openapi: 3.2.0 info: description: Welcome to Cloudflare's API documentation site. license: name: BSD-3-Clause url: https://opensource.org/licenses/BSD-3-Clause title: Cloudflare Devices API version: 4.0.0 servers: - description: Client API url: https://api.cloudflare.com/client/v4 security: - api_email: [] api_key: [] - api_token: [] - user_service_key: [] tags: - name: Devices paths: /accounts/{account_id}/devices: get: operationId: devices-list-devices summary: List devices (deprecated) description: 'List WARP devices. Not supported when multi-user mode is enabled for the account. **Deprecated**: please use one of the following endpoints instead: - GET /accounts/{account_id}/devices/physical-devices - GET /accounts/{account_id}/devices/registrations' parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: List devices response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_devices_response' 4XX: description: List devices response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' deprecated: true security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-fern-availability: deprecated x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.v1 x-fern-sdk-method-name: list /accounts/{account_id}/devices/policies: get: operationId: devices-list-device-settings-policies summary: List device settings profiles description: Fetches a list of the device settings profiles for an account. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' - name: profile_type in: query description: Filter profiles by client type. When omitted, only WARP profiles are returned. schema: $ref: '#/components/schemas/teams-devices_profile_type' responses: '200': description: List device settings profiles response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_device_settings_response_collection' 4XX: description: List device settings profiles response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.devices.profiles.custom x-fern-sdk-method-name: list /accounts/{account_id}/devices/policy: get: operationId: devices-get-default-device-settings-policy summary: Get the default device settings profile description: Fetches the default device settings profile for an account. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Get the default device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_default_device_settings_response' 4XX: description: Get the default device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.devices.profiles.default x-fern-sdk-method-name: get patch: operationId: devices-update-default-device-settings-policy summary: Update the default device settings profile description: Updates the default device settings profile for an account. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: type: object properties: allow_mode_switch: $ref: '#/components/schemas/teams-devices_allow_mode_switch' allow_updates: $ref: '#/components/schemas/teams-devices_allow_updates' allowed_to_leave: $ref: '#/components/schemas/teams-devices_allowed_to_leave' auto_connect: $ref: '#/components/schemas/teams-devices_auto_connect' captive_portal: $ref: '#/components/schemas/teams-devices_captive_portal' disable_auto_fallback: $ref: '#/components/schemas/teams-devices_disable_auto_fallback' dns_search_suffixes: $ref: '#/components/schemas/teams-devices_dns_search_suffixes' exclude: $ref: '#/components/schemas/teams-devices_exclude_request' exclude_office_ips: $ref: '#/components/schemas/teams-devices_exclude_office_ips' global_acceleration: $ref: '#/components/schemas/teams-devices_global_acceleration' include: $ref: '#/components/schemas/teams-devices_include_request' lan_allow_minutes: $ref: '#/components/schemas/teams-devices_lan_allow_minutes' lan_allow_subnet_size: $ref: '#/components/schemas/teams-devices_lan_allow_subnet_size' register_interface_ip_with_dns: $ref: '#/components/schemas/teams-devices_register_interface_ip_with_dns' sccm_vpn_boundary_support: $ref: '#/components/schemas/teams-devices_sccm_vpn_boundary_support' service_mode_v2: $ref: '#/components/schemas/teams-devices_service_mode_v2' support_url: $ref: '#/components/schemas/teams-devices_support_url' switch_locked: $ref: '#/components/schemas/teams-devices_switch_locked' tunnel_protocol: $ref: '#/components/schemas/teams-devices_tunnel_protocol' uninstall_protection: $ref: '#/components/schemas/teams-devices_uninstall_protection' virtual_networks: $ref: '#/components/schemas/teams-devices_virtual_networks' responses: '200': description: Update the default device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_default_device_settings_response' 4XX: description: Update the default device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.devices.profiles.default x-fern-sdk-method-name: update post: operationId: devices-create-device-settings-policy summary: Create a device settings profile description: Creates a device settings profile to be applied to certain devices matching the criteria. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: type: object properties: allow_mode_switch: $ref: '#/components/schemas/teams-devices_allow_mode_switch' allow_updates: $ref: '#/components/schemas/teams-devices_allow_updates' allowed_to_leave: $ref: '#/components/schemas/teams-devices_allowed_to_leave' auto_connect: $ref: '#/components/schemas/teams-devices_auto_connect' browser_extension_config: $ref: '#/components/schemas/teams-devices_browser_extension_config' captive_portal: $ref: '#/components/schemas/teams-devices_captive_portal' default: $ref: '#/components/schemas/teams-devices_default' description: allOf: - $ref: '#/components/schemas/teams-devices_schemas-description' - default: '' type: string x-auditable: true disable_auto_fallback: $ref: '#/components/schemas/teams-devices_disable_auto_fallback' dns_search_suffixes: $ref: '#/components/schemas/teams-devices_dns_search_suffixes' enabled: description: Whether the policy will be applied to matching devices. type: boolean example: true default: true x-auditable: true exclude: $ref: '#/components/schemas/teams-devices_exclude_request' exclude_office_ips: $ref: '#/components/schemas/teams-devices_exclude_office_ips' global_acceleration: $ref: '#/components/schemas/teams-devices_global_acceleration' include: $ref: '#/components/schemas/teams-devices_include_request' lan_allow_minutes: $ref: '#/components/schemas/teams-devices_lan_allow_minutes' lan_allow_subnet_size: $ref: '#/components/schemas/teams-devices_lan_allow_subnet_size' match: $ref: '#/components/schemas/teams-devices_schemas-match' name: description: The name of the device settings profile. type: string example: Allow Developers maxLength: 100 x-auditable: true precedence: $ref: '#/components/schemas/teams-devices_precedence' profile_type: $ref: '#/components/schemas/teams-devices_profile_type' register_interface_ip_with_dns: $ref: '#/components/schemas/teams-devices_register_interface_ip_with_dns' sccm_vpn_boundary_support: $ref: '#/components/schemas/teams-devices_sccm_vpn_boundary_support' service_mode_v2: $ref: '#/components/schemas/teams-devices_service_mode_v2' support_url: $ref: '#/components/schemas/teams-devices_support_url' switch_locked: $ref: '#/components/schemas/teams-devices_switch_locked' tunnel_protocol: $ref: '#/components/schemas/teams-devices_tunnel_protocol' uninstall_protection: $ref: '#/components/schemas/teams-devices_uninstall_protection' virtual_networks: $ref: '#/components/schemas/teams-devices_virtual_networks' required: - name responses: '200': description: Create a device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_device_settings_response' 4XX: description: Create a device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.devices.profiles.custom x-fern-sdk-method-name: create /accounts/{account_id}/devices/policy/exclude: delete: operationId: devices-delete-split-tunnel-exclude-list summary: Reset Split Tunnel exclude list description: Resets the Split Tunnel exclude list to the default value. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' - name: reset_defaults in: query description: Deprecated and ignored. Deleting the list always restores the defaults. schema: type: boolean default: true deprecated: true responses: '200': description: Reset the Split Tunnel exclude list response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_split_tunnel_response_collection' 4XX: description: Reset the Split Tunnel exclude list response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-auditable: true x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.default.excludes x-fern-sdk-method-name: delete get: operationId: devices-get-split-tunnel-exclude-list summary: Get the Split Tunnel exclude list description: Fetches the list of routes excluded from the WARP client's tunnel. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Get the Split Tunnel exclude list response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_split_tunnel_response_collection' 4XX: description: Get the Split Tunnel exclude list response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.default.excludes x-fern-sdk-method-name: get put: operationId: devices-set-split-tunnel-exclude-list summary: Set the Split Tunnel exclude list description: Sets the list of routes excluded from the WARP client's tunnel. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: type: array items: $ref: '#/components/schemas/teams-devices_split_tunnel' responses: '200': description: Set the Split Tunnel exclude list response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_split_tunnel_response_collection' 4XX: description: Set the Split Tunnel exclude list response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.default.excludes x-fern-sdk-method-name: update /accounts/{account_id}/devices/policy/fallback_domains: delete: operationId: devices-delete-local-domain-fallback-list summary: Reset Local Domain Fallback description: Restores the default Local Domain Fallback list for the default device profile. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' - name: reset_defaults in: query description: Deprecated and ignored. Deleting the list always restores the defaults. schema: type: boolean default: true deprecated: true responses: '200': description: Reset your Local Domain Fallback list response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_fallback_domain_response_collection' 4XX: description: Reset your Local Domain Fallback list response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-auditable: true x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.default.fallback-domains x-fern-sdk-method-name: delete get: operationId: devices-get-local-domain-fallback-list summary: Get your Local Domain Fallback list description: Fetches a list of domains to bypass Gateway DNS resolution. These domains will use the specified local DNS resolver instead. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Get your Local Domain Fallback list response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_fallback_domain_response_collection' 4XX: description: Get your Local Domain Fallback list response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.default.fallback-domains x-fern-sdk-method-name: get put: operationId: devices-set-local-domain-fallback-list summary: Set your Local Domain Fallback list description: Sets the list of domains to bypass Gateway DNS resolution. These domains will use the specified local DNS resolver instead. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: type: array items: $ref: '#/components/schemas/teams-devices_fallback_domain' responses: '200': description: Set your Local Domain Fallback list response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_fallback_domain_response_collection' 4XX: description: Set your Local Domain Fallback list response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.default.fallback-domains x-fern-sdk-method-name: update /accounts/{account_id}/devices/policy/include: get: operationId: devices-get-split-tunnel-include-list summary: Get the Split Tunnel include list description: Fetches the list of routes included in the WARP client's tunnel. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Get the Split Tunnel include list response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_split_tunnel_include_response_collection' 4XX: description: Get the Split Tunnel include list response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.default.includes x-fern-sdk-method-name: get put: operationId: devices-set-split-tunnel-include-list summary: Set the Split Tunnel include list description: Sets the list of routes included in the WARP client's tunnel. