry for the IP address returned by this load balancer. This only applies to gray-clouded (unproxied) load balancers.
api-shield_schema_upload_failure
dns_dns_analytics_api_result
object
7 properties
7 required
dns-records_dns_response_single
access_aud
string
The Application Audience (AUD) tag. Identifies the application associated with the CA.
custom-pages_api-response-common
object
4 properties
4 required
access_certificate_rule
object
Matches any valid client certificate.
1 property
1 required
dns-records_SVCBRecord
3 required
data-zone-analytics-api_ray_identifier
string
Ray identifier.
dns_dns_analytics_api_report
dns_dns_analytics_api_metrics
string
A comma-separated list of metrics to query.
observatory_region
string
A test region.
dweb-config_content_list_entry_type
string
Type of content list entry to block.
waf-managed-rules_result_info
object
4 properties
tls-certificates-and-hostnames_organization
string
Organization, provided by the CSR
observatory_availabilities
object
3 properties
rulesets_type
string
The type of URL normalization performed by Cloudflare.
waitingroom_preview_url
string
URL where the custom waiting room page can temporarily be previewed.
legacy-jhs_package_response_single
zones_settings
array
Settings available for the zone.
access_ca_components-schemas-single_response
tls-certificates-and-hostnames_keyless_tunnel
object
Configuration for using Keyless SSL through a Cloudflare Tunnel
2 properties
2 required
waf-managed-rules_group
object
6 properties
dns-records_DSRecord
3 required
dns-records_CNAMERecord
3 required
legacy-jhs_api-response-collection
object
zones_sha1_support
Allow SHA1 support.
dnssec_identifier
string
Identifier
waitingroom_event_session_duration
integernull
If set, the event will override the waiting room's sessionduration property while it is active. If null, the event will inherit it.
zones_edge_cache_ttl
Time (in seconds) that a resource will be ensured to remain on Cloudflare's cache servers.
tls-certificates-and-hostnames_certificate
string
The zone's SSL certificate or certificate and the intermediate(s).
dnssec_status
Status of DNSSEC, based on user-desired state and presence of necessary records.
tls-certificates-and-hostnames_certificate_pack_quota_response
load-balancing_steering_policy
string
Steering Policy for this load balancer. - "off": Use defaultpools. - "geo": Use regionpools/countrypools/poppools. For non-proxied requests, the country for co…
legacy-jhs_modified
string
When the Application was last modified.
load-balancing_components-schemas-name
string
The DNS hostname to associate with your Load Balancer. If this hostname already exists as a DNS record in Cloudflare's DNS, the Load Balancer will take precede…
dns-records_proxied
boolean
Whether the record is receiving the performance and security benefits of Cloudflare.
cache-purge_api-response-common
object
4 properties
4 required
dnssec_dnssec_response_single
legacy-jhs_schemas-mode
string
The action to apply to a matched request.
zones_webp_value
string
Value of the zone setting.
snippets-api_identifier
string
Identifier
legacy-jhs_schemas-urls
array
The URLs to include in the rule definition. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard pa…
bill-subs-api_name
string
The domain name
observatory_api-response-common
object
3 properties
3 required
access_is_ui_read_only
boolean
Lock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled.
api-shield_data_points
integer
The number of data points used for the threshold suggestion calculation.
email_email_setting_identifier
string
Email Routing settings identifier.
access_schemas-github
object
workers_filter-response-collection
zones_cache_level_value
string
Value of the zone setting.
tls-certificates-and-hostnames_schemas-uploaded_on
string
This is the time the certificate was uploaded.
logpush_api-response-common
object
4 properties
4 required
waf-managed-rules_allowed_modes_anomaly
array
Defines the available modes for the current WAF rule. Applies to anomaly detection WAF rules.
healthchecks_interval
integer
The interval between each health check. Shorter intervals may give quicker notifications if the origin status changes, but will increase load on the origin as…
waitingroom_waiting_room_id_response
cache_regional_tiered_cache_value
string
Value of the Regional Tiered Cache zone setting.
page-shield_policy_id
string
The ID of the policy.
healthchecks_failure_reason
string
The current failure reason if status is unhealthy.
waf-managed-rules_schemas-base
observatory_pages-response-collection
tls-certificates-and-hostnames_origin
string
Your origin hostname that requests to your custom hostnames will be sent to.
healthchecks_tcp_config
objectnull
Parameters specific to TCP health check.
2 properties
legacy-jhs_rule_single_id_response
bill-subs-api_schemas-price
number
The amount you will be billed for this plan.
zaraz_zaraz-config-history-response
legacy-jhs_ip_search
string
A single IP address to search for in existing rules.
bill-subs-api_duration
number
The duration of the plan subscription.
zones_security_level
Choose the appropriate security profile for your website, which will automatically adjust each of the security settings. If you choose to customize an individu…
email_rule_name
string
Routing rule name.
access_associated_hostnames
array
The hostnames of the applications that will use this certificate.
tls-certificates-and-hostnames_schemas-signature
string
Certificate's signature algorithm.
healthchecks_single_response
data-zone-analytics-api_uniques
object
1 property
zones_ssl_recommender
Enrollment in the SSL/TLS Recommender service which tries to detect and recommend (by sending periodic emails) the most secure SSL/TLS setting your origin serv…
logpush_identifier
string
Identifier
rulesets_Rule
object
11 properties
2 required
waitingroom_cookie_suffix
string
Appends a '' + a custom suffix to the end of Cloudflare Waiting Room's cookie name(cfwaitingroom). If cookiesuffix is "abcd", the cookie name will be cfwaiting…
access_http_only_cookie_attribute
boolean
Enables the HttpOnly cookie attribute, which increases security against XSS attacks.
custom-pages_api-response-common-failure
object
4 properties
4 required
tls-certificates-and-hostnames_expires_on
string
When the certificate from the authority expires.
tls-certificates-and-hostnames_quota
object
2 properties
zones_server_side_exclude_value
string
Value of the zone setting.
legacy-jhs_ua-rules_components-schemas-id
string
The unique identifier of the User Agent Blocking rule.
zones_development_mode
Development Mode temporarily allows you to enter development mode for your websites if you need to make changes to your site. This will bypass Cloudflare's acc…
dns-records_match
string
Whether to match all search requirements or at least one (any). If set to all, acts like a logical AND between filters. If set to any, acts like a logical OR i…
legacy-jhs_rule
object
7 properties
4 required
healthchecks_query_healthcheck
object
13 properties
2 required
tls-certificates-and-hostnames_custom_hostname_response_single
dns-records_dns-record
object
9 required
rulesets_CreateRulesetRequest
legacy-jhs_uri_search
string
A single URI to search for in the list of URLs of existing rules.
waitingroom_result_info
object
4 properties
dns-records_api-response-common-failure
object
4 properties
4 required
healthchecks_api-response-common
object
4 properties
4 required
dns-custom-nameservers_schemas-identifier
string
Identifier
load-balancing_country_pools
object
A mapping of country codes to a list of pool IDs (ordered by their failover priority) for the given country. Any country not explicitly defined will fall back…
bot-management_bot_management_response_body
api-shield_operation
object
tls-certificates-and-hostnames_hostname-authenticated-origin-pull
object
6 properties
legacy-jhs_package_components-schemas-name
string
The name of the WAF package.
access_settings
object
3 properties
3 required
zones_schemas-automatic_platform_optimization
[Automatic Platform Optimization for WordPress](https://developers.cloudflare.com/automatic-platform-optimization/) serves your WordPress site from Cloudflare'…
legacy-jhs_override_response_collection
access_ip_list_rule
object
Matches an IP address from a list.
1 property
1 required
waitingroom_event_custom_page_html
stringnull
If set, the event will override the waiting room's custompagehtml property while it is active. If null, the event will inherit it.
legacy-jhs_firewalluablock_response_single
tls-certificates-and-hostnames_ski
string
Subject Key Identifier
dns-records_dns_response_import_scan
tls-certificates-and-hostnames_api-response-common
object
4 properties
4 required
tls-certificates-and-hostnames_components-schemas-validation_method
object
1 property
1 required
legacy-jhs_result_info
object
4 properties
bot-management_bm_subscription_config
rulesets_Response
object
A response object.
4 properties
4 required
cache-purge_messages
array
zones_pagerule_settings_response_collection
access_schemas-exclude
array
Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.
access_components-schemas-domain
string
The domain and path that Access will secure.
tls-certificates-and-hostnames_enabled_write
boolean
Whether or not the Keyless SSL is on or off.
tls-certificates-and-hostnames_serial_number
string
The serial number on the uploaded certificate.
custom-pages_messages
array
load-balancing_components-schemas-id_response
logpush_instant_logs_job_response_collection
tls-certificates-and-hostnames_components-schemas-updated_at
string
This is the time the tls setting was updated.
logpush_last_error
stringnull
Records the last time the job failed. If not null, the job is currently failing. If null, the job has either never failed or has run successfully at least once…
tls-certificates-and-hostnames_schemas-validation_method
string
Validation method in use for a certificate pack order.
zones_orange_to_orange_value
string
Value of the zone setting.
waitingroom_rules_response_collection
tls-certificates-and-hostnames_components-schemas-created_at
string
This is the time the tls setting was originally created for this hostname.
access_apps_components-schemas-single_response-2
tls-certificates-and-hostnames_certificate_response_collection
tls-certificates-and-hostnames_ssl_validation_method_response_collection
legacy-jhs_overrides_components-schemas-id
string
The unique identifier of the WAF override.
zones_schemas-modified_on
string
The timestamp of when the Page Rule was last modified.
dns-records_CERTRecord
3 required
waitingroom_event_name
string
A unique name to identify the event. Only alphanumeric characters, hyphens and underscores are allowed.
zones_websockets_value
string
Value of the zone setting.
waitingroom_event_details_disable_session_renewal
boolean
legacy-jhs_response_single_origin_dns
zones_priority
integer
The priority of the rule, used to define which Page Rule is processed over another. A higher number indicates a higher priority. For example, if you have a cat…
email_email_setting_tag
string
Email Routing settings tag. (Deprecated, replaced by Email Routing settings identifier)
legacy-jhs_header_op
string
The operator used when matching: eq means "equal" and ne means "not equal".
dweb-config_content_list_entry_single_response
bot-management_api-response-single
object
access_schemas-policies
object
14 properties
access_okta_group_rule
object
Matches an Okta group. Requires an Okta identity provider.
