openapi: 3.2.0 info: description: Welcome to Cloudflare's API documentation site. license: name: BSD-3-Clause url: https://opensource.org/licenses/BSD-3-Clause title: Cloudflare Findings API version: 4.0.0 servers: - description: Client API url: https://api.cloudflare.com/client/v4 security: - api_email: [] api_key: [] - api_token: [] - user_service_key: [] tags: - name: Findings paths: /accounts/{account_id}/data-security/posture/findings: get: operationId: ListFindings summary: List posture findings description: 'List all security findings that have been identified as being problematic. This will return a list of findings regardless if they have been ignored or not.' parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - name: cursor in: query description: A cursor for pagination. Obtained from the `result_info.cursor` field of a previous response. schema: type: string - $ref: '#/components/parameters/posture-api_Direction' - $ref: '#/components/parameters/posture-api_Ignored' - $ref: '#/components/parameters/posture-api_IntegrationId' - $ref: '#/components/parameters/posture-api_MaxAfflictionDate' - $ref: '#/components/parameters/posture-api_MinAfflictionDate' - $ref: '#/components/parameters/posture-api_Observation' - $ref: '#/components/parameters/posture-api_FindingOrder' - $ref: '#/components/parameters/posture-api_Page' - $ref: '#/components/parameters/posture-api_PerPage' - $ref: '#/components/parameters/posture-api_Product' - $ref: '#/components/parameters/posture-api_Search' - $ref: '#/components/parameters/posture-api_Severity' - $ref: '#/components/parameters/posture-api_Type' - $ref: '#/components/parameters/posture-api_Vendor' - $ref: '#/components/parameters/posture-api_FindingTypeIds' responses: '200': description: 'OK: Successful HTTP request' content: application/json: schema: $ref: '#/components/schemas/posture-api_paginated-finding-list' '400': description: 'Bad Request: Invalid parameters' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '401': description: 'Unauthorized: Authentication required' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '403': description: 'Forbidden: Insufficient permissions' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' security: - api_token: [] tags: - Findings x-api-token-group: - Zero Trust Read - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.casb.findings x-fern-sdk-method-name: list /accounts/{account_id}/data-security/posture/findings/ignore: post: operationId: IgnoreFinding summary: Mark a finding as ignored description: Given a list of findings, mark as ignored. Does nothing if Finding is already ignored. parameters: - $ref: '#/components/parameters/posture-api_AccountTag' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/posture-api_FindingBulkActionRequest' responses: '200': description: 'OK: Successful HTTP request' content: application/json: schema: $ref: '#/components/schemas/posture-api_finding-response' '400': description: 'Bad Request: Invalid request parameters' security: - api_token: [] tags: - Findings x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.casb.findings x-fern-sdk-method-name: ignore /accounts/{account_id}/data-security/posture/findings/unignore: post: operationId: UnIgnoreFinding summary: Remove ignore marker from a finding description: Ability to un-ignore a Finding if it's previously been ignored. Does nothing if the Finding is not ignored. parameters: - $ref: '#/components/parameters/posture-api_AccountTag' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/posture-api_FindingBulkActionRequest' responses: '200': description: 'OK: Successful HTTP request' content: application/json: schema: $ref: '#/components/schemas/posture-api_finding-response' '400': description: 'Bad Request: Invalid request parameters' security: - api_token: [] tags: - Findings x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.casb.findings x-fern-sdk-method-name: unignore /accounts/{account_id}/data-security/posture/findings/{finding_id}: get: operationId: GetFinding summary: Get a posture finding description: Gets a security Finding that has been identified as being problematic. parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - $ref: '#/components/parameters/posture-api_FindingIdByte' responses: '200': description: 'OK: Successful HTTP request' content: application/json: schema: $ref: '#/components/schemas/posture-api_finding-response' '400': description: 'Bad Request: Invalid finding ID' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '401': description: 'Unauthorized: Authentication required' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '403': description: 'Forbidden: Insufficient permissions' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '404': description: 'Not Found: Finding not found' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' security: - api_token: [] tags: - Findings x-api-token-group: - Zero Trust Read - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.casb.findings x-fern-sdk-method-name: get /accounts/{account_id}/data-security/posture/findings/{finding_id}/instances: get: operationId: ListFindingInstances