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: type: array items: $ref: '#/components/schemas/teams-devices_split_tunnel_include' responses: '200': description: Set the Split Tunnel include list response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_split_tunnel_include_response_collection' 4XX: description: Set the Split Tunnel include list response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.default.includes x-fern-sdk-method-name: update /accounts/{account_id}/devices/policy/{policy_id}: delete: operationId: devices-delete-device-settings-policy summary: Delete a device settings profile description: Deletes a device settings profile and fetches a list of the remaining profiles for an account. parameters: - name: policy_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_schemas-uuid' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Delete a device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_device_settings_response_collection' 4XX: description: Delete a device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.devices.profiles.custom x-fern-sdk-method-name: delete get: operationId: devices-get-device-settings-policy-by-id summary: Get device settings profile by ID description: Fetches a device settings profile by ID. parameters: - name: policy_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_schemas-uuid' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Get device settings profile by ID response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_device_settings_response' 4XX: description: Get device settings profile by ID response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.devices.profiles.custom x-fern-sdk-method-name: get patch: operationId: devices-update-device-settings-policy summary: Update a device settings profile description: Updates a configured device settings profile. parameters: - name: policy_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_schemas-uuid' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: type: object properties: allow_mode_switch: $ref: '#/components/schemas/teams-devices_allow_mode_switch' allow_updates: $ref: '#/components/schemas/teams-devices_allow_updates' allowed_to_leave: $ref: '#/components/schemas/teams-devices_allowed_to_leave' auto_connect: $ref: '#/components/schemas/teams-devices_auto_connect' browser_extension_config: $ref: '#/components/schemas/teams-devices_browser_extension_config' captive_portal: $ref: '#/components/schemas/teams-devices_captive_portal' default: $ref: '#/components/schemas/teams-devices_default' description: $ref: '#/components/schemas/teams-devices_schemas-description' disable_auto_fallback: $ref: '#/components/schemas/teams-devices_disable_auto_fallback' dns_search_suffixes: $ref: '#/components/schemas/teams-devices_dns_search_suffixes' enabled: description: Whether the policy will be applied to matching devices. type: boolean example: true x-auditable: true exclude: $ref: '#/components/schemas/teams-devices_exclude_request' exclude_office_ips: $ref: '#/components/schemas/teams-devices_exclude_office_ips' global_acceleration: $ref: '#/components/schemas/teams-devices_global_acceleration' include: $ref: '#/components/schemas/teams-devices_include_request' lan_allow_minutes: $ref: '#/components/schemas/teams-devices_lan_allow_minutes' lan_allow_subnet_size: $ref: '#/components/schemas/teams-devices_lan_allow_subnet_size' match: $ref: '#/components/schemas/teams-devices_schemas-match' name: description: The name of the device settings profile. type: string example: Allow Developers maxLength: 100 x-auditable: true precedence: $ref: '#/components/schemas/teams-devices_precedence' register_interface_ip_with_dns: $ref: '#/components/schemas/teams-devices_register_interface_ip_with_dns' sccm_vpn_boundary_support: $ref: '#/components/schemas/teams-devices_sccm_vpn_boundary_support' service_mode_v2: $ref: '#/components/schemas/teams-devices_service_mode_v2' support_url: $ref: '#/components/schemas/teams-devices_support_url' switch_locked: $ref: '#/components/schemas/teams-devices_switch_locked' tunnel_protocol: $ref: '#/components/schemas/teams-devices_tunnel_protocol' uninstall_protection: $ref: '#/components/schemas/teams-devices_uninstall_protection' virtual_networks: $ref: '#/components/schemas/teams-devices_virtual_networks' responses: '200': description: Update a device settings profile Policy response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_device_settings_response' 4XX: description: Update a device settings profile Policy response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.devices.profiles.custom x-fern-sdk-method-name: update /accounts/{account_id}/devices/policy/{policy_id}/exclude: delete: operationId: devices-delete-split-tunnel-exclude-list-for-a-device-settings-policy summary: Reset Split Tunnel exclude list description: Resets the Split Tunnel exclude list to the default value for the selected device profile. parameters: - name: policy_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_schemas-uuid' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' - name: reset_defaults in: query description: Deprecated and ignored. Deleting the list always restores the defaults. schema: type: boolean default: true deprecated: true responses: '200': description: Reset the Split Tunnel exclude list for a device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_split_tunnel_response_collection' 4XX: description: Reset the Split Tunnel exclude list for a device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-auditable: true x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.custom.excludes x-fern-sdk-method-name: delete get: operationId: devices-get-split-tunnel-exclude-list-for-a-device-settings-policy summary: Get the Split Tunnel exclude list for a device settings profile description: Fetches the list of routes excluded from the WARP client's tunnel for a specific device settings profile. parameters: - name: policy_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_schemas-uuid' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Get the Split Tunnel exclude list for a device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_split_tunnel_response_collection' 4XX: description: Get the Split Tunnel exclude list for a device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.custom.excludes x-fern-sdk-method-name: get put: operationId: devices-set-split-tunnel-exclude-list-for-a-device-settings-policy summary: Set the Split Tunnel exclude list for a device settings profile description: Sets the list of routes excluded from the WARP client's tunnel for a specific device settings profile. parameters: - name: policy_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_schemas-uuid' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: type: array items: $ref: '#/components/schemas/teams-devices_split_tunnel' responses: '200': description: Set the Split Tunnel exclude list for a device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_split_tunnel_response_collection' 4XX: description: Set the Split Tunnel exclude list for a device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.custom.excludes x-fern-sdk-method-name: update /accounts/{account_id}/devices/policy/{policy_id}/fallback_domains: delete: operationId: devices-delete-local-domain-fallback-list-for-a-device-settings-policy summary: Reset Local Domain Fallback description: Restores the default Local Domain Fallback list for a specific device profile. parameters: - name: policy_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_schemas-uuid' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' - name: reset_defaults in: query description: Deprecated and ignored. Deleting the list always restores the defaults. schema: type: boolean default: true deprecated: true responses: '200': description: Reset the Local Domain Fallback list for a device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_fallback_domain_response_collection' 4XX: description: Reset the Local Domain Fallback list for a device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-auditable: true x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.custom.fallback-domains x-fern-sdk-method-name: delete get: operationId: devices-get-local-domain-fallback-list-for-a-device-settings-policy summary: Get the Local Domain Fallback list for a device settings profile description: Fetches the list of domains to bypass Gateway DNS resolution from a specified device settings profile. These domains will use the specified local DNS resolver instead. parameters: - name: policy_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_schemas-uuid' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Get the Local Domain Fallback list for a device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_fallback_domain_response_collection' 4XX: description: Get the Local Domain Fallback list for a device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.custom.fallback-domains x-fern-sdk-method-name: get put: operationId: devices-set-local-domain-fallback-list-for-a-device-settings-policy summary: Set the Local Domain Fallback list for a device settings profile description: Sets the list of domains to bypass Gateway DNS resolution. These domains will use the specified local DNS resolver instead. This will only apply to the specified device settings profile. parameters: - name: policy_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_schemas-uuid' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: type: array items: $ref: '#/components/schemas/teams-devices_fallback_domain' responses: '200': description: Set the Local Domain Fallback list for a device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_fallback_domain_response_collection' 4XX: description: Set the Local Domain Fallback list for a device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.custom.fallback-domains x-fern-sdk-method-name: update /accounts/{account_id}/devices/policy/{policy_id}/include: get: operationId: devices-get-split-tunnel-include-list-for-a-device-settings-policy summary: Get the Split Tunnel include list for a device settings profile description: Fetches the list of routes included in the WARP client's tunnel for a specific device settings profile. parameters: - name: policy_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_schemas-uuid' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Get the Split Tunnel include list for a device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_split_tunnel_include_response_collection' 4XX: description: Get the Split Tunnel include list for a device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.custom.includes x-fern-sdk-method-name: get put: operationId: devices-set-split-tunnel-include-list-for-a-device-settings-policy summary: Set the Split Tunnel include list for a device settings profile description: Sets the list of routes included in the WARP client's tunnel for a specific device settings profile. parameters: - name: policy_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_schemas-uuid' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: type: array items: $ref: '#/components/schemas/teams-devices_split_tunnel_include' responses: '200': description: Set the Split Tunnel include list for a device settings profile response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_split_tunnel_include_response_collection' 4XX: description: Set the Split Tunnel include list for a device settings profile response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.custom.includes x-fern-sdk-method-name: update /accounts/{account_id}/devices/revoke: post: operationId: devices-revoke-devices summary: Revoke devices (deprecated) description: 'Revokes a list of devices. Not supported when multi-user mode is enabled. **Deprecated**: please use POST /accounts/{account_id}/devices/registrations/revoke instead.' parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/teams-devices_revoke_devices_request' responses: '200': description: Revoke devices response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-single' 4XX: description: Revoke devices response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' deprecated: true