1 property
1 required
argo-analytics_api-response-common-failure
object
4 properties
4 required
zaraz_zaraz-config-row-base
object
4 properties
4 required
logpush_get_ownership_response
bill-subs-api_api-response-common
object
4 properties
4 required
page-shield_fetched_at
stringnull
The timestamp of when the script was last fetched.
waf-managed-rules_rule_response_collection
tls-certificates-and-hostnames_schemas-certificate_authority
string
Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details.](h…
legacy-jhs_schemas-cidr_configuration
object
2 properties
waitingroom_next_event_prequeue_start_time
stringnull
An ISO 8601 timestamp that marks when the next event will begin queueing.
tls-certificates-and-hostnames_validation_method_components-schemas-status
string
Result status.
dweb-config_create_request
object
4 properties
2 required
page-shield_pageshield-policy-id
string
The ID of the policy
api-shield_result_info
object
4 properties
healthchecks_check_regions
arraynull
A list of regions from which to run health checks. Null means Cloudflare will pick a default region.
access_type
string
The application type.
legacy-jhs_header_name
string
The name of the response header to match.
legacy-jhs_package
object
bill-subs-api_legacy_id
string
The legacy identifier for this rate plan, if any.
zones_h2_prioritization_value
string
Value of the zone setting.
access_schemas-google-apps
object
tls-certificates-and-hostnames_schemas-hostname
string
The hostname on the origin for which the client certificate uploaded will be used.
legacy-jhs_schemas-ip_configuration
object
2 properties
cache-purge_identifier
string
zones_ciphers
An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format.
legacy-jhs_methods
array
The HTTP methods to match. You can specify a subset (for example, ['POST','PUT']) or all methods (['ALL']). This field is optional when creating a rate limit.
access_saml_group_rule
object
Matches a SAML group. Requires a SAML identity provider.
1 property
1 required
api-shield_validation_enabled
boolean
Flag whether schema is enabled for validation.
tls-certificates-and-hostnames_keyless-certificate
object
zones_paused
boolean
Indicates whether the zone is only using Cloudflare DNS services. A true value means the zone will not receive security or performance benefits.
legacy-jhs_filter-rule-response
object
zaraz_zaraz-config-response
dns_dns_analytics_api_since
string
Start date and time of requesting data period in ISO 8601 format.
email_api-response-collection
object
tls-certificates-and-hostnames_components-schemas-certificate_response_collection
tls-certificates-and-hostnames_components-schemas-status
Status of the hostname's activation.
zones_route
object
3 properties
access_schemas-warp_props
tls-certificates-and-hostnames_private_key
string
The zone's private key.
legacy-jhs_api-response-common
object
4 properties
4 required
legacy-jhs_zonelockdown
object
7 properties
7 required
observatory_schedule_frequency
string
The frequency of the test.
rulesets_RulesetKind
string
The kind of the ruleset.
secondary-dns_peers
array
A list of peer tags.
zones_min_tls_version
Only accepts HTTPS requests that use at least the TLS protocol version specified. For example, if TLS 1.1 is selected, TLS 1.0 connections will be rejected, wh…
waitingroom_event_end_time
string
An ISO 8601 timestamp that marks the end of the event.
rulesets_RuleId
string
The unique ID of the rule.
access_schemas-oidc
object
logpush_error_message
stringnull
If not null, the job is currently failing. Failures are usually repetitive (example: no permissions to write to destination bucket). Only the last failure is r…
tls-certificates-and-hostnames_schemas-identifier
string
Keyless certificate identifier tag.
cache_origin_max_http_version_value
string
Value of the Origin Max HTTP Version Setting.
access_api-response-common-failure
object
4 properties
4 required
cache_api-response-common
object
4 properties
4 required
email_email_setting_modified
string
The date and time the settings have been modified.
zones_browser_check
Browser Integrity Check is similar to Bad Behavior and looks for common HTTP headers abused most commonly by spammers and denies access to your page. It will a…
argo-config_api-response-common-failure
object
4 properties
4 required
dns-records_NSRecord
3 required
access_max_age
number
The maximum number of seconds the results of a preflight request can be cached.
access_api-response-common
object
4 properties
4 required
waitingroom_zone_settings
object
1 property
waitingroom_rule_expression
string
Criteria defining when there is a match for the current rule.
load-balancing_components-schemas-description
string
Object description.
zones_opportunistic_onion
Add an Alt-Svc header to all legitimate requests from Tor, allowing the connection to use our onion services instead of exit nodes.
page-shield_list-zone-policies-response
tls-certificates-and-hostnames_signature
string
The type of hash used for the certificate.
rulesets_RuleAction
string
The action to perform when the rule matches.
tls-certificates-and-hostnames_client-certificates_components-schemas-certificate_authority
object
Certificate Authority used to issue the Client Certificate
2 properties
zones_always_use_https
Reply to all requests for URLs that use "http" with a 301 redirect to the equivalent "https" URL. If you only want to redirect for a subset of requests, consid…
legacy-jhs_origin_dns_type
string
The type of DNS record associated with the origin. "" is used to specify a combination of A/AAAA records.
zones_max_upload_value
number
Value of the zone setting. Notes: The size depends on the plan level of the zone. (Enterprise = 500, Business = 200, Pro = 100, Free = 100)
access_custom_deny_message
string
The custom error message shown to a user when they are denied access to the application.
load-balancing_load-balancer_components-schemas-identifier
string
tls-certificates-and-hostnames_host
string
The keyless SSL name.
bill-subs-api_schemas-name
string
The plan name.
workers_api-response-common
object
4 properties
4 required
bill-subs-api_price
number
The price of the subscription that will be billed, in US dollars.
waitingroom_search_engine_crawler_bypass
boolean
Whether to allow verified search engine crawlers to bypass all waiting rooms on this zone. Verified search engine crawlers will not be tracked or counted by th…
api-shield_properties
array
Requests information about certain properties.
rulesets_RulePosition
object
An object configuring where the rule will be placed.
bill-subs-api_current_period_end
string
The end of the current period and also when the next billing is due.
observatory_page-test-response-single
secondary-dns_force_result
string
When forceaxfr query parameter is set to true, the response is a simple string
bot-management_enable_js
boolean
Use lightweight, invisible JavaScript detections to improve Bot Management. [Learn more about JavaScript Detections](https://developers.cloudflare.com/bots/ref…
legacy-jhs_configurations
array
A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of ip or iprange…
waitingroom_event_details_custom_page_html
string
access_schemas-custom_deny_url
string
The custom URL a user is redirected to when they are denied access to the application.
access_cors_headers
object
8 properties
dns-records_messages
array
logpush_sample
integer
The sample parameter is the sample rate of the records set by the client: "sample": 1 is 100% of records "sample": 10 is 10% and so on.
legacy-jhs_dns_type
string
The type of DNS record associated with the application.
custom-pages_custom_pages_response_single
dweb-config_identifier
string
Identifier
legacy-jhs_custom_response
object
A custom content type and reponse to return when the threshold is exceeded. The custom response configured in this object will override the custom error for th…
cache-purge_Tags
object
1 property
tls-certificates-and-hostnames_fingerprint_sha256
string
Unique identifier of the Client Certificate
observatory_trend-response
access_gsuite_group_rule
object
Matches a group in Google Workspace. Requires a Google Workspace identity provider.
1 property
1 required
bill-subs-api_install_id
string
app install id.
tls-certificates-and-hostnames_components-schemas-hostname
string
The hostname for which the tls settings are set.
rulesets_RulesRequest
array
The list of rules in the ruleset.
legacy-jhs_rewrite_action
object
Specifies that, when a WAF rule matches, its configured action will be replaced by the action configured in this object.
5 properties
argo-analytics_response_single
zones_waf
The WAF examines HTTP requests to your website. It inspects both GET and POST requests and applies rules to help filter out illegitimate traffic from legitimat…
access_include
array
Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.
access_policies_components-schemas-response_collection-2
access_schemas-id_response
tls-certificates-and-hostnames_advanced_certificate_pack_response_single
api-shield_uuid
string
UUID identifier
tls-certificates-and-hostnames_components-schemas-serial_number
string
The serial number on the created Client Certificate.
rulesets_RuleCategory
string
A category of the rule.
legacy-jhs_timeout
number
The time in seconds during which Cloudflare will perform the mitigation action. Must be an integer value greater than or equal to the period. Notes: If "mode"…
email_email_setting_status
string
Show the state of your account, and the type or configuration error.
bill-subs-api_api-response-single
object
zones_proxy_read_timeout_value
number
Value of the zone setting. Notes: Value must be between 1 and 6000
zones_cache_level
Cache Level functions based off the setting level. The basic setting will cache most static resources (i.e., css, images, and JavaScript). The simplified setti…
zones_api-response-single-id
object
zones_max_upload
Maximum size of an allowable upload.
data-zone-analytics-api_colo_response
access_device_posture_rule
object
Enforces a device posture rule has run successfully
1 property
1 required
observatory_lighthouse_error_code
string
The error code of the Lighthouse result.
api-shield_schemas-single_response
dns-custom-nameservers_api-response-collection
object
bill-subs-api_rate-plan
object
6 properties
access_schemas-organizations
object
8 properties
waitingroom_status_event_id
string
argo-config_patch
object
Update enablement of Argo Smart Routing
1 property
1 required
zones_opportunistic_encryption
Enables the Opportunistic Encryption feature for a zone.
tls-certificates-and-hostnames_certificate_authority
string
The Certificate Authority that will issue the certificate
load-balancing_api-response-single
object
dweb-config_content_list_entry_collection_response
waf-managed-rules_schemas-identifier
string
Identifier
waitingroom_patch_rule
object
5 properties
2 required
legacy-jhs_origin_traffic
boolean
When true, only the uncached traffic served from your origin servers will count towards rate limiting. In this case, any cached traffic served by Cloudflare wi…
access_schemas-saml_saas_app
object
11 properties
cache_base
object
2 properties
2 required
zones_early_hints
When enabled, Cloudflare will attempt to speed up overall page loads by serving 103 responses with Link headers from the final response. Refer to [Early Hints]…
zones_ipv6_value
string
Value of the zone setting.
api-shield_schema_upload_response
object
2 properties
1 required
data-zone-analytics-api_flag
boolean
The log retention flag for Logpull API.