summary: List instances of a finding description: Lists all security finding instances for a given security finding. parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - $ref: '#/components/parameters/posture-api_Archived' - $ref: '#/components/parameters/posture-api_FindingIdByte' - name: cursor in: query description: A cursor for pagination. Obtained from the `result_info.cursor` field of a previous response. schema: type: string - $ref: '#/components/parameters/posture-api_Direction' - $ref: '#/components/parameters/posture-api_MaxAfflictionDate' - $ref: '#/components/parameters/posture-api_MinAfflictionDate' - $ref: '#/components/parameters/posture-api_FindingInstanceOrder' - $ref: '#/components/parameters/posture-api_Page' - $ref: '#/components/parameters/posture-api_PerPage' - $ref: '#/components/parameters/posture-api_Search' - $ref: '#/components/parameters/posture-api_RemediationStatuses' - $ref: '#/components/parameters/posture-api_FindingInstanceIds' - $ref: '#/components/parameters/posture-api_AssetIds' responses: '200': description: 'OK: Successful HTTP request' content: application/json: schema: $ref: '#/components/schemas/posture-api_paginated-finding-instance-list' '400': description: 'Bad Request: Invalid request parameters' '404': description: 'Not Found: Finding not found' security: - api_token: [] tags: - Findings x-api-token-group: - Zero Trust Read - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.casb.findings.instances x-fern-sdk-method-name: list /accounts/{account_id}/data-security/posture/findings/{finding_id}/instances/archive: post: operationId: ArchiveFindingInstance summary: Archive a finding description: Archive one or more finding instances. parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - $ref: '#/components/parameters/posture-api_FindingIdByte' requestBody: content: application/json: schema: $ref: '#/components/schemas/posture-api_FindingInstanceBulkActionRequest' responses: '200': description: 'OK: Successful HTTP request' content: application/json: schema: $ref: '#/components/schemas/posture-api_finding-instance-response' '400': description: 'Bad Request: Invalid request parameters' '404': description: 'Not Found: Finding not found' security: - api_token: [] tags: - Findings x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.casb.findings.instances x-fern-sdk-method-name: archive /accounts/{account_id}/data-security/posture/findings/{finding_id}/instances/unarchive: post: operationId: UnarchiveFindingInstance summary: Remove the archive marking from a finding instance description: Remove the archive marking from one or more finding instances. parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - $ref: '#/components/parameters/posture-api_FindingIdByte' requestBody: content: application/json: schema: $ref: '#/components/schemas/posture-api_FindingInstanceBulkActionRequest' responses: '200': description: 'OK: Successful HTTP request' content: application/json: schema: $ref: '#/components/schemas/posture-api_finding-instance-response' '400': description: 'Bad Request: Invalid request parameters' '404': description: 'Not Found: Finding not found' security: - api_token: [] tags: - Findings x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.casb.findings.instances x-fern-sdk-method-name: unarchive /accounts/{account_id}/data-security/posture/findings/{finding_id}/instances/{instance_id}: get: operationId: GetFindingInstance summary: Get a finding instance using an instance ID description: Gets a security Finding instance by id. parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - $ref: '#/components/parameters/posture-api_FindingIdByte' - $ref: '#/components/parameters/posture-api_FindingInstanceId' responses: '200': description: 'OK: Successful HTTP request' content: application/json: schema: $ref: '#/components/schemas/posture-api_finding-instance-response' '400': description: 'Bad Request: Invalid request parameters' '404': description: 'Not Found: Finding instance not found' security: - api_token: [] tags: - Findings x-api-token-group: - Zero Trust Read - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.casb.findings.instances x-fern-sdk-method-name: get /accounts/{account_id}/data-security/posture/findings/{finding_id}/reset_finding_severity: post: operationId: ResetFindingSeverity summary: Reset severity for a finding back to the default description: 'If a Finding''s severity has been changed, reset it back to default value. Does nothing if no override exists.' parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - $ref: '#/components/parameters/posture-api_FindingIdByte' responses: '200': description: 'OK: Successful HTTP request' content: application/json: schema: $ref: '#/components/schemas/posture-api_finding-response' '400': description: 'Bad Request: Invalid request parameters' '404': description: 'Not Found: Finding not found' '500': description: 'Internal Server Error: Unexpected failure resetting finding severity' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' security: - api_token: [] tags: - Findings x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.casb.findings