security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: deprecated x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.v1 x-fern-sdk-method-name: revoke /accounts/{account_id}/devices/unrevoke: post: operationId: devices-unrevoke-devices summary: Unrevoke devices (deprecated) description: 'Unrevokes a list of devices. Not supported when multi-user mode is enabled. **Deprecated**: please use POST /accounts/{account_id}/devices/registrations/unrevoke instead.' parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/teams-devices_unrevoke_devices_request' responses: '200': description: Unrevoke devices response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-single' 4XX: description: Unrevoke devices response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' deprecated: true security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Write x-fern-availability: deprecated x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.v1 x-fern-sdk-method-name: unrevoke /accounts/{account_id}/devices/{device_id}: get: operationId: devices-device-details summary: Get device (deprecated) description: 'Fetches a single WARP device. Not supported when multi-user mode is enabled for the account. **Deprecated**: please use one of the following endpoints instead: - GET /accounts/{account_id}/devices/physical-devices/{device_id} - GET /accounts/{account_id}/devices/registrations/{registration_id}' parameters: - name: device_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_registration_id' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Get device details response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_device_response' 4XX: description: Get device details response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' deprecated: true security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-fern-availability: deprecated x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.v1 x-fern-sdk-method-name: get /accounts/{account_id}/devices/{device_id}/override_codes: get: operationId: devices-list-admin-override-code-for-device summary: Get override codes (deprecated) description: 'Fetches a one-time use admin override code for a device. This relies on the **Admin Override** setting being enabled in your device configuration. Not supported when multi-user mode is enabled for the account. **Deprecated:** please use GET /accounts/{account_id}/devices/registrations/{registration_id}/override_codes instead.' parameters: - name: device_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_registration_id' - name: account_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Get an admin override code for a device response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_override_codes_response' 4XX: description: Get an admin override code for a device response failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' deprecated: true security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - Zero Trust Read - Zero Trust Write x-fern-availability: deprecated x-fern-sdk-group-name: zero-trust.devices.override-codes x-fern-sdk-method-name: list /zones/{zone_id}/devices/policy/certificates: get: operationId: devices-get-policy-certificates summary: Get device certificate provisioning status description: Fetches device certificate provisioning. parameters: - name: zone_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' responses: '200': description: Get WARP client provision certificates enabled status response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_devices_policy_certificates_single' 4XX: description: Get WARP client provision certificates enabled status failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - SSL and Certificates Write - SSL and Certificates Read x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.default.certificates x-fern-sdk-method-name: get patch: operationId: devices-update-policy-certificates summary: Update device certificate provisioning status description: Enable Zero Trust Clients to provision a certificate, containing a x509 subject, and referenced by Access device posture policies when the client visits MTLS protected domains. This facilitates device posture without a WARP session. parameters: - name: zone_id in: path required: true schema: $ref: '#/components/schemas/teams-devices_identifier' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/teams-devices_devices_policy_certificates' responses: '200': description: Update a zone to toggle permission for devices to provision certificates response. content: application/json: schema: $ref: '#/components/schemas/teams-devices_devices_policy_certificates_single' 4XX: description: Patch a zone to toggle permission for devices to provision certificates failure. content: application/json: schema: $ref: '#/components/schemas/teams-devices_api-response-common-failure' security: - api_email: [] api_key: [] api_token: [] tags: - Devices x-api-token-group: - SSL and Certificates Write x-fern-availability: generally-available x-fern-ignore: true x-fern-sdk-group-name: zero-trust.devices.profiles.default.certificates x-fern-sdk-method-name: update components: schemas: teams-devices_key_type: description: Type of the key. type: string example: curve25519 x-auditable: true teams-devices_version: description: The WARP client version. type: string example: 1.0.0 teams-devices_exclude_split_tunnel_with_host: type: object properties: description: $ref: '#/components/schemas/teams-devices_split_tunnel_description' host: $ref: '#/components/schemas/teams-devices_split_tunnel_host' required: - host teams-devices_switch_locked: description: Whether to allow the user to turn off the WARP switch and disconnect the client. type: boolean example: true default: false x-auditable: true teams-devices_os_distro_name: description: The Linux distro name. type: string example: ubuntu x-auditable: true teams-devices_include_split_tunnel_description: description: A description of the Split Tunnel item, displayed in the client UI. type: string example: Include testing domains in the tunnel maxLength: 100 x-auditable: true x-stainless-terraform-configurability: computed_optional teams-devices_default: description: Whether the policy is the account default. WARP group profiles cannot set this field. type: boolean example: false default: false x-auditable: true teams-devices_os_distro_revision: description: The Linux distro revision. type: string example: 1.0.0 x-auditable: true teams-devices_devices: type: object properties: created: $ref: '#/components/schemas/teams-devices_created' deleted: $ref: '#/components/schemas/teams-devices_deleted' device_type: $ref: '#/components/schemas/teams-devices_platform' id: $ref: '#/components/schemas/teams-devices_registration_id' ip: $ref: '#/components/schemas/teams-devices_ip' key: $ref: '#/components/schemas/teams-devices_key' last_seen: $ref: '#/components/schemas/teams-devices_last_seen' mac_address: $ref: '#/components/schemas/teams-devices_mac_address' manufacturer: $ref: '#/components/schemas/teams-devices_manufacturer' model: $ref: '#/components/schemas/teams-devices_model' name: $ref: '#/components/schemas/teams-devices_schemas-name' os_distro_name: $ref: '#/components/schemas/teams-devices_os_distro_name' os_distro_revision: $ref: '#/components/schemas/teams-devices_os_distro_revision' os_version: $ref: '#/components/schemas/teams-devices_os_version' os_version_extra: $ref: '#/components/schemas/teams-devices_os_version_extra' revoked_at: $ref: '#/components/schemas/teams-devices_revoked_at' serial_number: $ref: '#/components/schemas/teams-devices_serial_number' updated: $ref: '#/components/schemas/teams-devices_updated' user: $ref: '#/components/schemas/teams-devices_user' version: $ref: '#/components/schemas/teams-devices_version' teams-devices_support_url: description: The URL to launch when the Send Feedback button is clicked. type: string example: https://1.1.1.1/help default: '' teams-devices_include_split_tunnel_with_host: type: object properties: description: $ref: '#/components/schemas/teams-devices_include_split_tunnel_description' host: $ref: '#/components/schemas/teams-devices_include_split_tunnel_host' required: - host teams-devices_mac_address: description: The device mac address. type: string example: 00-00-5E-00-53-00 x-auditable: true teams-devices_device: type: object properties: account: $ref: '#/components/schemas/teams-devices_account' created: $ref: '#/components/schemas/teams-devices_created' deleted: $ref: '#/components/schemas/teams-devices_deleted' device_type: $ref: '#/components/schemas/teams-devices_device_type' gateway_device_id: $ref: '#/components/schemas/teams-devices_gateway_device_id' id: $ref: '#/components/schemas/teams-devices_registration_id' ip: $ref: '#/components/schemas/teams-devices_ip' key: $ref: '#/components/schemas/teams-devices_key' key_type: $ref: '#/components/schemas/teams-devices_key_type' last_seen: $ref: '#/components/schemas/teams-devices_last_seen' mac_address: $ref: '#/components/schemas/teams-devices_mac_address' model: $ref: '#/components/schemas/teams-devices_model' name: $ref: '#/components/schemas/teams-devices_schemas-name' os_version: $ref: '#/components/schemas/teams-devices_os_version' serial_number: $ref: '#/components/schemas/teams-devices_serial_number' tunnel_type: $ref: '#/components/schemas/teams-devices_tunnel_type' updated: $ref: '#/components/schemas/teams-devices_updated' user: $ref: '#/components/schemas/teams-devices_user' version: $ref: '#/components/schemas/teams-devices_version' teams-devices_default_device_settings_response: allOf: - $ref: '#/components/schemas/teams-devices_api-response-single' - properties: result: $ref: '#/components/schemas/teams-devices_default_device_settings_policy' type: object teams-devices_global_acceleration: description: Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/. type: - object - 'null' properties: api_endpoints: description: IP:port entries for the API endpoints. type: array items: type: string x-auditable: true example: - 198.51.100.1:443 maxItems: 5 autoswitch: description: Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided. type: boolean example: true default: false x-auditable: true enabled: description: Global acceleration settings are used only when "enabled". type: boolean example: true x-auditable: true masque_endpoints: description: IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided. type: array items: type: string x-auditable: true example: - 198.51.100.1:443 maxItems: 5 wireguard_endpoints: description: IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided. type: array items: type: string x-auditable: true example: - 198.51.100.1:2408 maxItems: 5 required: - enabled - wireguard_endpoints - masque_endpoints - api_endpoints teams-devices_user: type: object properties: email: $ref: '#/components/schemas/teams-devices_email' id: $ref: '#/components/schemas/teams-devices_components-schemas-uuid' name: description: The enrolled device user's name. type: string example: John Appleseed teams-devices_profile_type: description: The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed. type: string example: warp default: warp enum: - warp - browser_extension x-auditable: true teams-devices_split_tunnel_description: description: A description of the Split Tunnel item, displayed in the client UI. type: string example: Exclude testing domains from the tunnel maxLength: 100 x-auditable: true x-stainless-terraform-configurability: computed_optional teams-devices_allow_mode_switch: description: Whether to allow the user to switch WARP between modes. type: boolean example: true default: false x-auditable: true teams-devices_split_tunnel_host: description: The domain name to exclude from the tunnel. If `host` is present, `address` must not be present. type: string example: '*.example.com' x-auditable: true x-stainless-terraform-configurability: computed_optional teams-devices_device_response: allOf: - $ref: '#/components/schemas/teams-devices_api-response-single' - properties: result: $ref: '#/components/schemas/teams-devices_device' type: object teams-devices_target_dex_test: type: object properties: id: description: The id of the DEX test targeting this policy. type: string x-auditable: true name: description: The name of the DEX test targeting this policy. type: string x-auditable: true teams-devices_lan_allow_subnet_size: description: The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset. type: number example: 24 x-auditable: true teams-devices_email: description: The contact email address of the user. type: string example: user@example.com maxLength: 90 x-auditable: true teams-devices_disable_for_time: type: object properties: '1': description: Override code that is valid for 1 hour. type: string example: '9106681' '3': description: Override code that is valid for 3 hours. type: string example: '5356247' '6': description: Override code that is valid for 6 hours. type: string example: '9478972' '12': description: Override code that is valid for 12 hour2. type: string example: '3424359' '24': description: Override code that is valid for 24 hour.2. type: string example: '2887634' teams-devices_result_info: type: object properties: count: description: Total number of results for the requested service. type: number example: 1 page: description: Current page within paginated list of results. type: number example: 1 per_page: description: Number of results per page of results. type: number example: 20 total_count: description: Total results available without any search parameters. type: number example: 2000 teams-devices_device_type: type: string example: windows x-auditable: true teams-devices_fallback_domain_response_collection: allOf: - $ref: '#/components/schemas/teams-devices_api-response-collection' - properties: result: type: array items: $ref: '#/components/schemas/teams-devices_fallback_domain' type: object teams-devices_api-response-common: type: object properties: errors: $ref: '#/components/schemas/teams-devices_messages' messages: $ref: '#/components/schemas/teams-devices_messages' result: anyOf: - type: object - items: type: object type: array - type: string success: description: Whether the API call was successful. type: boolean example: true enum: - true required: - success - errors - messages - result teams-devices_dns_search_suffix: type: object properties: description: description: A description of the DNS search suffix. type: string example: Example internal domains x-auditable: true x-stainless-terraform-configurability: computed_optional suffix: description: The DNS search suffix to append when resolving short hostnames. type: string example: internal.corp x-auditable: true required: - suffix teams-devices_gateway_unique_id: type: string example: 699d98642c564d2e855e9661899b7252 teams-devices_api-response-common-failure: type: object properties: errors: example: - code: 7003 message: No route for the URI allOf: - $ref: '#/components/schemas/teams-devices_messages' minLength: 1 messages: example: [] allOf: - $ref: '#/components/schemas/teams-devices_messages' result: type: - object - 'null' enum: - null success: description: Whether the API call was successful. type: boolean example: false enum: - false required: - success - errors - messages - result teams-devices_fallback_domain: type: object properties: description: description: A description of the fallback domain, displayed in the client UI. type: string example: Domain bypass for local development maxLength: 100 x-auditable: true dns_server: description: A list of IP addresses to handle domain resolution. type: array items: $ref: '#/components/schemas/teams-devices_ip' suffix: description: The domain suffix to match when resolving locally. type: string example: example.com x-auditable: true required: - suffix teams-devices_uninstall_protection: description: Determines whether uninstalling the WARP client requires an override code. (Windows only). type: boolean example: false default: false x-auditable: true teams-devices_split_tunnel_response_collection: allOf: - $ref: '#/components/schemas/teams-devices_api-response-collection' - properties: result: type: array items: $ref: '#/components/schemas/teams-devices_split_tunnel' type: object teams-devices_allow_updates: description: Whether to receive update notifications when a new version of the client is available. type: boolean example: true default: false x-auditable: true teams-devices_sccm_vpn_boundary_support: description: Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only). type: boolean example: false default: false x-auditable: true teams-devices_os_version_extra: description: Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version. type: string example: (a) or 6889 or Ubuntu 24.04 teams-devices_registration_id: description: Registration ID. Equal to Device ID except for accounts which enabled [multi-user mode](https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/windows-multiuser/). type: string example: f174e90a-fafe-4643-bbbc-4a0ed4fc8415 maxLength: 36 x-auditable: true teams-devices_exclude: description: List of routes excluded in the WARP client's tunnel. type: array items: $ref: '#/components/schemas/teams-devices_split_tunnel' default: - address: 10.0.0.0/8 - address: 100.64.0.0/10 - address: 169.254.0.0/16 description: DHCP Unspecified - address: 172.16.0.0/12 - address: 192.0.0.0/24 - address: 192.168.0.0/16 - address: 224.0.0.0/24 - address: 240.0.0.0/4 - address: 255.255.255.255/32 description: DHCP Broadcast - address: fe80::/10 description: IPv6 Link Local - address: fd00::/8 - address: ff01::/16 - address: ff02::/16 - address: ff03::/16 - address: ff04::/16 - address: ff05::/16 teams-devices_disable_auto_fallback: description: If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`. type: boolean example: true default: false x-auditable: true teams-devices_gateway_device_id: type: string example: PD33E90AXfafe14643cbbbc-4a0ed4fc8415Q deprecated: true teams-devices_include_request: description: List of routes included in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request. type: array items: $ref: '#/components/schemas/teams-devices_split_tunnel_include' x-stainless-terraform-configurability: computed_optional teams-devices_api-response-collection: type: object allOf: - $ref: '#/components/schemas/teams-devices_api-response-common' - properties: result: type: - array - 'null' items: type: object result_info: $ref: '#/components/schemas/teams-devices_result_info' type: object teams-devices_components-schemas-uuid: description: UUID. type: string example: f174e90a-fafe-4643-bbbc-4a0ed4fc8415 maxLength: 36 readOnly: true x-auditable: true teams-devices_schemas-name: description: The device name. type: string example: My mobile device teams-devices_fallback_domains: type: array items: $ref: '#/components/schemas/teams-devices_fallback_domain' default: - suffix: intranet - suffix: internal - suffix: private - suffix: localdomain - suffix: domain - suffix: lan - suffix: home - suffix: host - suffix: corp - suffix: local - suffix: localhost - suffix: home.arpa - suffix: invalid - suffix: test teams-devices_created: description: When the device was created. type: string format: date-time example: '2017-06-14T00:00:00Z' x-auditable: true teams-devices_browser_extension_config: description: Browser extension proxy settings. Required when profile_type is browser_extension and invalid for WARP profiles. type: - object - 'null' properties: proxy_control: description: Whether the user may disable the browser extension proxy. type: string enum: - unlocked - locked x-auditable: true proxy_enabled: description: Whether the browser extension proxy is active. type: boolean x-auditable: true additionalProperties: false required: - proxy_enabled - proxy_control teams-devices_service_mode_v2: type: object properties: mode: description: The mode to run the WARP client under. type: string example: proxy x-auditable: true x-stainless-terraform-configurability: computed_optional port: description: The port number when used with proxy mode. type: number example: 3000 x-auditable: true x-stainless-terraform-configurability: computed_optional x-stainless-terraform-configurability: computed_optional teams-devices_exclude_request: description: List of routes excluded in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request. type: array items: $ref: '#/components/schemas/teams-devices_split_tunnel' x-stainless-terraform-configurability: computed_optional teams-devices_include: description: List of routes included in the WARP client's tunnel. type: array items: $ref: '#/components/schemas/teams-devices_split_tunnel_include' teams-devices_tunnel_type: description: Type of the tunnel connection used. type: string example: masque x-auditable: true teams-devices_devices_policy_certificates_single: allOf: - $ref: '#/components/schemas/teams-devices_api-response-single' - properties: result: $ref: '#/components/schemas/teams-devices_devices_policy_certificates' type: object teams-devices_split_tunnel: type: object oneOf: - $ref: '#/components/schemas/teams-devices_exclude_split_tunnel_with_address' - $ref: '#/components/schemas/teams-devices_exclude_split_tunnel_with_host' teams-devices_updated: description: When the device was updated. type: string format: date-time example: '2017-06-14T00:00:00Z' x-auditable: true teams-devices_tunnel_protocol: description: Determines which tunnel protocol to use. type: string example: wireguard default: '' x-auditable: true teams-devices_auto_connect: description: The amount of time in seconds to reconnect after having been disabled. type: number example: 0 default: 0 x-auditable: true teams-devices_api-response-single: type: object allOf: - $ref: '#/components/schemas/teams-devices_api-response-common' - properties: result: type: - object - 'null' anyOf: - type: object - type: string type: object teams-devices_os_version: description: The operating system version. type: string example: 10.0.0 teams-devices_schemas-uuid: type: string example: f174e90a-fafe-4643-bbbc-4a0ed4fc8415 maxLength: 36 x-auditable: true teams-devices_precedence: description: The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field. type: number example: 100 x-auditable: true teams-devices_platform: type: string example: windows enum: - windows - mac - linux - android - ios - chromeos x-auditable: true teams-devices_captive_portal: description: Turn on the captive portal after the specified amount of time. type: number example: 180 default: 180 x-auditable: true teams-devices_register_interface_ip_with_dns: description: Determines if the operating system will register WARP's local interface IP with your on-premises DNS server. type: boolean example: true default: true x-auditable: true teams-devices_manufacturer: description: The device manufacturer name. type: string example: My phone corp teams-devices_last_seen: description: When the device last connected to Cloudflare services. type: string format: date-time example: '2017-06-14T00:00:00Z' x-auditable: true teams-devices_ip: description: IPv4 or IPv6 address. type: string example: 1.1.1.1 x-auditable: true teams-devices_override_codes_response: allOf: - $ref: '#/components/schemas/teams-devices_api-response-single' - properties: result: type: object properties: disable_for_time: $ref: '#/components/schemas/teams-devices_disable_for_time' type: object teams-devices_lan_allow_minutes: description: The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset. type: number example: 30 x-auditable: true teams-devices_serial_number: description: The device serial number. type: string example: EXAMPLEHMD6R teams-devices_allowed_to_leave: description: Whether to allow devices to leave the organization. type: boolean example: true default: true x-auditable: true teams-devices_split_tunnel_include: type: object oneOf: - $ref: '#/components/schemas/teams-devices_include_split_tunnel_with_address' - $ref: '#/components/schemas/teams-devices_include_split_tunnel_with_host' teams-devices_devices_response: allOf: - $ref: '#/components/schemas/teams-devices_api-response-collection' - properties: result: type: array items: $ref: '#/components/schemas/teams-devices_devices' type: object teams-devices_dns_search_suffixes: description: List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear. type: array items: $ref: '#/components/schemas/teams-devices_dns_search_suffix' default: [] x-stainless-terraform-configurability: computed_optional teams-devices_device_settings_policy: type: object properties: allow_mode_switch: $ref: '#/components/schemas/teams-devices_allow_mode_switch' allow_updates: $ref: '#/components/schemas/teams-devices_allow_updates' allowed_to_leave: $ref: '#/components/schemas/teams-devices_allowed_to_leave' auto_connect: $ref: '#/components/schemas/teams-devices_auto_connect' browser_extension_config: $ref: '#/components/schemas/teams-devices_browser_extension_config' captive_portal: $ref: '#/components/schemas/teams-devices_captive_portal' default: $ref: '#/components/schemas/teams-devices_default' description: $ref: '#/components/schemas/teams-devices_schemas-description' disable_auto_fallback: $ref: '#/components/schemas/teams-devices_disable_auto_fallback' dns_search_suffixes: $ref: '#/components/schemas/teams-devices_dns_search_suffixes' enabled: description: Whether the policy will be applied to matching devices. type: boolean example: true default: true x-auditable: true exclude: $ref: '#/components/schemas/teams-devices_exclude' exclude_office_ips: $ref: '#/components/schemas/teams-devices_exclude_office_ips' fallback_domains: $ref: '#/components/schemas/teams-devices_fallback_domains' gateway_unique_id: $ref: '#/components/schemas/teams-devices_gateway_unique_id' global_acceleration: $ref: '#/components/schemas/teams-devices_global_acceleration' include: $ref: '#/components/schemas/teams-devices_include' lan_allow_minutes: $ref: '#/components/schemas/teams-devices_lan_allow_minutes' lan_allow_subnet_size: $ref: '#/components/schemas/teams-devices_lan_allow_subnet_size' match: $ref: '#/components/schemas/teams-devices_schemas-match' name: description: The name of the device settings profile. type: string example: Allow Developers maxLength: 100 x-auditable: true policy_id: $ref: '#/components/schemas/teams-devices_schemas-uuid' precedence: $ref: '#/components/schemas/teams-devices_precedence' profile_type: $ref: '#/components/schemas/teams-devices_profile_type' register_interface_ip_with_dns: $ref: '#/components/schemas/teams-devices_register_interface_ip_with_dns' sccm_vpn_boundary_support: $ref: '#/components/schemas/teams-devices_sccm_vpn_boundary_support' service_mode_v2: $ref: '#/components/schemas/teams-devices_service_mode_v2' support_url: $ref: '#/components/schemas/teams-devices_support_url' switch_locked: $ref: '#/components/schemas/teams-devices_switch_locked' target_tests: type: array items: $ref: '#/components/schemas/teams-devices_target_dex_test' deprecated: true x-fern-deprecated: true tunnel_protocol: $ref: '#/components/schemas/teams-devices_tunnel_protocol' uninstall_protection: $ref: '#/components/schemas/teams-devices_uninstall_protection' virtual_networks: $ref: '#/components/schemas/teams-devices_virtual_networks' teams-devices_model: description: The device model name. type: string example: MyPhone(pro-X) teams-devices_devices_policy_certificates: type: object properties: enabled: description: The current status of the device policy certificate provisioning feature for WARP clients. type: boolean example: true required: - enabled teams-devices_include_split_tunnel_with_address: type: object properties: address: $ref: '#/components/schemas/teams-devices_include_split_tunnel_address' description: $ref: '#/components/schemas/teams-devices_include_split_tunnel_description' required: - address teams-devices_device_settings_response_collection: allOf: - $ref: '#/components/schemas/teams-devices_api-response-collection' - properties: result: type: array items: $ref: '#/components/schemas/teams-devices_device_settings_policy' type: object teams-devices_schemas-match: description: 'The wirefilter expression to match devices. Available values: "identity.email", "identity.groups.id", "identity.groups.name", "identity.groups.email", "identity.service_token_uuid", "identity.saml_attributes", "network", "os.name", "os.version".' type: string example: identity.email == "test@cloudflare.com" maxLength: 500 x-auditable: true teams-devices_include_split_tunnel_host: description: The domain name to include in the tunnel. If `host` is present, `address` must not be present. type: string example: '*.example.com' x-auditable: true x-stainless-terraform-configurability: computed_optional teams-devices_exclude_office_ips: description: Whether to add Microsoft IPs to Split Tunnel exclusions. type: boolean example: true default: false x-auditable: true teams-devices_identifier: type: string example: 699d98642c564d2e855e9661899b7252 teams-devices_schemas-description: description: A description of the policy. type: string example: Policy for test teams. maxLength: 500 x-auditable: true teams-devices_exclude_split_tunnel_with_address: type: object properties: address: $ref: '#/components/schemas/teams-devices_split_tunnel_address' description: $ref: '#/components/schemas/teams-devices_split_tunnel_description' required: - address teams-devices_revoke_devices_request: description: A list of Registration IDs to revoke. type: array items: $ref: '#/components/schemas/teams-devices_registration_id' maxLength: 200 teams-devices_split_tunnel_address: description: The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present. type: string example: 192.0.2.0/24 x-auditable: true x-stainless-terraform-configurability: computed_optional teams-devices_account: type: object properties: account_type: type: string deprecated: true id: type: string deprecated: true name: description: The name of the enrolled account. type: string example: Company x-auditable: true teams-devices_virtual_networks: description: Virtual network access settings for the device. type: - object - 'null' properties: allowed: description: List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required. type: array items: format: uuid type: string x-auditable: true example: - f174e90a-fafe-4643-bbbc-4a0ed4fc8415 minItems: 1 uniqueItems: true default: description: The default virtual network ID. Must be included in the `allowed` list. type: string format: uuid example: f174e90a-fafe-4643-bbbc-4a0ed4fc8415 x-auditable: true required: - allowed - default teams-devices_device_settings_response: allOf: - $ref: '#/components/schemas/teams-devices_api-response-single' - properties: result: $ref: '#/components/schemas/teams-devices_device_settings_policy' type: object teams-devices_revoked_at: description: When the device was revoked. type: string format: date-time example: '2017-06-14T00:00:00Z' x-auditable: true teams-devices_messages: type: array items: properties: code: type: integer minimum: 1000 message: type: string required: - code - message type: object uniqueItems: true example: [] teams-devices_unrevoke_devices_request: description: A list of Registration IDs to unrevoke. type: array items: $ref: '#/components/schemas/teams-devices_registration_id' maxLength: 200 teams-devices_deleted: description: True if the device was deleted. type: boolean example: true teams-devices_default_device_settings_policy: type: object properties: allow_mode_switch: $ref: '#/components/schemas/teams-devices_allow_mode_switch' allow_updates: $ref: '#/components/schemas/teams-devices_allow_updates' allowed_to_leave: $ref: '#/components/schemas/teams-devices_allowed_to_leave' auto_connect: $ref: '#/components/schemas/teams-devices_auto_connect' captive_portal: $ref: '#/components/schemas/teams-devices_captive_portal' default: description: Whether the policy will be applied to matching devices. type: boolean example: true x-auditable: true disable_auto_fallback: $ref: '#/components/schemas/teams-devices_disable_auto_fallback' dns_search_suffixes: $ref: '#/components/schemas/teams-devices_dns_search_suffixes' enabled: description: Whether the policy will be applied to matching devices. type: boolean example: true default: true x-auditable: true exclude: $ref: '#/components/schemas/teams-devices_exclude' exclude_office_ips: $ref: '#/components/schemas/teams-devices_exclude_office_ips' fallback_domains: $ref: '#/components/schemas/teams-devices_fallback_domains' gateway_unique_id: $ref: '#/components/schemas/teams-devices_gateway_unique_id' global_acceleration: $ref: '#/components/schemas/teams-devices_global_acceleration' include: $ref: '#/components/schemas/teams-devices_include' policy_id: $ref: '#/components/schemas/teams-devices_schemas-uuid' profile_type: $ref: '#/components/schemas/teams-devices_profile_type' register_interface_ip_with_dns: $ref: '#/components/schemas/teams-devices_register_interface_ip_with_dns' sccm_vpn_boundary_support: $ref: '#/components/schemas/teams-devices_sccm_vpn_boundary_support' service_mode_v2: $ref: '#/components/schemas/teams-devices_service_mode_v2' support_url: $ref: '#/components/schemas/teams-devices_support_url' switch_locked: $ref: '#/components/schemas/teams-devices_switch_locked' tunnel_protocol: $ref: '#/components/schemas/teams-devices_tunnel_protocol' uninstall_protection: $ref: '#/components/schemas/teams-devices_uninstall_protection' virtual_networks: $ref: '#/components/schemas/teams-devices_virtual_networks' teams-devices_key: description: The device's public key. type: string example: yek0SUYoOQ10vMGsIYAevozXUQpQtNFJFfFGqER/BGc= teams-devices_split_tunnel_include_response_collection: allOf: - $ref: '#/components/schemas/teams-devices_api-response-collection' - properties: result: type: array items: $ref: '#/components/schemas/teams-devices_split_tunnel_include' type: object teams-devices_include_split_tunnel_address: description: The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present. type: string example: 192.0.2.0/24 x-auditable: true x-stainless-terraform-configurability: computed_optional securitySchemes: api_email: in: header name: X-Auth-Email type: apiKey api_key: in: header name: X-Auth-Key type: apiKey api_token: scheme: bearer type: http user_service_key: in: header name: X-Auth-User-Service-Key type: apiKey externalDocs: description: Cloudflare Radar Documentation url: https://developers.cloudflare.com/radar/ x-forge-commands: abuse-reports: description: Submit and track abuse reports for phishing, malware, and other policy violations on Cloudflare-proxied sites groups: appeals: description: Appeal eligibility for abuse reports emails: description: Emails sent for abuse reports mitigations: description: Mitigation actions taken in response to abuse reports accounts: description: Account settings, members, roles, subscriptions, and API tokens for your Cloudflare account groups: applications: description: Applications operations categories: description: Categories operations organizations: description: Move accounts between organizations profile: description: View and manage the profile for a Cloudflare account roles: description: View the roles available for assigning to account members, each defining a set of permissions subscriptions: description: View and manage plan subscriptions attached to this account tokens: description: Create and manage scoped API tokens for programmatic access to the Cloudflare API ai-gateway: description: Proxy, cache, rate-limit, and observe requests to AI providers — OpenAI, Anthropic, Workers AI, and more groups: custom-domains: description: Manage custom hostnames that route requests through an AI Gateway custom-providers: description: Manage account-level custom AI providers and their endpoint settings datasets: description: 'Deprecated: manage filtered collections of gateway logs used by evaluations' dynamic-routing: description: Route requests across multiple AI providers with fallback, load-balancing, and versioned deployments dynamic-routing.deployments: description: Deploy dynamic route versions and view deployment history dynamic-routing.versions: description: Create and inspect saved versions of a dynamic route evaluation-types: description: 'Deprecated: list the evaluator types that evaluations can use' evaluations: description: 'Deprecated: score the logs in a dataset with selected evaluator types' gateways: description: Create and configure AI Gateways for an account gateways.providers: description: Store and rotate upstream AI provider keys for a gateway logs: description: Inspect, annotate, and delete gateway request logs stored by Legacy Logs ai-search: description: 'Managed search-as-a-service: crawl, index, and query content with AI-powered relevance and chat completions' groups: items: description: Content indexed by AI Search instances jobs: description: Indexing job lifecycle for AI Search instances namespace: description: Logical groupings for organizing AI Search instances tokens: description: Credentials used by AI Search instances ai-security: description: Detect prompt injection, PII, and unsafe topics in traffic to your AI applications groups: custom-topics: description: Organization-specific topic categories used by AI Security for Apps content detection analytics: description: Zone-level traffic analytics — dashboard