zones_email_obfuscation_value
string
Value of the zone setting.
rulesets_available
boolean
When true, the Managed Transform is available in the current Cloudflare plan.
load-balancing_load-balancer_components-schemas-single_response
workers_api-response-common-failure
object
4 properties
4 required
dns-records_TLSARecord
3 required
tls-certificates-and-hostnames_ownership_verification
object
This is a record which can be placed to activate a hostname.
access_id
string
The ID of the CA.
tls-certificates-and-hostnames_enabled
boolean
Whether or not the Keyless SSL is on or off.
api-shield_api-response-single
object
zones_prefetch_preload
Cloudflare will prefetch any URLs that are included in the response headers. This is limited to Enterprise Zones.
bill-subs-api_externally_managed
boolean
Indicates whether this plan is managed externally.
legacy-jhs_paused
boolean
When true, indicates that the WAF package is currently paused.
tls-certificates-and-hostnames_base
object
10 properties
9 required
zones_schemas-api-response-common
object
4 properties
4 required
argo-analytics_messages
array
secondary-dns_api-response-common-failure
object
4 properties
4 required
zones_sort_query_string_for_cache
Cloudflare will treat files with the same query strings as the same file in cache, regardless of the order of the query strings. This is limited to Enterprise…
logpush_dataset
stringnull
Name of the dataset.
data-zone-analytics-api_api-response-common
object
4 properties
4 required
data-zone-analytics-api_timestamps
string
By default, timestamps in responses are returned as Unix nanosecond integers. The ?timestamps= argument can be set to change the format in which response times…
observatory_create-schedule-response
data-zone-analytics-api_bandwidth
object
Breakdown of totals for bandwidth in the form of bytes.
7 properties
access_schemas-bookmark_props
object
5 properties
2 required
api-shield_patch_discovery_response
argo-config_messages
array
zaraz_zaraz-history-response
waf-managed-rules_allowed_modes_allow_traditional
array
Defines the available modes for the current WAF rule.
tls-certificates-and-hostnames_hostname
string
The custom hostname that will point to your hostname via CNAME.
tls-certificates-and-hostnames_type
string
The type 'legacycustom' enables support for legacy clients which do not include SNI in the TLS handshake.
waf-managed-rules_api-response-single
object
cache-purge_Everything
object
1 property
zones_nel_value
object
Value of the zone setting.
1 property
access_any_valid_service_token_rule
object
Matches any valid Access Service Token
1 property
1 required
dns_dns_analytics_api_api-response-common-failure
object
4 properties
4 required
api-shield_collection_response_paginated
waitingroom_status
string
waf-managed-rules_api-response-collection
object
zones_ssl_value
string
Value of the zone setting. Notes: Depends on the zone's plan level
dweb-config_content_list_entries
array
Content list entries.
dns-records_tags
array
Custom tags for the DNS record. This field has no effect on DNS responses.
load-balancing_location_strategy
object
Controls location-based steering for non-proxied requests. See steeringpolicy to learn how steering is affected.
2 properties
waitingroom_waiting_room_id
page-shield_resource_id
string
The ID of the resource.
dnssec_api-response-common-failure
object
4 properties
4 required
access_schemas-onelogin
object
dns-records_base
object
11 properties
waitingroom_single_response
cache_cache_reserve_clear_end_ts
string
The time that the latest Cache Reserve Clear operation completed.
waitingroom_event_details_result
object
16 properties
rulesets_ZoneId
string
The unique ID of the zone.
waitingroom_waitingroom
object
23 properties
dweb-config_api-response-collection
object
rulesets_RulesetId
string
The unique ID of the ruleset.
cache_origin_post_quantum_encryption_value
string
Value of the Origin Post Quantum Encryption Setting.
waitingroom_disable_session_renewal
boolean
Only available for the Waiting Room Advanced subscription. Disables automatic renewal of session cookies. If true, an accepted user will have sessionduration m…
tls-certificates-and-hostnames_zone-authenticated-origin-pull_components-schemas-enabled
boolean
Indicates whether zone-level authenticated origin pulls is enabled.
dns_dns_analytics_api_dimensions
string
A comma-separated list of dimensions to group results by.
access_schemas-feature_app_props
object
6 properties
1 required
zones_mirage
Automatically optimize image loading for website visitors on mobile devices. Refer to [our blog post](http://blog.cloudflare.com/mirage2-solving-mobile-speed)…
waf-managed-rules_anomaly_rule
When triggered, anomaly detection WAF rules contribute to an overall threat score that will determine if a request is considered malicious. You can configure t…
7 required
load-balancing_components-schemas-enabled
boolean
Whether to enable (the default) this load balancer.
healthchecks_suspended
boolean
If suspended, no health checks are sent to the origin.
waitingroom_api-response-single
object
waf-managed-rules_rule_components-schemas-identifier
string
The unique identifier of the WAF rule.
access_service-tokens_components-schemas-name
string
The name of the service token.
zones_base
object
4 properties
2 required
page-shield_enabled
boolean
When true, indicates that Page Shield is enabled.
access_schemas-groups
object
7 properties
tls-certificates-and-hostnames_issuer
string
The certificate authority that issued the certificate.
legacy-jhs_package_components-schemas-status
string
When set to active, indicates that the WAF package will be applied to the zone.
logpush_schemas-destination_conf
string
Unique WebSocket address that will receive messages from Cloudflare’s edge.
access_schemas-okta
object
access_ui_read_only_toggle_reason
string
A description of the reason why the UI read only field is being toggled.
cache-purge_schemas-identifier
string
Identifier
waitingroom_api-response-collection
object
page-shield_hash
stringnull
The computed hash of the analyzed script.
waitingroom_description
string
A note that you can use to add more details about the waiting room.
rulesets_Messages
array
A list of warning messages.
dns_dns_analytics_api_messages
array
observatory_result_info
object
4 properties
tls-certificates-and-hostnames_zone-authenticated-origin-pull
object
4 properties
access_login_design
object
5 properties
zones_mobile_redirect_value
object
Value of the zone setting.
3 properties
legacy-jhs_schemas-ref
string
A short reference tag. Allows you to select related filters.
logpush_logpush_job_response_collection
legacy-jhs_egs-pagination
object
2 properties
legacy-jhs_firewall-rules_components-schemas-priority
number
The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined…
dweb-config_description
string
An optional description of the hostname.
waitingroom_event_queueing_method
stringnull
If set, the event will override the waiting room's queueingmethod property while it is active. If null, the event will inherit it.
page-shield_pageshield-policy-value
string
The policy which will be applied
legacy-jhs_threshold
number
The threshold that will trigger the configured mitigation action. Configure this value along with the period property to establish a threshold per period.
legacy-jhs_components-schemas-paused
boolean
When true, indicates that the firewall rule is currently paused.
access_allow_all_origins
boolean
Allows all origins.
tls-certificates-and-hostnames_state
string
State, provided by the CSR
zones_browser_cache_ttl
Browser Cache TTL (in seconds) specifies how long Cloudflare-cached resources will remain on your visitors' computers. Cloudflare will honor any larger times s…
dweb-config_timestamp
string
logpush_destination_exists_response
tls-certificates-and-hostnames_per_hostname_settings_response_delete
zones_challenge_ttl
Specify how long a visitor is allowed access to your site after successfully completing a challenge (such as a CAPTCHA). After the TTL has expired the visitor…
dweb-config_content_list_entry_description
string
An optional description of the content list entry.
tls-certificates-and-hostnames_keyless_private_ip
string
Private IP of the Key Server Host
legacy-jhs_rule_collection_response
access_ca
object
3 properties
legacy-jhs_ua-rules_components-schemas-description
string
An informative summary of the rule.
rulesets_UpdateRulesetRequest
bot-management_api-response-common
object
4 properties
4 required
email_rule_response_single
waf-managed-rules_description
stringnull
An informative summary of what the rule group does.
tls-certificates-and-hostnames_components-schemas-validity_days
integer
The number of days the Client Certificate will be valid after the issuedon date
cache_variants_response_value
object
1 property
tls-certificates-and-hostnames_client_certificate
object
18 properties
legacy-jhs_tls
string
The type of TLS termination associated with the application.
access_schemas-identifier
dns-records_URIRecord
4 required
tls-certificates-and-hostnames_messages
array
zones_url_target
object
URL target.
2 properties
secondary-dns_single_response_incoming
healthchecks_consecutive_fails
integer
The number of consecutive fails required from a health check before changing the health to unhealthy.
email_dns_record
object
List of records needed to enable an Email Routing zone.
5 properties
bill-subs-api_schemas-rate-plan
object
zone-activation_api-response-common-failure
object
4 properties
4 required
load-balancing_region_pools
object
A mapping of region codes to a list of pool IDs (ordered by their failover priority) for the given region. Any regions not explicitly defined will fall back to…
legacy-jhs_anomaly_detection_mode
string
When a WAF package uses anomaly detection, each rule is given a score when triggered. If the total score of all triggered rules exceeds the sensitivity defined…
secondary-dns_schemas-force_response
legacy-jhs_filter
object
5 properties
legacy-jhs_dns_ttl
integer
The TTL of our resolution of your DNS record in seconds.
api-shield_auth_id_tokens
integer
The total number of auth-ids seen across this calculation.
api-shield_collection_response
zones_origin_error_page_pass_thru_value
string
Value of the zone setting.
access_oidc_saas_app
object
11 properties
zones_schemas-api-response-single-id
object
dnssec_ds
stringnull
Full DS record.
legacy-jhs_urls
array
The URLs to include in the current WAF override. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildca…
api-shield_validation_default_mitigation_action_patch
stringnull
The default mitigation action used when there is no mitigation action defined on the operation Mitigation actions are as follows: log - log request when reques…
legacy-jhs_firewalluablock_response_collection
bot-management_sbfm_likely_config
waf-managed-rules_mode_anomaly
string
When set to on, the current WAF rule will be used when evaluating the request. Applies to anomaly detection WAF rules.
api-shield_schema_upload_log_event
object
3 properties
1 required
cache_cache_reserve_clear_response_value
object
1 property
access_duration
string
The duration for how long the service token will be valid. Must be in the format 300ms or 2h45m. Valid time units are: ns, us (or µs), ms, s, m, h. The default…
api-shield_method
string
The HTTP method used to access the endpoint.
access_public_key
string
The public key to add to your SSH server configuration.
data-zone-analytics-api_datacenters
array
A breakdown of all dashboard analytics data by co-locations. This is limited to Enterprise zones only.
zones_challenge_ttl_value
number
Value of the zone setting.
dns-records_SMIMEARecord
3 required
legacy-jhs_lockdowns_components-schemas-id
string
The unique identifier of the Zone Lockdown rule.
legacy-jhs_filter-rules-response-collection
access_apps_components-schemas-response_collection-2
dweb-config_api-response-single
object
tls-certificates-and-hostnames_certificate_response_id_only
tls-certificates-and-hostnames_certificate_pack_response_collection
cache_cache_reserve_value
string
Value of the Cache Reserve zone setting.
tls-certificates-and-hostnames_setting_id
string
The TLS Setting name.
data-zone-analytics-api_timeseries
array
Time deltas containing metadata about each bucket of time. The number of buckets (resolution) is determined by the amount of time between the since and until p…
zones_security_header
Cloudflare security header for a zone.
page-shield_pageshield-policy-description
string
A description for the policy
observatory_uuid
string
UUID
secondary-dns_disable_transfer_result
string
The zone transfer status of a primary zone
waitingroom_rule_position
object
Reorder the position of a rule
email_result_info
object
4 properties
api-shield_discovery_operation
object
zones_orange_to_orange
Orange to Orange (O2O) allows zones on Cloudflare to CNAME to other zones also on Cloudflare.
legacy-jhs_components-schemas-action
string
The action to apply to a matched request. The log action is only available on an Enterprise plan.
bill-subs-api_is_subscribed
boolean
Indicates whether you are currently subscribed to this plan.
tls-certificates-and-hostnames_client-certificates_components-schemas-status
Client Certificates may be active or revoked, and the pendingreactivation or pendingrevocation represent in-progress asynchronous transitions
api-shield_validation_override_mitigation_action_patch
stringnull
When set, this overrides both zone level and operation level mitigation actions. - none will skip running schema validation entirely for the request To clear a…
dweb-config_api-response-common-failure
object
4 properties
4 required
speed_api-response-common-failure
object
4 properties
4 required
zones_email_obfuscation
Encrypt email adresses on your web page from bots, while keeping them visible to humans. (https://support.cloudflare.com/hc/en-us/articles/200170016).
zones_targets
array
The rule targets to evaluate on each request.
access_allowed_idps
array
The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.
page-shield_update-zone-settings-response
object
4 properties
waitingroom_event_response
access_schemas-name
string
The name of the identity provider, shown to users on the login page.
argo-analytics_api-response-common
object
4 properties
4 required
custom-pages_api-response-single
object
legacy-jhs_schemas-response_single
tls-certificates-and-hostnames_sslpost
object
SSL properties used when creating the custom hostname.
tls-certificates-and-hostnames_result_info
object
4 properties
legacy-jhs_ref
string
A short reference tag. Allows you to select related firewall rules.
legacy-jhs_ssl-recommender_components-schemas-value
string
bill-subs-api_rate_plan
object
The rate plan applied to the subscription.
7 properties
cache_cache_reserve_clear_state
string
The current state of the Cache Reserve Clear operation.
access_app_launcher_visible
boolean
Displays the application in the App Launcher.
waitingroom_messages
array
access_auth_domain
string
The unique subdomain assigned to your Zero Trust organization.
tls-certificates-and-hostnames_policy
string
Specify the policy that determines the region where your private key will be held locally. HTTPS connections to any excluded data center will still be fully en…
zones_prefetch_preload_value
string
Value of the zone setting.
bot-management_config_single
object
page-shield_connection
object
10 properties
observatory_trend
object
8 properties
zones_true_client_ip_header_value
string
Value of the zone setting.
snippets-api_messages
array
zones_always_online
When enabled, Cloudflare serves limited copies of web pages available from the [Internet Archive's Wayback Machine](https://archive.org/web/) if your server is…
zones_api-response-common
object
3 properties
3 required
access_require
array
Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.
legacy-jhs_override_response_single
load-balancing_api-response-common-failure
object
4 properties
4 required
api-shield_api-response-collection
object
zone-activation_api-response-single
object
waitingroom_api-response-common-failure
object
4 properties
4 required
access_approval_required
boolean
Requires the user to request access from an administrator at the start of each session.
tls-certificates-and-hostnames_uploaded_on
string
When the certificate was uploaded to Cloudflare.
access_schemas-pingone
object
legacy-jhs_origin_dns
object
The name and type of DNS record for the Spectrum application.
3 properties
legacy-jhs_ratelimit_response_collection
secondary-dns_force_response
observatory_identifier
string
Identifier
email_update_rule_properties
object
5 properties
2 required
dns-custom-nameservers_api-response-common-failure
object
4 properties
4 required
bill-subs-api_component_values
array
The list of add-ons subscribed to.
access_schemas-aud
string
Audience tag.
zaraz_identifier
string
Identifier
waitingroom_event_prequeue_start_time
stringnull
An ISO 8601 timestamp that marks when to begin queueing all users before the event starts. The prequeue must start at least five minutes before eventstarttime.
data-zone-analytics-api_logs
rulesets_schemas-response_model
object
2 properties
observatory_page_test
object
7 properties
legacy-jhs_filter-delete-response-single
waitingroom_zone_settings_response
data-zone-analytics-api_query_response
object
The exact parameters/timestamps the analytics service used to return data.
3 properties
zones_ipv6
Enable IPv6 on all subdomains that are Cloudflare enabled. (https://support.cloudflare.com/hc/en-us/articles/200168586).
zones_name
string
The domain name
bot-management_auto_update_model
boolean
Automatically update to the newest bot detection models created by Cloudflare as they are released. [Learn more.](https://developers.cloudflare.com/bots/refere…
healthchecks_name
string
A short name to identify the health check. Only alphanumeric characters, hyphens and underscores are allowed.
bill-subs-api_api-response-collection
object
dweb-config_target
string
Target gateway of the hostname.
access_domain_rule
object
Match an entire email domain.
1 property
1 required
zones_opportunistic_onion_value
string
Value of the zone setting. Notes: Default value depends on the zone's plan level.
waf-managed-rules_api-response-common
object
4 properties
4 required
dnssec_key_type
stringnull
Algorithm key type.
argo-analytics_identifier
string
Identifier
api-shield_validation_override_mitigation_action_write
stringnull
When set, this overrides both zone level and operation level mitigation actions. - none will skip running schema validation entirely for the request - null ind…
load-balancing_default_pools
array
A list of pool IDs ordered by their failover priority. Pools defined here are used by default, or when regionpools are not configured for a given region.
email_update_catch_all_rule_properties
object
4 properties
2 required
waf-managed-rules_mode_allow_traditional
string
When set to on, the current rule will be used when evaluating the request. Applies to traditional (allow) WAF rules.
legacy-jhs_rate-limits_components-schemas-id
string
The unique identifier of the rate limit.
rulesets_Errors
array
A list of error messages.
workers_kv_namespace_binding
object
3 properties
3 required
legacy-jhs_dns_name
string
The name of the DNS record associated with the application.
legacy-jhs_app_id
string
Application identifier.
legacy-jhs_ip_configuration
object
2 properties
zones_true_client_ip_header
Allows customer to continue to use True Client IP (Akamai feature) in the headers we send to the origin. This is limited to Enterprise Zones.
bill-subs-api_schemas-identifier
string
Subscription identifier tag.
legacy-jhs_rate-limits
object
cache-purge_Hosts
object
1 property
legacy-jhs_filter-rules-response-collection-delete
bot-management_fight_mode
boolean
Whether to enable Bot Fight Mode.
zones_api-response-single
object
healthchecks_result_info
object
4 properties
zones_sort_query_string_for_cache_value
string
Value of the zone setting.
legacy-jhs_asn_configuration
object
2 properties
access_groups_components-schemas-single_response
bill-subs-api_frequency
string
How often the subscription is renewed automatically.
tls-certificates-and-hostnames_name_write
string
The keyless SSL name.
legacy-jhs_match
object
Determines which traffic the rate limit counts towards the threshold.
waitingroom_estimated_queued_users
integer
rulesets_RulesetPhase
string
The phase of the ruleset.
dweb-config_content_list_update_request
object
2 properties
2 required
waf-managed-rules_api-response-common-failure
object
4 properties
4 required
data-zone-analytics-api_since
The (inclusive) beginning of the requested time frame. This value can be a negative integer representing the number of minutes in the past relative to time the…
zones_automatic_platform_optimization
object
6 properties
6 required
dns_dns_analytics_api_api-response-common
object
4 properties
4 required
tls-certificates-and-hostnames_expired_on
string
Date that the Client Certificate expires
tls-certificates-and-hostnames_hostname-authenticated-origin-pull_components-schemas-certificate
string
The hostname certificate.
healthchecks_identifier
string
Identifier
waf-managed-rules_traditional_allow_rule
When triggered, traditional WAF rules cause the firewall to immediately act on the request based on the rule configuration. An 'allow' rule will immediately al…
8 required
waf-managed-rules_schemas-group
object
5 required
logpush_output_options
objectnull
The structured replacement for logpulloptions. When including this field, the logpulloption field will be ignored.
12 properties
secondary-dns_api-response-common
object
4 properties
4 required
workers_schemas-pattern
string
dnssec_digest_type
stringnull
Coded type for digest algorithm.
dweb-config_result_info
object
4 properties
load-balancing_load-balancer
object
21 properties
cache_variants_value
object
Value of the zone setting.
11 properties
legacy-jhs_schemas-paused
boolean
When true, indicates that the rule is currently paused.
tls-certificates-and-hostnames_certificate_pack_response_single
dns-records_api-response-single
object
access_schemas-yandex
object
cache_schemas-value
string
Enables Tiered Cache.
zones_origin_error_page_pass_thru
Cloudflare will proxy customer error pages on any 502,504 errors on origin server instead of showing a default Cloudflare error page. This does not apply to 52…
workers_filter-response-single
email_rule_identifier
string
Routing rule identifier.
logpush_enabled
boolean
Flag that indicates if the job is enabled.
waitingroom_queueing_method
string
Sets the queueing method used by the waiting room. Changing this parameter from the default queueing method is only available for the Waiting Room Advanced sub…
legacy-jhs_argo_smart_routing
boolean
Enables Argo Smart Routing for this application. Notes: Only available for TCP applications with traffictype set to "direct".
page-shield_js_integrity_score
integernull
The integrity score of the JavaScript content.
tls-certificates-and-hostnames_customhostname
object
11 properties
dns-records_AAAARecord
3 required
cache_cache_reserve_clear
You can use Cache Reserve Clear to clear your Cache Reserve, but you must first disable Cache Reserve. In most cases, this will be accomplished within 24 hours…
access_email_list_rule
object
Matches an email address from a list.