summaries, per-colo breakdowns, and Argo latency metrics groups: colo: description: Per-data-center (colo) traffic analytics breakdown for the zone dashboard: description: Aggregated zone dashboard analytics — requests, bandwidth, threats, and page views latency: description: Argo Smart Routing latency analytics showing time-to-first-byte improvements argo: description: Network optimization features that speed up and improve reliability of traffic to your origins groups: smart-routing: description: Route traffic through the fastest network paths to your origin using real-time latency data tiered-caching: description: Reduce origin load by having upper-tier data centers serve cache misses before reaching your origin basin-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables billing: description: Account billing profiles and usage data for Cloudflare subscriptions and add-on services groups: profiles: description: Billing profile with payment method, address, and invoice preferences usage: description: Metered usage data for billed services — requests, bandwidth, and feature consumption botnet-feed: description: Botnet threat intelligence feeds — IP and ASN-level data on known command-and-control infrastructure groups: asn: description: ASN-level botnet activity data showing networks with known C2 infrastructure configs: description: Botnet feed subscription configuration and notification preferences builds: description: Build and deploy Workers from connected repositories, then inspect build status and logs. groups: deploy-hooks: description: Manage branch-specific HTTP hooks that start builds. limits: description: View build-minute availability and refresh information. logs: description: Retrieve build logs. repos: description: Manage source repository connections for Workers Builds. tokens: description: Manage credentials used by Workers Builds to deploy Workers. triggers: description: Configure how repository changes build and deploy Workers. versions: description: Find builds associated with Worker versions. workers: description: Manage repository-backed build configuration for Workers. cache: description: Purge cached content and configure Cache Reserve, tiered caching, and variant serving groups: origin-cloud-regions: description: Manage Origin Cloud Regions routing and failover configurations settings: description: Configure Cache Reserve, tiered caching, and variant serving settings.regional-tiered-cache: description: Restrict tiered cache topology to data centers within a specific geographic region settings.reserve: description: Persistent storage tier that keeps cached assets even after eviction from edge caches settings.smart-tiered-cache: description: Automatically determine the best upper-tier data centers for tiered cache topology settings.variants: description: Serve different cached versions of an image based on the Accept header (WebP, AVIF, etc.) client-side-security: description: Client-Side Security — monitor JavaScript, connections, and cookies on your pages for supply-chain attacks groups: connections: description: Third-party connections made by scripts on your pages — track data exfiltration risks cookies: description: Cookies set by your pages with classification and same-site attribute tracking policies: description: Content Security Policies that control which scripts and connections are allowed on your pages scripts: description: JavaScript files detected on your pages with change tracking and malicious code detection settings: description: Fine tune Client-Side Security behaviors cloud-connector: description: Route traffic from Cloudflare directly to cloud provider services (AWS, Azure, GCP) without origin servers groups: rules: description: Routing rules that map request patterns to cloud provider endpoints cloudforce-one: description: Detection rule management APIs groups: binary-storage: description: Upload and retrieve malware samples and suspicious binaries for analysis requests: description: Additional request operations — priority listing and asset creation rules: description: Rule management operations groups: approvals: description: Approval workflow operations email: description: Email rule operations exemptions: description: Exemption rule operations managed: description: Managed rule operations stats: description: Rule statistics operations tree: description: Rule navigation tree operations scans: description: Scan URLs, IPs, and domains for threat intelligence indicators containers: description: Deploy and manage Containers applications on Cloudflare's global network groups: applications: description: Manage Containers applications applications.instances: description: Inspect Containers instances belonging to applications applications.rollouts: description: Manage rollouts for scheduler-backed applications applications.versions: description: Inspect versions of scheduler-backed applications registries: description: Manage Containers image registries registries.credentials: description: Generate image registry credentials content-scan: description: Malicious uploads detection, scan uploaded content in HTTP requests for malware and malicious payloads groups: expressions: description: Custom expressions that tell the scanner how to reach content objects it cannot parse on its own custom-pages: description: Manage custom error and challenge pages and their assets for accounts and zones groups: account-custom-pages: description: Manage account-level custom pages account-custom-pages.preview-tokens: description: Preview tokens for account-level custom pages assets: description: Manage account- and zone-level custom assets zone-custom-pages: description: Manage zone-level custom pages zone-custom-pages.preview-tokens: description: Preview tokens for zone-level custom pages d1: description: D1 is Cloudflare's managed, serverless database with SQLite's SQL semantics, built-in disaster recovery, and Worker and HTTP API access. groups: time-travel: description: use specific point-in-time backups of your D1 database x-forge-epilogue: For more information about Time Travel, see https://developers.cloudflare.com/d1/reference/time-travel diagnostics: description: Network diagnostic tools — traceroutes from Cloudflare's edge and endpoint health checks groups: endpoint-healthchecks: description: Monitor external endpoint availability with periodic HTTP/HTTPS health checks traceroutes: description: Run traceroutes from Cloudflare data centers to diagnose network path issues email-routing: description: Route incoming email to verified destination addresses or Workers with routing rules, catch-all behavior, and managed DNS records groups: addresses: description: Verified destination email addresses that can receive forwarded mail dns: description: Inspect or unlock the DNS records required by Email Routing rules: description: Match incoming email addresses and forward messages to destination mailboxes or Workers settings: description: Inspect and update Email Routing settings email-security: description: Cloud email security — investigate threats, manage allow/block policies, and detect phishing groups: analytics: description: Analytics and reporting — monthly report and per-day breakdowns of threat activity bulk-actions: description: Asynchronous jobs that move or release every message matching a search — create, monitor, and manage bulk jobs investigate: description: Search and investigate email messages — view detections, traces, raw content, and take remediation actions phishguard: description: PhishGuard user-reported phishing reports — view detected threats for a date range settings: description: Email security configuration — block senders, allow policies, content policies, domains, trusted domains, impersonation registry, and URL handling submissions: description: Reclassify submissions — track user and team reports of false positives and missed detections email-sending: description: Send transactional email and manage sending subdomains and their DNS configuration groups: limits: description: Inspect account-level sending quotas and current usage subdomains: description: Configure sending subdomains and keep their DNS records healthy suppressions: description: Prevent delivery to suppressed addresses and manage the account suppression list filters: description: Filter expressions used by legacy firewall rules to match requests — prefer Rulesets for new configurations firewall: description: Legacy firewall rules, zone lockdowns, access rules, user-agent blocking, and WAF packages groups: access-rules: description: IP-based access rules that allow, block, challenge, or whitelist traffic globally or per-zone lockdowns: description: Zone lockdown rules that restrict access to URLs by IP address or range rules: description: Legacy firewall rules with filter expressions — prefer Rulesets for new configurations ua-rules: description: Block or challenge requests based on the User-Agent header string waf: description: Legacy WAF managed rule packages, rule groups, individual rules, and override configurations zone-access-rules: description: Zone-scoped IP access rules for blocking or allowing traffic google-tag-gateway: description: Google Tag Gateway operations groups: config: description: Google Tag Gateway config operations healthchecks: description: Standalone health checks that monitor origin server availability from Cloudflare's edge groups: previews: description: Test a health check configuration before deploying it to production hyperdrive: description: Accelerate access to existing databases by caching queries and pooling connections at the edge iam: description: Identity and access management — permission groups, resource groups, user groups, and SSO connectors groups: permission-groups: description: View the permission groups that can be assigned to API tokens and policies resource-groups: description: Define scopes that limit which account resources a policy or token can access sso: description: Configure single sign-on connectors to authenticate account members through an external identity provider user-groups: description: Organize account members into groups for easier permission assignment images: description: Store, resize, and deliver optimized images globally — variants, signing keys, and direct uploads groups: flows: description: Zone-level transformation flows that control how images are resized and optimized on delivery import: description: Import images from S3 keys: description: Manage signing keys for generating private image URLs variants: description: Manage named resize variants for transforming images on delivery intel: description: Threat intelligence lookups — IP reputation, domain info, ASN details, WHOIS, and indicator feeds groups: asn: description: ASN intelligence — ownership, geolocation, and subnet details for autonomous systems attack-surface-report: description: Attack surface intelligence — exposed assets, vulnerabilities, and infrastructure mapping dns: description: Passive DNS data showing historical DNS resolution records for domains domain-history: description: Historical domain registration and categorization changes over time domains: description: Domain intelligence — risk scores, categories, and associated infrastructure indicator-feeds: description: Threat indicator feeds — subscribe to and manage curated lists of malicious IPs, domains, and URLs ip-lists: description: Curated IP lists used for threat detection and policy enforcement ips: description: IP address intelligence — geolocation, risk assessment, and hosting provider details miscategorizations: description: Report and track domain miscategorization corrections whois: description: WHOIS registration data for domains including registrant, registrar, and nameservers k2: description: Durable, ordered event streams that you produce records to and consume from with subscriptions groups: streams: description: K2 streams, their retention, and the HTTP and Workers binding inputs used to produce records streams.subscriptions: description: Subscriptions that consume a K2 stream, with committed-position lag leaked-credential-checks: description: Detect compromised credentials in login requests by checking against known breach databases groups: detections: description: Custom detection locations that tell the WAF where to find usernames and passwords in requests load-balancers: description: Distribute traffic across origin pools with health