1 property
1 required
access_schemas-saml
object
tls-certificates-and-hostnames_hostname_aop_response_collection
legacy-jhs_anomaly_description
string
A summary of the purpose/function of the WAF package.
zones_tls_client_auth
TLS Client Auth requires Cloudflare to connect to your origin server using a client certificate (Enterprise Only).
page-shield_identifier
string
Identifier
workers_filter-no-id
object
2 properties
2 required
access_allowed_headers
array
Allowed HTTP request headers.
legacy-jhs_ipv6_configuration
object
2 properties
snippets-api_snippet
object
Snippet Information
3 properties
legacy-jhs_country_configuration
object
2 properties
waf-managed-rules_allowed_modes_deny_traditional
array
The list of possible actions of the WAF rule when it is triggered.
access_organizations_components-schemas-single_response
rulesets_RuleEnabled
boolean
Whether the rule should be executed.
access_service-tokens
object
6 properties
tls-certificates-and-hostnames_geo_restrictions
object
Specify the region where your private key can be held locally for optimal TLS performance. HTTPS connections to any excluded data center will still be fully en…
1 property
email_rule_priority
number
Priority of the routing rule.
zones_browser_check_value
string
Value of the zone setting.
tls-certificates-and-hostnames_universal
object
1 property
legacy-jhs_content_type
string
The content type of the body. Must be one of the following: text/plain, text/xml, or application/json.
tls-certificates-and-hostnames_uuidObject
object
1 property
tls-certificates-and-hostnames_keyless_response_collection
zones_always_online_value
string
Value of the zone setting.
legacy-jhs_rules
object
An object that allows you to override the action of specific WAF rules. Each key of this object must be the ID of a WAF rule, and each value must be a valid WA…
tls-certificates-and-hostnames_schemas-certificateObject
object
8 properties
secondary-dns_time
string
The time for a specific event.
page-shield_api-response-common
object
4 properties
4 required
dns-records_ARecord
3 required
waitingroom_default_template_language
string
The language of the default page template. If no defaulttemplatelanguage is provided, then en-US (English) will be used.
tls-certificates-and-hostnames_schemas-hosts
array
Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty.
email_email_setting_created
string
The date and time the settings have been created.
observatory_api-response-common-failure
object
4 properties
4 required
legacy-jhs_package_components-schemas-description
string
A summary of the purpose/function of the WAF package.
zones_hotlink_protection_value
string
Value of the zone setting.
access_components-schemas-id_response
legacy-jhs_schemas-configuration
object
The rule configuration.
access_identity-providers_components-schemas-single_response
zones_brotli_value
string
Value of the zone setting.
zones_hotlink_protection
When enabled, the Hotlink Protection option ensures that other sites cannot suck up your bandwidth by building pages that use images hosted on your site. Anyti…
page-shield_pageshield-policy
object
6 properties
zones_tls_1_2_only_value
string
Value of the zone setting.
data-zone-analytics-api_api-response-single
object
legacy-jhs_messages
array
load-balancing_messages
array
tls-certificates-and-hostnames_components-schemas-certificate_response_single
data-zone-analytics-api_bandwidth_by_colo
object
Breakdown of totals for bandwidth in the form of bytes.
3 properties
api-shield_api-response-common-failure
object
4 properties
4 required
waitingroom_preview_response
zones_minify
Automatically minify certain assets for your website. Refer to [Using Cloudflare Auto Minify](https://support.cloudflare.com/hc/en-us/articles/200168196) for m…
waitingroom_rule_id
string
The ID of the rule.
legacy-jhs_id
string
Identifier of a recommedation result.
dns-records_LOCRecord
3 required
cache_cache_reserve_response_value
object
1 property
load-balancing_pop_pools
object
(Enterprise only): A mapping of Cloudflare PoP identifiers to a list of pool IDs (ordered by their failover priority) for the PoP (datacenter). Any PoPs not ex…
zones_webp
When the client requesting the image supports the WebP image codec, and WebP offers a performance advantage over the original image format, Cloudflare will ser…
access_decision
string
The action Access will take if a user matches this policy.
zones_zone_settings_response_single
healthchecks_api-response-collection
object
zones_automatic_https_rewrites_value
string
Value of the zone setting. Notes: Default value depends on the zone's plan level.
data-zone-analytics-api_dashboard_response
access_access_group_rule
object
Matches an Access group.
1 property
1 required
access_everyone_rule
object
Matches everyone.
1 property
1 required
snippets-api_rules
array
List of snippet rules
custom-pages_state
string
The custom page state.
legacy-jhs_firewall-rules_components-schemas-id
string
The unique identifier of the firewall rule.
dns-custom-nameservers_api-response-common
object
4 properties
4 required
zones_security_level_value
string
Value of the zone setting.
healthchecks_timeout
integer
The timeout (in seconds) before marking the health check as failed.
tls-certificates-and-hostnames_validation_method_definition
string
Desired validation method.
access_same_site_cookie_attribute
string
Sets the SameSite cookie setting, which provides increased security against CSRF attacks.
speed_cloudflare_fonts_value
string
Whether the feature is enabled or disabled.
legacy-jhs_expression
string
The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/).
observatory_count-response
tls-certificates-and-hostnames_per_hostname_settings_response_collection
dweb-config_content_list_entry
object
Content list entry to be blocked.
6 properties
access_user_seat_expiration_inactive_time
string
The amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and…
bot-management_messages
array
legacy-jhs_components-schemas-configuration
object
The configuration object for the current rule.
2 properties
page-shield_api-response-collection
object
dns-records_NAPTRRecord
3 required
cache_variants
Variant support enables caching variants of images with certain file extensions in addition to the original. This only applies when the origin server sends the…
access_approval_group
object
A group of email addresses that can approve a temporary authentication request.
3 properties
1 required
rulesets_RulesetsResponse
array
A list of rulesets. The returned information will not include the rules in each ruleset.
waitingroom_next_event_start_time
stringnull
An ISO 8601 timestamp that marks when the next event will start.
email_dns_settings_response_collection
zones_http3_value
string
Value of the HTTP3 setting.
access_schemas-apps
object
access_schemas-saas_props
object
7 properties
legacy-jhs_action_mode
string
The default action performed by the rules in the WAF package.
dnssec_api-response-common
object
4 properties
4 required
access_service-tokens_components-schemas-single_response
custom-pages_identifier
string
Identifier
zones_h2_prioritization
HTTP/2 Edge Prioritization optimises the delivery of resources served through HTTP/2 to improve page load performance. It also supports fine control of content…
observatory_lighthouse_report
object
The Lighthouse report.
12 properties
access_allow_all_methods
boolean
Allows all HTTP request methods.
tls-certificates-and-hostnames_uuid
string
The DCV Delegation unique identifier.
rulesets_id
string
Human-readable identifier of the Managed Transform.
waitingroom_query_event
object
13 properties
3 required
zones_0rtt_value
string
Value of the 0-RTT setting.
rulesets_Message
object
A message.
3 properties
1 required
legacy-jhs_edge_ips
The anycast edge IP configuration for the hostname of this application.
waf-managed-rules_messages
array
access_identifier
string
Identifier
healthchecks_consecutive_successes
integer
The number of consecutive successes required from a health check before changing the health to healthy.
tls-certificates-and-hostnames_validation_method
string
Validation Method selected for the order.
page-shield_result_info
object
4 properties
api-shield_single_response
waf-managed-rules_default_mode
The default action/mode of a rule.
tls-certificates-and-hostnames_ownership_verification_http
object
This presents the token to be served by the given http url to activate a hostname.
access_schemas-centrify
object
dns-records_comment
string
Comments or notes about the DNS record. This field has no effect on DNS responses.
tls-certificates-and-hostnames_schemas-certificate
string
The zone's SSL certificate or SSL certificate and intermediate(s).
dns-records_page
number
Page number of paginated results.
waitingroom_response_collection
healthchecks_retries
integer
The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately.
zones_ip_geolocation_value
string
Value of the zone setting.
access_ca_components-schemas-response_collection
custom-pages_url
string
The URL associated with the custom page.
healthchecks_address
string
The hostname or IP address of the origin server to run health checks on.
api-shield_p90
integer
The p90 quantile of requests (in periodseconds).
legacy-jhs_ratelimit_response_single
dnssec_api-response-single
object
tls-certificates-and-hostnames_delete_advanced_certificate_pack_response_single
tls-certificates-and-hostnames_hostname_post
string
The custom hostname that will point to your hostname via CNAME.
waitingroom_max_estimated_time_minutes
integer
legacy-jhs_ip_range_search
string
A single IP address range to search for in existing rules.
legacy-jhs_ua-rules
object
tls-certificates-and-hostnames_api-response-single
object
zaraz_zaraz-config-return
tls-certificates-and-hostnames_cert_id
string
Certificate identifier tag.
zones_pseudo_ipv4_value
string
Value of the Pseudo IPv4 setting.
rulesets_RulesetVersion
string
The version of the ruleset.
api-shield_kind
string
Kind of schema
bot-management_sbfm_definitely_automated
string
Super Bot Fight Mode (SBFM) action to take on definitely automated requests.
dns_dns_analytics_api_api-response-single
object
zones_http2
HTTP2 enabled for this zone.
bill-subs-api_schemas-frequency
string
The frequency at which you will be billed for this plan.
access_fingerprint
string
The MD5 fingerprint of the certificate.
observatory_schedule-response-single
email_rule_catchall-actions
array
List actions for the catch-all routing rule.
api-shield_public_schema
object
6 properties
4 required
dnssec_dnssec
object
13 properties
workers_binding_name
string
A JavaScript variable name for the binding.
waitingroom_event_response_collection
bill-subs-api_zone
object
A simple zone object. May have null properties if not a zone subscription.