monitoring, geo-steering, and failover groups: monitor-groups: description: Group monitors together for shared configuration and bulk management monitor-groups.references: description: List references to monitor groups used by load balancer pools monitors: description: Health check configurations that probe origin servers and determine pool availability monitors.previews: description: Health check configurations that probe origin servers and determine pool availability monitors.references: description: Health check configurations that probe origin servers and determine pool availability pools: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.health: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.references: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences previews: description: Preview the result of a health check monitor configuration before applying it regions: description: Geographic regions used for regional pool steering and traffic policies searches: description: Search across all load balancer resources (pools, monitors, load balancers) by name or reference logs: description: Log control, retention, and raw log access — CMB config, ray ID lookups, and received fields groups: control: description: Log control operations received: description: Received log operations magic-network-monitoring: description: Flow-based network traffic monitoring with configurable alerting rules and VPC flow ingestion groups: configs: description: Account-level monitoring configuration — sampling rates, thresholds, and notification settings rules: description: Monitoring rules that define traffic thresholds and trigger alerts or prefix advertisements vpc-flows: description: Ingest VPC flow logs from cloud providers for network visibility and anomaly detection magic-transit: description: DDoS-protected network transit — GRE/IPsec tunnels, static routes, Magic WAN sites, connectors, and packet captures groups: advanced-dns-protection: description: Advanced Dns Protection operations advanced-tcp-protection: description: Advanced Tcp Protection operations apps: description: Application-aware traffic policies for Magic WAN that steer traffic by app type bgp-filter-profiles: description: BGP filter profiles for controlling which routes are allowed or denied on Magic Transit tunnels bgp-settings: description: BGP settings for controlling default ASN and route redistribution on Magic Transit tunnels cf-interconnects: description: Cloudflare Network Interconnect (CNI) links for direct physical or virtual peering gre-tunnels: description: GRE tunnel endpoints that connect your network to Cloudflare for Magic Transit ipsec-tunnels: description: IPsec tunnel endpoints with pre-shared key management for encrypted transit pcaps: description: Packet capture requests for debugging traffic flowing through Magic Transit tunnels routes: description: Static routes that direct IP prefix traffic through specific GRE/IPsec tunnels sites: description: Magic WAN branch sites — base CRUD, LAN/WAN interface configuration, ACLs, connectors, app configuration, and NetFlow config mcp: description: Manage MCP portals and upstream MCP servers for Cloudflare Access AI controls groups: portals: description: Manage MCP portals, attached servers, and Code Mode settings servers: description: Manage upstream MCP servers, credentials, capabilities, and sync state network-interconnects: description: Physical and virtual private interconnects between your infrastructure and Cloudflare's network groups: cnis: description: Cloud Network Interconnect (CNI) connections — private links from cloud providers to Cloudflare interconnects: description: Physical cross-connect and partner interconnect sessions with LOA and status tracking settings: description: Account-level interconnect settings and default configurations slots: description: Available interconnect facility slots showing port capacity at Cloudflare data centers organizations: description: Multi-user organizations that group accounts, members, and shared settings under a single entity groups: account-organizations: description: List organizations associated with a specific account accounts: description: Accounts operations members: description: Members operations members-batch-create: description: Members Batch Create operations organization-profile: description: View and update the public profile information for an organization shares: description: Shares operations origin-post-quantum-encryption: description: Enable post-quantum key exchange for connections between Cloudflare and your origin server pages: description: Full-stack application hosting with Git-integrated builds, preview deployments, and custom domains groups: projects: description: Pages projects, deployments, build logs, and custom domain bindings pipelines: description: Ingest, transform, and route event streams into R2, analytics, or other destinations in real time groups: sinks: description: Destinations where pipeline data is written — R2 buckets, HTTP endpoints, or other storage streams: description: Inbound data streams that feed events into a pipeline for processing precursor: description: Precursor settings for a zone queues: description: Reliable message queuing between Workers — produce, consume, and batch-process messages at scale groups: consumers: description: Workers that automatically receive and process messages from a queue messages: description: Push messages to a queue and pull or acknowledge them from consumers purge: description: Remove all pending messages from a queue subscriptions: description: Manage queue subscriptions for event-driven message routing r2: description: S3-compatible object storage with zero egress fees — buckets, lifecycle rules, event notifications, and data migration groups: buckets: description: Create and configure R2 buckets including CORS, lifecycle, custom domains, event notifications, and object locks buckets.jobs: description: Create and inspect background jobs for an R2 bucket buckets.local-uploads: description: R2 bucket local upload configuration super-slurper: description: Migrate data from external S3-compatible storage into R2 buckets with resumable transfer jobs temporary-credentials: description: Generate short-lived S3-compatible credentials scoped to specific buckets and operations r2-data-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables radar: description: Internet-wide traffic intelligence — BGP, DNS, HTTP trends, attack data, and network quality insights groups: agent-readiness: description: Agent readiness summary statistics across the Cloudflare network ai: description: AI inference trends and model usage statistics across the Cloudflare network annotations: description: Radar annotations marking significant Internet events (outages, cable cuts, etc.) as112: description: AS112 DNS sinkhole statistics — reverse DNS query volumes for private address space attacks: description: DDoS and application-layer attack trends, vectors, and target analysis bgp: description: BGP routing data — prefix announcements, AS-level stats, route leaks, and hijack events bots: description: Internet-wide bot traffic trends, categories, and distribution statistics ct: description: Certificate Transparency log monitoring and newly-issued certificate discovery datasets: description: Downloadable Radar datasets for offline analysis and research dns: description: Global DNS query trends — top domains, resolver stats, and DNSSEC adoption email: description: Email security trends — DMARC/SPF/DKIM adoption, spam, and phishing statistics entities: description: Look up ASNs, IPs, domains, and locations with metadata and traffic summaries geolocations: description: Geographic location metadata used for regional traffic analysis http: description: HTTP protocol trends — TLS versions, HTTP versions, browser share, and OS distribution leaked-credentials: description: Leaked credential detection trends and exposure statistics netflows: description: Network-layer traffic flow data and volumetric trend analysis origins: description: Cloud and hosting origin providers (e.g. Amazon, by region) and their traffic metrics post-quantum: description: Post-quantum encryption adoption and deployment trends across the Internet quality: description: Internet connection quality metrics — speed, latency, and jitter by geography and ASN ranking: description: Top domain rankings based on DNS query popularity across the Cloudflare network robots-txt: description: Robots.txt adoption and crawler directive trends across the web search: description: Search Radar data across IPs, ASNs, domains, and locations tcp-resets-timeouts: description: TCP connection reset and timeout statistics indicating network health issues tlds: description: Top-level domain (TLD) metadata and performance trends traffic-anomalies: description: Detected traffic anomalies and unusual patterns in Internet traffic flows verified-bots: description: Catalog of known good bots (Googlebot, Bingbot, etc.) and their traffic patterns rate-limits: description: Legacy per-zone rate limiting rules — prefer Advanced Rate Limiting in Rulesets for new configurations realtime: description: Real-time audio, video, and data services on Cloudflare's global network groups: kit: description: SDK-backed meetings, participants, recordings, livestreams, and webhooks kit.analytics: description: Usage and livestream analytics for RealtimeKit applications kit.analytics.livestreams: description: Livestream analytics for RealtimeKit applications kit.analytics.livestreams.daily: description: Daily livestream analytics for RealtimeKit applications kit.analytics.usage: description: Usage analytics for RealtimeKit applications kit.apps: description: RealtimeKit applications that group meetings, sessions, and configuration kit.livestreams: description: Independent and meeting-based livestreams and their sessions kit.livestreams.sessions: description: Sessions for RealtimeKit livestreams kit.meetings: description: Meetings, participants, access tokens, and meeting livestreams kit.meetings.active: description: Live meeting state and participant controls kit.meetings.active.polls: description: Polls for active meeting sessions kit.meetings.livestream: description: Livestream operations associated with RealtimeKit meetings kit.meetings.participants: description: Participants in RealtimeKit meetings kit.meetings.participants.tokens: description: Access tokens for RealtimeKit meeting participants kit.presets: description: Reusable meeting configuration for media, permissions, and interface behavior kit.recordings: description: Meeting and participant-track recordings and recording controls kit.recordings.active: description: Active recordings for RealtimeKit meetings kit.recordings.tracks: description: Participant-track recordings for RealtimeKit meetings kit.sessions: description: Historical session data, participants, chat, transcripts, and summaries kit.sessions.chat: description: Chat messages from historical RealtimeKit sessions kit.sessions.livestreams: description: Livestreams associated with historical RealtimeKit sessions kit.sessions.participants: description: Participants in historical RealtimeKit sessions kit.sessions.peers: description: Peer details from historical RealtimeKit sessions kit.sessions.summaries: description: Summaries of historical RealtimeKit sessions kit.sessions.transcripts: description: Transcripts from historical RealtimeKit sessions kit.webhooks: description: Webhook endpoints and supported events for RealtimeKit notifications kit.webhooks.events: description: Supported events for RealtimeKit webhooks moq: description: MoQ relays for publishing and subscribing to media streams moq.relays: description: Relays are isolated MoQ scopes that carry media between publishers and subscribers moq.relays.tokens: description: Tokens that authorize publishers and subscribers to connect to a relay sfu: description: SFU apps that route WebRTC media and data between participants sfu.apps: description: SFU application namespaces for sessions and tracks turn: description: TURN keys that help clients traverse NATs and firewalls turn.keys: description: Keys used to generate short-lived TURN credentials request-tracers: description: Trace how a request would be processed through Cloudflare's rules and configuration pipeline groups: traces: description: Simulate request processing to debug rule matches, transforms, and