2 properties
legacy-jhs_package_components-schemas-identifier
string
The unique identifier of a WAF package.
workers_routes
object
3 properties
3 required
email_create_rule_properties
object
5 properties
2 required
bill-subs-api_component-value
object
3 properties
access_certificates_components-schemas-name
string
The name of the certificate.
waitingroom_total_active_users
integer
Sets the total number of active user sessions on the route at a point in time. A route is a combination of host and path on which a waiting room is available.…
zones_cname_flattening
Whether or not cname flattening is on.
cache_api-response-common-failure
object
4 properties
4 required
zones_schemas-identifier
string
Identifier
zones_minify_value
object
Value of the zone setting.
3 properties
tls-certificates-and-hostnames_advanced_type
string
Type of certificate pack.
tls-certificates-and-hostnames_schemas-status
string
Status of the Keyless SSL.
data-zone-analytics-api_requests_by_colo
object
Breakdown of totals for requests.
5 properties
api-shield_api_discovery_patch_multiple_request
object
dweb-config_content_list_details
object
1 property
api-shield_zone_schema_validation_settings_patch
object
2 properties
access_service_token_rule
object
Matches a specific Access Service Token
1 property
1 required
rulesets_CreateOrUpdateRuleRequest
page-shield_list-zone-scripts-response
page-shield_pageshield-policy-expression
string
The expression which must match for the policy to be applied, using the Cloudflare Firewall rule expression syntax
access_schemas-linkedin
object
legacy-jhs_dns
object
The name and type of DNS record for the Spectrum application.
2 properties
bill-subs-api_can_subscribe
boolean
Indicates whether you can subscribe to this plan.
api-shield_suggested_threshold
integer
The suggested threshold in requests done by the same authid or periodseconds.
cache_cache_reserve
Increase cache lifetimes by automatically storing all cacheable files into Cloudflare's persistent object storage buckets. Requires Cache Reserve subscription.…
waf-managed-rules_rule_group_response_single
load-balancing_result_info
object
4 properties
email_rule_enabled
boolean
Routing rule status.
snippets-api_snippet_name
string
Snippet identifying name
dns_dns_analytics_api_query
object
7 properties
5 required
email_email_settings_response_single
access_precedence
integer
The order of execution for this policy. Must be unique for each policy.
data-zone-analytics-api_api-response-common-failure
object
4 properties
4 required
dns_dns_analytics_api_until
string
End date and time of requesting data period in ISO 8601 format.
bill-subs-api_component_value
object
A component value for a subscription.
4 properties
cache_schemas-patch
object
Update enablement of Smart Tiered Cache
1 property
1 required
argo-analytics_api-response-single
object
zones_result_info
object
4 properties
waitingroom_rule_enabled
boolean
When set to true, the rule is enabled.
secondary-dns_name
string
Zone name.
api-shield_patch_discoveries_response
data-zone-analytics-api_totals_by_colo
object
Breakdown of totals by data type.
5 properties
email_api-response-common
object
4 properties
4 required
workers_route-response-collection
logpush_instant_logs_job
objectnull
5 properties
tls-certificates-and-hostnames_custom_origin_sni
string
A hostname that will be sent to your custom origin server as SNI for TLS handshake. This can be a valid subdomain of the zone or custom origin server name or t…
zones_0rtt
0-RTT session resumption enabled for this zone.
tls-certificates-and-hostnames_verification_errors
array
These are errors that were encountered while trying to activate a hostname.
waf-managed-rules_name
string
The name of the rule group.
access_azure_group_rule
object
Matches an Azure group. Requires an Azure identity provider.
1 property
1 required
legacy-jhs_schemas-filters
object
5 properties
waitingroom_event_description
string
A note that you can use to add more details about the event.
legacy-jhs_components-schemas-modified_on
string
The timestamp of when the rule was last modified.
tls-certificates-and-hostnames_hostname-authenticated-origin-pull_components-schemas-enabled
booleannull
Indicates whether hostname-level authenticated origin pulls is enabled. A null value voids the association.
custom-pages_custom_pages_response_collection
data-zone-analytics-api_sample
number
When ?sample= is provided, a sample of matching records is returned. If sample=0.1 then 10% of records will be returned. Sampling is random: repeated calls wil…
dns-records_result_info
object
4 properties
tls-certificates-and-hostnames_settingObjectDelete
object
5 properties
api-shield_operation_features
object
dnssec_digest
stringnull
Digest hash.
healthchecks_api-response-single
object
access_logo_url
string
The image URL for the logo shown in the App Launcher dashboard.
legacy-jhs_common_components-schemas-identifier
string
Identifier
zones_edge_cache_ttl_value
number
Value of the zone setting. Notes: The minimum TTL available depends on the plan level of the zone. (Enterprise = 30, Business = 1800, Pro = 3600, Free = 7200)
tls-certificates-and-hostnames_verification_info
object
Certificate's required verification information.
2 properties
access_certificates_components-schemas-single_response
zones_min_tls_version_value
string
Value of the zone setting.
dnssec_public_key
stringnull
Public key for DS record.
email_rule_catchall-matchers
array
List of matchers for the catch-all routing rule.
zones_response_buffering
Enables or disables buffering of responses from the proxied server. Cloudflare may buffer the whole payload to deliver it at once to the client versus allowing…
dns-records_api-response-common
object
4 properties
4 required
access_name
string
The name of your Zero Trust organization.
access_service_auth_401_redirect
boolean
Returns a 401 status code when the request is blocked by a Service Auth policy.
dweb-config_api-response-common
object
4 properties
4 required
bill-subs-api_messages
array
bot-management_identifier
string
Identifier
legacy-jhs_proxy_protocol
string
Enables Proxy Protocol to the origin. Refer to [Enable Proxy protocol](https://developers.cloudflare.com/spectrum/getting-started/proxy-protocol/) for implemen…
argo-config_value
string
Enables Argo Smart Routing.
access_apps_components-schemas-name
string
The name of the application.
tls-certificates-and-hostnames_zone-authenticated-origin-pull_components-schemas-certificate
string
The zone's leaf certificate.
waitingroom_query_waitingroom
object
18 properties
4 required
zones_ssl_recommender_enabled
boolean
ssl-recommender enrollment setting.
tls-certificates-and-hostnames_per_hostname_settings_response
zones_early_hints_value
string
Value of the zone setting.
access_result_info
object
4 properties
dweb-config_dnslink
string
DNSLink value used if the target is ipfs.
logpush_destination_conf
string
Uniquely identifies a resource (such as an s3 bucket) where data will be pushed. Additional configuration parameters supported by the destination may be includ…
legacy-jhs_schemas-filter-response-collection
api-shield_parameter_schemas_definition
object
An operation schema object containing a response.
2 properties
observatory_messages
array
dns-records_SSHFPRecord
3 required
dnssec_digest_algorithm
stringnull
Type of digest algorithm.
tls-certificates-and-hostnames_api-response-common-failure
object
4 properties
4 required
waitingroom_cookie_attributes
object
Configures cookie attributes for the waiting room cookie. This encrypted cookie stores a user's status in the waiting room, such as queue position.
2 properties
legacy-jhs_sensitivity
string
The sensitivity of the WAF package.
legacy-jhs_schemas-action
object
The action to perform when the threshold of matched traffic within the configured period is exceeded.
legacy-jhs_protocol
string
The port configuration at Cloudflare’s edge. May specify a single port, for example "tcp/1000", or a range of ports, for example "tcp/1000-2000".
waitingroom_event_details_new_users_per_minute
integer
dnssec_dnssec_multi_signer
boolean
If true, multi-signer DNSSEC is enabled on the zone, allowing multiple providers to serve a DNSSEC-signed zone at the same time. This is required for DNSKEY re…
cache-purge_Prefixes
object
1 property
api-shield_zone_schema_validation_settings
object
2 properties
api-shield_name
string
The name of the characteristic field, i.e., the header or cookie name.
tls-certificates-and-hostnames_hostname-authenticated-origin-pull_components-schemas-certificate_response_collection
legacy-jhs_firewalluablock
object
5 properties
rulesets_enabled
boolean
When true, the Managed Transform is enabled.
access_identity-providers_components-schemas-response_collection
object
api-shield_openapiwiththresholds
object
A OpenAPI 3.0.0 compliant schema.
api-shield_api_discovery_state
string
State of operation in API Discovery review - Operation is not saved into API Shield Endpoint Management saved - Operation is saved into API Shield Endpoint Man…
tls-certificates-and-hostnames_verification_type
string
Method of verification.
dnssec_algorithm
stringnull
Algorithm key code.
api-shield_host
string
RFC3986-compliant host.
access_purpose_justification_prompt
string
A custom message that will appear on the purpose justification screen.
tls-certificates-and-hostnames_priority
number
The order/priority in which the certificate will be used in a request. The higher priority will break ties across overlapping 'legacycustom' certificates, but…
legacy-jhs_lockdowns_components-schemas-description
string
An informative summary of the rule.
legacy-jhs_origin_dns_name
string
The name of the DNS record associated with the origin.
data-zone-analytics-api_until
The (exclusive) end of the requested time frame. This value can be a negative integer representing the number of minutes in the past relative to time the reque…
zones_string_constraint
object
String constraint.
2 properties
2 required
observatory_timestamp
string
zones_created_on
string
The timestamp of when the Page Rule was created.
zones_zone
object
13 properties
12 required
zones_ssl
SSL encrypts your visitor's connection and safeguards credit card numbers and other personal data to and from your website. SSL can take up to 5 minutes to ful…
dns_dns_analytics_api_limit
integer
Limit number of returned metrics.
api-shield_operation_mitigation_action
stringnull
When set, this applies a mitigation action to this operation - log log request when request does not conform to schema for this operation - block deny access t…
observatory_url
string
A URL.
logpush_session_id
string
Unique session id of the job.
cache-purge_UrlAndHeaders
object
2 properties
access_purpose_justification_required
boolean
Require users to enter a justification when they log in to the application.
tls-certificates-and-hostnames_ssl
object
SSL properties for the custom hostname.
logpush_api-response-common-failure
object
4 properties
4 required
rulesets_response_list
array
legacy-jhs_app_id_param
string
Comma-delimited list of Spectrum Application Id(s). If provided, the response will be limited to Spectrum Application Id(s) that match.
dnssec_flags
numbernull
Flag for DNSSEC record.
dnssec_dnssec_presigned
boolean
If true, allows Cloudflare to transfer in a DNSSEC-signed zone including signatures from an external provider, without requiring Cloudflare to sign any records…
bot-management_sbfm_static_resource_protection
boolean
Super Bot Fight Mode (SBFM) to enable static resource protection. Enable if static resources on your application need bot protection. Note: Static resource pro…
zones_sha1_support_value
string
Value of the zone setting.
snippets-api_api-response-common-failure
object
4 properties
4 required
healthchecks_api-response-common-failure
object
4 properties
4 required
legacy-jhs_package_response_collection
zones_page-rule
object
7 properties
7 required
data-zone-analytics-api_timeseries_by_colo
array
Time deltas containing metadata about each bucket of time. The number of buckets (resolution) is determined by the amount of time between the since and until p…
healthchecks_healthchecks
object
18 properties
legacy-jhs_schemas-description_search
string
A string to search for in the description of existing rules.
logpush_logpush_job_response_single
legacy-jhs_header_value
string
The value of the response header, which must match exactly.
waitingroom_event_new_users_per_minute
integernull
If set, the event will override the waiting room's newusersperminute property while it is active. If null, the event will inherit it. This can only be set if t…
zaraz_zaraz-workflow
string
Zaraz workflow
legacy-jhs_lockdowns_components-schemas-priority
number
The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will…
waf-managed-rules_base
object
5 properties
legacy-jhs_disabled
boolean
When true, indicates that the rate limit is currently disabled.
healthchecks_description
string
A human-readable description of the health check.
access_groups_components-schemas-response_collection
cache_patch
object
Update enablement of Tiered Caching
1 property
1 required
legacy-jhs_anomaly_name
string
The name of the WAF package.
access_github_organization_rule
object
Matches a Github organization. Requires a Github identity provider.
1 property
1 required
legacy-jhs_traffic_type
string
Determines how data travels from the edge to your origin. When set to "direct", Spectrum will send traffic directly to your origin, and the application's type…
zones_image_resizing
Image Resizing provides on-demand resizing, conversion and optimisation for images served through Cloudflare's network. Refer to the [Image Resizing documentat…
waitingroom_queueing_status_code
integer
HTTP status code returned to a user while in the queue.
speed_identifier
string
Identifier
bill-subs-api_unit_price
number
The unit price of the addon.
dns-records_ttl
number
Time To Live (TTL) of the DNS record in seconds. Setting to 1 means 'automatic'. Value must be between 60 and 86400, with the minimum reduced to 30 for Enterpr…
dns-records_MXRecord
4 required
load-balancing_proxied
boolean
Whether the hostname should be gray clouded (false) or orange clouded (true).
access_enable_binding_cookie
boolean
Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.
secondary-dns_dns-secondary-secondary-zone
object
4 properties
4 required
zones_schemas-api-response-common-failure
object
4 properties
4 required
cache-purge_Files
object
1 property
zones_pseudo_ipv4
The value set for the Pseudo IPv4 setting.
api-shield_configuration
object
1 property
legacy-jhs_schemes
array
The HTTP schemes to match. You can specify one scheme (['HTTPS']), both schemes (['HTTP','HTTPS']), or all schemes (['ALL']). This field is optional.
healthchecks_response_collection
zones_proxy_read_timeout
Maximum time between two read operations from origin.
dweb-config_web3-hostname
object
8 properties
access_components-schemas-name
string
The name of the Access group.
tls-certificates-and-hostnames_client_certificate_response_single
zones_vanity_name_servers
array
An array of domains used for custom name servers. This is only available for Business and Enterprise plans.
legacy-jhs_origin_port
The destination port at the origin. Only specified in conjunction with origindns. May use an integer to specify a single origin port, for example 1000, or a st…
api-shield_api_discovery_origin
string
ML - Discovered operation was sourced using ML API Discovery SessionIdentifier - Discovered operation was sourced using Session Identifier API Discovery
zones_target
A request condition target.
2 required
tls-certificates-and-hostnames_schemas-validity_days
integer
The validity period in days for the certificates ordered via Total TLS.
zones_tls_1_3
Enables Crypto TLS 1.3 feature for a zone.
cache_zone_cache_settings_response_single
dweb-config_api-response-single-id
object
tls-certificates-and-hostnames_hostname_association
object
2 properties
api-shield_zone_schema_validation_settings_put
object
2 properties
1 required
api-shield_traffic_stats
object
1 property
logpush_instant_logs_job_response_single
zones_browser_cache_ttl_value
number
Value of the zone setting. Notes: Setting a TTL of 0 is equivalent to selecting Respect Existing Headers
zones_automatic_https_rewrites
Enable the Automatic HTTPS Rewrites feature for this zone.
logpush_validate_ownership_response
tls-certificates-and-hostnames_custom_origin_server
string
a valid hostname that’s been added to your DNS zone as an A, AAAA, or CNAME record.
secondary-dns_enable_transfer_result
string
The zone transfer status of a primary zone
zones_status
string
The status of the Page Rule.
rulesets_request_model
object
2 properties
tls-certificates-and-hostnames_modified_on
string
When the certificate was last modified.
zaraz_api-response-common-failure
object
4 properties
4 required
waitingroom_session_duration
integer
Lifetime of a cookie (in minutes) set by Cloudflare for users who get access to the route. If a user is not seen by Cloudflare again in that time period, they…
tls-certificates-and-hostnames_hostname_certid_object
object
14 properties
tls-certificates-and-hostnames_custom_hostname_response_collection
dweb-config_name
string
The hostname that will point to the target gateway via CNAME.
bot-management_optimize_wordpress
boolean
Whether to optimize Super Bot Fight Mode protections for Wordpress.
dns-custom-nameservers_result_info
object
4 properties
legacy-jhs_package_definition
object
6 properties
5 required
waf-managed-rules_mode_deny_traditional
string
The action that the current WAF rule will perform when triggered. Applies to traditional (deny) WAF rules.
tls-certificates-and-hostnames_validation_record
object
Certificate's required validation record.
5 properties
api-shield_type
string
The type of characteristic.
tls-certificates-and-hostnames_common_name
string
Common Name of the Client Certificate
zones_polish
Removes metadata and compresses your images for faster page load times. Basic (Lossless): Reduce the size of PNG, JPEG, and GIF files - no impact on visual qua…
observatory_api-response-collection
object
zones_server_side_exclude
If there is sensitive content on your website that you want visible to real visitors, but that you want to hide from suspicious visitors, all you have to do is…
email_identifier
string
Identifier
waitingroom_schemas-api-response-common
object
4 properties
4 required
legacy-jhs_firewall-rules_components-schemas-description
string
An informative summary of the firewall rule.
tls-certificates-and-hostnames_sslsettings
object
SSL specific settings.
5 properties
legacy-jhs_rule_single_response
waitingroom_event_shuffle_at_event_start
boolean
If enabled, users in the prequeue will be shuffled randomly at the eventstarttime. Requires that prequeuestarttime is not null. This is useful for situations w…
cache_origin_max_http_version_response_value
object
1 property
bot-management_sbfm_verified_bots
string
Super Bot Fight Mode (SBFM) action to take on verified bots requests.
waitingroom_event_details_queueing_method
string
rulesets_identifier
string
Identifier
page-shield_get-zone-script-response
access_country_rule
object
Matches a specific country
1 property
1 required
bill-subs-api_legacy_discount
boolean
Indicates whether this plan has a legacy discount applied.
access_email_rule
object
Matches a specific email.
1 property
1 required
bill-subs-api_available-rate-plan
object
10 properties
zones_polish_value
string
Value of the zone setting.
dns-records_DNSKEYRecord
3 required
tls-certificates-and-hostnames_bundle_method
string
A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses th…
access_generic-oauth-config
object
2 properties
zones_response_buffering_value
string
Value of the zone setting.
tls-certificates-and-hostnames_components-schemas-uploaded_on
string
The time when the certificate was uploaded.
waitingroom_event_disable_session_renewal
booleannull
If set, the event will override the waiting room's disablesessionrenewal property while it is active. If null, the event will inherit it.
access_schemas-identity-providers
tls-certificates-and-hostnames_validity_days
integer
Validity Days selected for the order.
api-shield_validation_override_mitigation_action
stringnull
When set, this overrides both zone level and operation level mitigation actions. - none will skip running schema validation entirely for the request - null ind…
load-balancing_load-balancer_components-schemas-response_collection
bill-subs-api_identifier
string
Identifier
waitingroom_event_id_response
legacy-jhs_description_search
string
A string to search for in the description of existing rules.
workers_api-response-single-id
object
email_rule_catchall-matcher
object
Matcher for catch-all routing rule.
1 property
1 required
dweb-config_status
string
Status of the hostname's activation.
page-shield_pageshield-policy-enabled
boolean
Whether the policy is enabled
legacy-jhs_filters_components-schemas-paused
boolean
When true, indicates that the filter is currently paused.
tls-certificates-and-hostnames_custom-hostname
object
3 properties
3 required
api-shield_operation_feature_thresholds
object
1 property
9 required
legacy-jhs_filter-rule-base
object
7 properties
bill-subs-api_subscription-v2
object
11 properties
page-shield_use_cloudflare_reporting_endpoint
boolean
When true, CSP reports will be sent to https://csp-reporting.cloudflare.com/cdn-cgi/scriptmonitor/report
legacy-jhs_created
string
When the Application was created.
waf-managed-rules_rule
object
legacy-jhs_rule_components-schemas-identifier
string
The unique identifier of the IP Access rule.
waitingroom_event_start_time
string
An ISO 8601 timestamp that marks the start of the event. At this time, queued users will be processed with the event's configuration. The start time must be at…
load-balancing_api-response-collection
object
tls-certificates-and-hostnames_location
string
Location, provided by the CSR
waitingroom_new_users_per_minute
integer
Sets the number of new users that will be let into the route every minute. This value is used as baseline for the number of users that are let in per minute. S…
zones_advanced_ddos
Advanced protection from Distributed Denial of Service (DDoS) attacks on your website. This is an uneditable value that is 'on' in the case of Business and Ent…
data-zone-analytics-api_dashboard
object
Totals and timeseries data.