routing decisions resource-sharing: description: Share Cloudflare resources (zones, accounts) across organizations with granular access controls groups: recipients: description: Update share recipients resources: description: Individual resources (zones, configs) that have been shared with recipients rules: description: Resources used by Cloudflare rules and rulesets groups: lists: description: Custom account-level lists of IPs, hostnames, ASNs, or redirects used in rule expressions rum: description: Real User Measurement (Web Analytics) — track page loads, Core Web Vitals, and visitor metrics groups: rules: description: Rules that control which pages and paths are tracked by Web Analytics site-info: description: Web Analytics sites — register domains and get the JavaScript beacon snippet scim: description: SCIM 2.0 provisioning — manage users, groups, and identity provider sync for your account groups: groups: description: Groups operations resource-types: description: Resource Types operations schemas: description: Schemas operations service-provider-config: description: Service Provider Config operations users: description: Users operations secrets-store: description: Centralized secret management — store API keys, tokens, and credentials for use across Workers and other products groups: quota: description: Account quota limits for secrets stores, secrets count, and storage capacity secrets: description: Encrypted key-value secrets within a store. Pass --store-id to scope. stores: description: Secret stores that hold encrypted key-value secrets accessible by Workers and services security-center: description: Security posture dashboard — view and manage security insights, misconfigurations, and vulnerabilities groups: insights: description: Security findings and recommendations across your account — DNS, SSL, WAF misconfigurations, etc. zone-insights: description: Zone-scoped security insights — counts by class, severity, type, and dismissal security-txt: description: Manage the /.well-known/security.txt file that tells security researchers how to report vulnerabilities smart-shield: description: Smart Shield settings, health checks, and cache reserve management groups: cache-reserve-clear: description: Cache Reserve Clear operations health-checks: description: Health checks operations spectrum: description: Proxy and protect arbitrary TCP/UDP applications through Cloudflare's network with DDoS mitigation groups: analytics: description: Real-time and historical connection analytics for Spectrum applications apps: description: Spectrum application configurations that map protocols and ports to origin servers speed: description: Observatory speed tests — run Lighthouse audits, track performance trends, and schedule recurring tests groups: availabilities: description: Check which speed test regions and configurations are available for your zone pages: description: Tested pages with their performance history, trends, and individual test results schedule: description: Scheduled recurring speed tests that automatically run at regular intervals ssl: description: SSL/TLS certificate management — certificate packs, Universal SSL, verification, and TLS mode recommendations groups: automatic-upgrader: description: SSL automatic mode enrollment — get or update automatic SSL/TLS upgrader settings recommendations: description: Get the recommended SSL/TLS encryption mode based on your origin server's certificate configuration stream: description: Video encoding, storage, and delivery — upload, live-stream, clip, caption, and embed video at scale groups: audio-tracks: description: Add, edit, or remove additional audio tracks on a video captions: description: Upload, generate, or retrieve captions and subtitles for videos in multiple languages clip: description: Create a new video clip from an existing video by specifying start and end times copy: description: Import a video from a URL into Stream for processing and delivery direct-upload: description: Generate a tokenized URL that lets end-users upload video directly to Stream downloads: description: Create downloadable MP4 renditions of a video for offline viewing embed: description: Retrieve the HTML embed code snippet for a video keys: description: Signing keys used to generate short-lived signed URLs for private video playback live-inputs: description: Enable and disable live input streams token: description: Generate short-lived signed URL tokens for secure private video playback typed-downloads: description: Type-specific stream download creation and deletion videos: description: Aggregate video storage usage statistics for the account watermarks: description: Watermark profiles that overlay an image on every video in the account webhooks: description: Webhook notifications for video lifecycle events (ready, error, etc.) tenants: description: Multi-tenant account management — manage tenant accounts, entitlements, and memberships groups: account-types: description: Account Types operations accounts: description: Accounts operations entitlements: description: Entitlements operations memberships: description: Memberships operations turnstile: description: CAPTCHA-free bot verification widgets that protect forms and APIs without degrading user experience groups: widgets: description: Turnstile widget configurations — site keys, secret rotation, and challenge mode settings url-scanner: description: Scan URLs for phishing, malware, and other threats — submit scans and retrieve detailed results groups: response: description: Response operations responses: description: Raw HTTP response data captured during URL scans scan: description: Scan operations scans: description: URL scan requests and results — submit URLs for analysis and retrieve threat verdicts user: description: Your Cloudflare user profile, invitations, organizations, billing, and personal API tokens groups: billing: description: View billing history and payment profile for your user (deprecated — prefer account-level billing) firewall: description: Firewall operations load-balancers.monitors: description: Load Balancers operations load-balancers.monitors.preview: description: Load Balancers operations load-balancers.monitors.references: description: Load Balancers operations load-balancers.pools: description: Load Balancers operations load-balancers.pools.edit.pools: description: Load Balancers operations load-balancers.pools.health: description: Load Balancers operations load-balancers.pools.preview: description: Load Balancers operations load-balancers.pools.references: description: Load Balancers operations load-balancers.preview: description: Load Balancers operations load-balancing-analytics.events: description: Load Balancing Analytics operations subscriptions: description: View and manage zone-level plan subscriptions owned by your user tenants: description: Tenants operations tokens: description: Create and manage personal API tokens scoped to your user for programmatic API access user.analytics: description: User-level traffic analytics — aggregated totals and timeseries across all zones vectorize: description: Globally distributed vector database for building semantic search, recommendations, and RAG applications on Workers groups: deprecated-indexes: description: Deprecated v1 Vectorize index operations metadata-index: description: Metadata indexes for filtered vector search waiting-rooms: description: Virtual queues that throttle traffic to your site during peak demand with customizable waiting pages groups: account-waiting-rooms: description: Account-scoped waiting room listing events: description: Scheduled events that temporarily override waiting room settings for sales, launches, etc. page: description: Custom HTML waiting page templates and preview rendering rules: description: Rules that bypass or modify waiting room behavior for specific request patterns settings: description: Zone-level waiting room defaults and cookie configuration statuses: description: Real-time queue status showing active users, queued users, and estimated wait times workflows: description: Durable, multi-step workflows that run on Workers with automatic retries and state persistence groups: instances: description: Workflow instance operations versions: description: Workflow version operations zaraz: description: Server-side tag manager — load third-party tools (analytics, pixels, etc.) from Cloudflare's edge without client-side JS groups: config: description: Full Zaraz configuration including tools, triggers, and variables for the zone default: description: Default Zaraz configuration template used as a starting point for new zones export: description: Export the current Zaraz configuration as a portable JSON document history: description: Configuration version history — browse and restore previous Zaraz configurations publish: description: Publish pending Zaraz configuration changes to make them live on the zone workflow: description: Workflow state for Zaraz configuration changes (draft vs. published) zero-trust: description: Cloudflare's SASE platform — secure access, device posture, DLP, tunnels, gateway policies, and network segmentation groups: dex: description: Digital Experience Monitoring — synthetic tests, fleet-wide device metrics, and network path diagnostics dlp.custom-prompt-topics: description: Data Loss Prevention - manage custom prompt topics for AI-based content detection dlp.data-classes: description: Data Loss Prevention - manage data classes used to classify sensitive information dlp.data-tag-categories: description: Data Loss Prevention - manage categories that organize data tags dlp.data-tag-category-templates: description: Data Loss Prevention - browse templates for creating data tag categories dlp.data-tags: description: Data Loss Prevention - manage tags used to classify and organize sensitive data dlp.datasets: description: Data Loss Prevention - manage datasets, versions, and uploads dlp.document-fingerprints: description: Data Loss Prevention - manage document fingerprints for detecting matching documents dlp.email.account-mapping: description: Data Loss Prevention - configure account mappings for outbound email scanning dlp.email.rules: description: Data Loss Prevention - manage outbound email scanning rules and their priorities dlp.entries: description: Data Loss Prevention - list and manage detection entries dlp.limits: description: Data Loss Prevention - view account limits and resource quotas dlp.patterns: description: Data Loss Prevention - validate regular expressions used for content detection dlp.profiles: description: Data Loss Prevention - list and retrieve profiles dlp.profiles.custom: description: Data Loss Prevention - manage custom profiles dlp.profiles.predefined: description: Data Loss Prevention - manage predefined profiles dlp.sensitivity-group-templates: description: Data Loss Prevention - browse templates for creating sensitivity groups dlp.sensitivity-groups: description: Data Loss Prevention - manage sensitivity groups and their level ordering dlp.sensitivity-levels: description: Data Loss Prevention - manage sensitivity levels within sensitivity groups dlp.settings: description: Data Loss Prevention - manage account-level settings dlp.validators: description: Data Loss Prevention - list and retrieve content validators dlp.validators.proximity-words: description: Data Loss Prevention - manage proximity-word validators risk-scoring: description: User Risk Scoring - retrieve and reset user risk scores risk-scoring.behaviours: description: User Risk Scoring - manage behaviors used to calculate user risk scores risk-scoring.integrations: description: User Risk Scoring - manage integrations that provide risk score signals risk-scoring.integrations.references: description: User Risk Scoring - retrieve integrations by external reference risk-scoring.summary: description: User Risk Scoring - retrieve account risk score summaries zones: description: Zones are domains on Cloudflare — list, create, and configure domain settings groups: aegis: description: Aegis operations fonts: description: Fonts operations origin-h2-max-streams: description: Origin H2 Max Streams operations origin-max-http-version: description: Origin Max Http Version operations origin-tls-compliance-modes: description: Manage zone Origin TLS Compliance Modes setting rum: description: Rum operations speed-brain: description: Speed Brain operations