2 properties
bill-subs-api_current_period_start
string
When the current billing period started. May match initialperiodstart if this is the first period.
page-shield_zone_settings_response_single
waf-managed-rules_rules_count
number
The number of rules in the current rule group.
legacy-jhs_delete_filter_if_unused
boolean
When true, indicates that Cloudflare should also delete the associated filter if there are no other firewall rules referencing the filter.
zones_actions
array
The set of actions to perform if the targets of this rule match the request. Actions can redirect to another URL or override settings, but not both.
bill-subs-api_zone_subscription_response_single
legacy-jhs_filter-rules-single-response
dns_dns_analytics_api_filters
string
Segmentation filter in 'attribute operator value' format.
waitingroom_rule_action
string
The action to take when the expression matches.
observatory_availabilities-response
access_schemas-empty_response
dns-records_HTTPSRecord
3 required
observatory_labeled_region
object
A test region with a label.
2 properties
waitingroom_json_response_enabled
boolean
Only available for the Waiting Room Advanced subscription. If true, requests to the waiting room with the header Accept: application/json will receive a JSON r…
logpush_logpush_field_response_collection
legacy-jhs_schemas-filter-response-single
tls-certificates-and-hostnames_fallback_origin_response
rulesets_api-response-common-failure
object
4 properties
4 required
zones_type
string
A full zone implies that DNS is hosted with Cloudflare. A partial zone is typically a partner-hosted zone or a CNAME setup.
tls-certificates-and-hostnames_config
array
access_allow_all_headers
boolean
Allows all HTTP request headers.
tls-certificates-and-hostnames_custom-certificate
object
14 properties
11 required
rulesets_schemas-request_model
object
2 properties
load-balancing_session_affinity
string
Specifies the type of session affinity the load balancer should use unless specified as "none" or "" (default). The supported types are: - "cookie": On the fir…
dnssec_delete_dnssec_response_single
legacy-jhs_filters_components-schemas-description
string
An informative summary of the filter.
legacy-jhs_body
string
The response body to return. The value must conform to the configured content type.
tls-certificates-and-hostnames_hostname_aop_single_response
tls-certificates-and-hostnames_ssl_universal_settings_response
access_schemas-onetimepin
object
access_schemas-self_hosted_props
object
16 properties
2 required
waitingroom_identifier
string
Identifier
access_client_secret
string
The Client Secret for the service token. Access will check for this value in the CF-Access-Client-Secret request header.
observatory_device_type
string
The type of device.
tls-certificates-and-hostnames_hostname-authenticated-origin-pull_components-schemas-status
Status of the certificate or the association.
email_catch_all_rule
object
6 properties
legacy-jhs_waf_rewrite_action
The WAF rule action to apply.
api-shield_period_seconds
integer
The period over which this threshold is suggested.
tls-certificates-and-hostnames_settingObject
object
5 properties
legacy-jhs_deleted-filter
object
2 properties
2 required
load-balancing_session_affinity_attributes
object
Configures attributes for session affinity.
6 properties
api-shield_schema_upload_details_warnings_only
object
1 property
waitingroom_additional_routes
array
Only available for the Waiting Room Advanced subscription. Additional hostname and path combinations to which this waiting room will be applied. There is an im…
tls-certificates-and-hostnames_keyless_response_single
tls-certificates-and-hostnames_port
number
The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server.
legacy-jhs_components-schemas-description
string
An informative summary of the rate limit. This value is sanitized and any tags will be removed.
waitingroom_create_rule
object
4 properties
2 required
access_certificates
object
7 properties
rulesets_scope
string
The scope of the URL normalization.
waitingroom_event_total_active_users
integernull
If set, the event will override the waiting room's totalactiveusers property while it is active. If null, the event will inherit it. This can only be set if th…
dns-records_name
string
DNS record name (or @ for the zone apex) in Punycode.
legacy-jhs_notes
string
An informative summary of the rule, typically used as a reminder or explanation.
dns-records_dns_response_collection
secondary-dns_id_response
workers_route-response-single
dns-records_search
string
Allows searching in multiple properties of a DNS record simultaneously. This parameter is intended for human users, not automation. Its exact behavior is inten…
tls-certificates-and-hostnames_country
string
Country, provided by the CSR
zones_mirage_value
string
Value of the zone setting.
workers_route-no-id
object
2 properties
1 required
secondary-dns_api-response-single
object
zones_identifier
string
Identifier
waitingroom_timestamp
string
waf-managed-rules_identifier
string
The unique identifier of a WAF package.
waitingroom_event_details_session_duration
integer
tls-certificates-and-hostnames_created_at
string
This is the time the hostname was created.
waitingroom_path
string
Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the s…
data-zone-analytics-api_requests
object
Breakdown of totals for requests.
8 properties
dns-records_content
string
DNS record content.
data-zone-analytics-api_threats
object
Breakdown of totals for threats.
3 properties
zones_image_resizing_value
string
Whether the feature is enabled, disabled, or enabled in open proxy mode.
logpush_filter
string
Filters to drill down into specific events.
dns-records_priority
number
Required for MX, SRV and URI records; unused by other record types. Records with lower priorities are preferred.
tls-certificates-and-hostnames_total_tls_settings_response
dweb-config_content_list_details_response
tls-certificates-and-hostnames_components-schemas-expires_on
string
When the certificate from the authority expires.
observatory_page-test-response-collection
api-shield_endpoint
string
The endpoint which can contain path parameter templates in curly braces, each will be replaced from left to right with {varN}, starting with {var1}, during ins…
tls-certificates-and-hostnames_schemas-csr
string
The Certificate Signing Request (CSR). Must be newline-encoded.
waitingroom_event_suspended
boolean
Suspends or allows an event. If set to true, the event is ignored and traffic will be handled based on the waiting room configuration.
custom-pages_result_info
object
4 properties
logpush_last_complete
stringnull
Records the last time for which logs have been successfully pushed. If the last successful push was for logs range 2018-07-23T10:00:00Z to 2018-07-23T10:01:00Z…
api-shield_characteristics
array
legacy-jhs_mode
string
The action to perform.
dweb-config_content_list_entry_content
string
CID or content path of content to block.
logpush_fields
string
Comma-separated list of fields.
tls-certificates-and-hostnames_identifier
string
Identifier
email_rule_action
object
Actions pattern.
2 properties
2 required
api-shield_schema_upload_details_errors_critical
object
2 properties
api-shield_openapi
object
A OpenAPI 3.0.0 compliant schema.
page-shield_updated_at
string
The timestamp of when Page Shield was last updated.
rulesets_ExecuteSensitivityLevel
string
dns_dns_analytics_api_time_delta
string
Unit of time to group data by.
data-zone-analytics-api_identifier
string
Identifier
rulesets_request_list
array
page-shield_messages
array
access_schemas-facebook
object
dnssec_key_tag
numbernull
Code for key tag.
zones_ip_geolocation
Enable IP Geolocation to have Cloudflare geolocate visitors to your website and pass the country code to you. (https://support.cloudflare.com/hc/en-us/articles…
access_schemas-app_launcher_props
legacy-jhs_deleted
boolean
When true, indicates that the firewall rule was deleted.
access_schemas-session_duration
string
The amount of time that tokens issued for this application will be valid. Must be in the format 300ms or 2h45m. Valid time units are: ns, us (or µs), ms, s, m,…
data-zone-analytics-api_messages
array
logpush_id
integer
Unique id of the job.
legacy-jhs_api-response-common-failure
object
4 properties
4 required
zones_api-response-common-failure
object
4 properties
4 required
legacy-jhs_api-response-single
object
page-shield_pageshield-policy-action
string
The action to take if the expression matches
dns_dns_analytics_api_identifier
string
Identifier
dns-records_order
string
Field to order DNS records by.
secondary-dns_auto_refresh_seconds
number
How often should a secondary zone auto refresh regardless of DNS NOTIFY. Not applicable for primary zones.
access_policy_check_response
page-shield_list-zone-connections-response
secondary-dns_single_response_outgoing
zones_always_use_https_value
string
Value of the zone setting.
legacy-jhs_sort
array
The sort order for the result set; sort fields must be included in metrics or dimensions.
logpush_api-response-single
object
data-zone-analytics-api_flag_response
legacy-jhs_overrides_components-schemas-description
stringnull
An informative summary of the current URI-based WAF override.
access_exclude
array
Rules evaluated with a NOT logical operator. To match a policy, a user cannot meet any of the Exclude rules.
api-shield_requests
integer
The estimated number of requests covered by these calculations.
legacy-jhs_override
object
8 properties
legacy-jhs_detection_mode
string
The mode that defines how rules within the package are evaluated during the course of a request. When a package uses anomaly detection mode (anomaly value), ea…
cache_value
string
Enables Tiered Caching.
access_schemas-biso_props
tls-certificates-and-hostnames_zone-authenticated-origin-pull_components-schemas-status
Status of the certificate activation.
email_rule_catchall-action
object
Action for the catch-all routing rule.
2 properties
1 required
zone-activation_identifier
string
Identifier
email_rule_matcher
object
Matching pattern to forward your actions.
3 properties
3 required
logpush_logpush_job
objectnull
11 properties
legacy-jhs_ip_firewall
boolean
Enables IP Access Rules for this application. Notes: Only available for TCP applications.
waitingroom_event_details_total_active_users
integer
access_schemas-isolation_required
boolean
Require this application to be served in an isolated browser for users matching this policy.
logpush_frequency
stringnull
The frequency at which Cloudflare sends batches of logs to your destination. Setting frequency to high sends your logs in larger quantities of smaller files. S…
dns-custom-nameservers_schemas-empty_response
waf-managed-rules_modified_rules_count
number
The number of rules within the group that have been modified from their default configuration.
page-shield_get-zone-connection-response
access_certificates_components-schemas-response_collection
rulesets_Ruleset
object
A ruleset object.
7 properties
3 required
tls-certificates-and-hostnames_updated_at
string
The time when the certificate was updated.
access_client_id
string
The Client ID for the service token. Access will check for this value in the CF-Access-Client-ID request header.
tls-certificates-and-hostnames_components-schemas-signature
string
The type of hash used for the Client Certificate..
tls-certificates-and-hostnames_status
Status of the zone's custom SSL.
healthchecks_type
string
The protocol to use for the health check. Currently supported protocols are 'HTTP', 'HTTPS' and 'TCP'.
tls-certificates-and-hostnames_client_certificate_response_collection
dweb-config_single_response
bot-management_suppress_session_score
boolean
Whether to disable tracking the highest bot score for a session in the Bot Management cookie.
rulesets_FailureResponse
object
A failure response object.
4 properties
4 required
access_approval_groups
array
Administrators who can approve a temporary authentication request.
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Cloudflare publishes across the network.