x-fern-sdk-method-name: reset-severity /accounts/{account_id}/data-security/posture/findings/{finding_id}/tune_finding_severity: post: operationId: ChangeFindingSeverity summary: Update the severity for a finding description: 'Update the severity of a Finding. This will update the `severity_override` field on the Finding payload with the new severity value.' parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - $ref: '#/components/parameters/posture-api_FindingIdByte' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/posture-api_TuneFindingSeverityRequest' responses: '200': description: 'OK: Successful HTTP request' content: application/json: schema: $ref: '#/components/schemas/posture-api_finding-response' '400': description: 'Bad Request: Invalid request parameters' '404': description: 'Not Found: Finding not found' '500': description: 'Internal Server Error: Unexpected failure updating finding severity' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' security: - api_token: [] tags: - Findings x-api-token-group: - Zero Trust Write x-fern-availability: generally-available x-fern-sdk-group-name: zero-trust.casb.findings x-fern-sdk-method-name: tune-severity components: schemas: posture-api_RemediationJobStatusEnum: description: Status of a remediation job. type: string example: pending enum: - pending - processing - completed - failed - validating posture-api_FindingType: type: object allOf: - $ref: '#/components/schemas/posture-api_BaseFindingType' - properties: remediation: $ref: '#/components/schemas/posture-api_FindingRemediation' type: object required: - category - id - name - remediation - severity - vendor posture-api_error-response: description: Standard error response structure. type: object properties: errors: $ref: '#/components/schemas/posture-api_messages' messages: $ref: '#/components/schemas/posture-api_messages' success: description: Indicates the request failed. type: boolean example: false enum: - false required: - success - errors - messages posture-api_api-response-collection: description: Response structure for paginated collections. type: object properties: errors: $ref: '#/components/schemas/posture-api_messages' messages: $ref: '#/components/schemas/posture-api_messages' result_info: $ref: '#/components/schemas/posture-api_result-info' success: description: Whether the API call was successful. type: boolean example: true required: - success - errors - messages - result_info posture-api_finding-instance-response: type: object allOf: - $ref: '#/components/schemas/posture-api_api-response-common' - properties: result: $ref: '#/components/schemas/posture-api_FindingInstance' type: object posture-api_finding-response: type: object allOf: - $ref: '#/components/schemas/posture-api_api-response-common' - properties: result: $ref: '#/components/schemas/posture-api_Finding' type: object posture-api_FindingCategory: description: Category information for a finding. type: object properties: observation: $ref: '#/components/schemas/posture-api_ObservationEnum' product: $ref: '#/components/schemas/posture-api_ProductEnum' type: $ref: '#/components/schemas/posture-api_FindingCategoryTypeEnum' example: observation: Issue product: SaaS type: Posture required: - observation - product - type posture-api_DlpContext: description: DLP context information for a finding. type: object properties: created: description: When the DLP context was created. type: string format: date-time example: '2025-03-18T17:25:38.695977Z' readOnly: true deleted: description: When the DLP context was deleted. type: - string - 'null' format: date-time example: '2025-03-18T17:25:38.695977Z' entry_ids: description: DLP Entry IDs. type: array items: format: uuid type: string example: - 21befc68-a297-4090-ac10-17a051b901cd - d6dd1e16-f78c-401a-b564-45c4e44aa467 id: description: Unique identifier for the DLP context. type: string format: uuid example: 7653ff3a-d25e-4c10-8034-3460937c045b match_context_max_extent: description: DLP Right Boundary of match context. type: - integer - 'null' example: 512 maximum: 2147483647 minimum: 0 match_context_min_extent: description: DLP Left Boundary of match context. type: - integer - 'null' example: 1 maximum: 2147483647 minimum: 0 match_context_payload: description: DLP Match context payload that matched the profile in question. type: - object - 'null' example: {} additionalProperties: true profile_id: description: DLP Profile ID. type: string format: uuid example: ab20a60b-21f2-4b13-ac98-24dcee27ac0e updated: description: When the DLP context was last updated. type: string format: date-time example: '2025-03-18T17:25:38.695977Z' readOnly: true required: - created - entry_ids - profile_id - updated posture-api_IntegrationPolicy: description: Policy configuration for an integration. type: object properties: client_id: description: OAuth client ID for the policy. type: - string - 'null' compliance_level: description: Compliance level for the policy. type: string example: standard dlp_enabled: description: Whether DLP is enabled for this policy. type: boolean example: true id: description: Policy identifier. type: string format: uuid example: d647642e-09ac-4b34-8acc-ac30f57adc2c link: description: Link to policy documentation. type: - string - 'null' format: uri name: description: Policy name. type: string example: Google Workspace Standard Policy permissions: description: List of permissions included in the policy. type: array items: type: string example: - https://www.googleapis.com/auth/admin.directory.domain.readonly - https://www.googleapis.com/auth/admin.directory.user.readonly example: compliance_level: standard dlp_enabled: true id: d647642e-09ac-4b34-8acc-ac30f57adc2c name: Google Workspace Standard Policy posture-api_BaseFindingType: description: Basic finding type information. type: object properties: category: type: object allOf: - $ref: '#/components/schemas/posture-api_FindingCategory' - readOnly: true type: object description: description: Detailed description of the finding. type: - string - 'null' example: This finding indicates that a file in your Slack workspace is publicly accessible. id: description: The unique identifier of the finding. type: string format: uuid example: a20895dd-9c3b-43bd-a608-71c98c6c2d94 readOnly: true name: description: The name of the finding. type: string example: Slack File Publicly Accessible severity: type: string allOf: - $ref: '#/components/schemas/posture-api_SeverityEnum' - description: Default severity used when no integration-specific severity override exists. type: string vendor: description: The SaaS/Cloud vendor of the platform with which the finding is associated. type: string example: Google Workspace readOnly: true required: - id - name - category - vendor - severity posture-api_RemediationJobSummary: description: Summary information about a remediation job. type: object properties: created_at: description: When the remediation job was created. type: string format: date-time example: '2025-03-18T18:30:15.123456Z' id: description: Unique identifier for the remediation job. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 stale: description: Whether this remediation job is stale (created before the finding instance's affliction_date). type: boolean example: false status: $ref: '#/components/schemas/posture-api_RemediationJobStatusEnum' example: created_at: '2025-03-18T18:30:15.123456Z' id: 123e4567-e89b-12d3-a456-426614174000 stale: false status: pending required: - id - status - created_at - stale posture-api_FindingCategoryTypeEnum: description: The type of the finding category. type: string example: Content enum: - Content - Posture posture-api_paginated-finding-instance-list: type: object allOf: - $ref: '#/components/schemas/posture-api_api-response-collection' - properties: result: description: Array of finding instance objects. type: array items: $ref: '#/components/schemas/posture-api_FindingInstance' type: object posture-api_VendorsEnum: description: Supported vendor types for integrations. type: string example: GOOGLE_WORKSPACE enum: - ANTHROPIC - AWS - BITBUCKET - BOX - CONFLUENCE - DROPBOX - GITHUB - GOOGLE_CLOUD_PLATFORM - GOOGLE_WORKSPACE - JIRA - MICROSOFT - MICROSOFT_INTERNAL - OPENAI - SALESFORCE - SERVICENOW - SLACK - ZOOM posture-api_api-response-common: description: Common response structure for all API endpoints. type: object properties: errors: $ref: '#/components/schemas/posture-api_messages' messages: $ref: '#/components/schemas/posture-api_messages' success: description: Whether the API call was successful. type: boolean example: true required: - success - errors - messages posture-api_IntegrationSummary: description: Summary information about an integration. type: object properties: created: description: When entity was created. type: string format: date-time example: '2021-08-10T20:16:11.851451Z' readOnly: true credential_health_status: $ref: '#/components/schemas/posture-api_CredentialHealthStatusEnum' credentials_expiry: description: The date and time when the integration credentials will expire. type: - string - 'null' format: date-time example: '2025-03-18T17:25:38.697902Z' id: description: Integration ID. type: string format: uuid example: c416bc38-75dc-425f-ae25-c37b5df5c37f is_paused: description: Whether the given integration is paused by the user. type: boolean example: false default: false last_hydrated: description: When were the integration credentials last updated. type: string format: date-time example: '2025-03-18T17:25:38.697894Z' readOnly: true name: description: Name of the integration. type: string example: Example integration maxLength: 256 permissions: description: The vendor-specific permissions associated with the integration. type: array items: type: string example: - GroupMember.Read.All - Group.Read.All readOnly: true policy: $ref: '#/components/schemas/posture-api_IntegrationPolicy' status: description: Current status of the integration. type: string example: Healthy readOnly: true updated: description: Last entity was updated. type: string format: date-time example: '2021-08-10T20:16:11.851451Z' readOnly: true upgradable: description: Whether the integrations permissions can be updated. type: boolean example: false readOnly: true upgrade_dismissed: description: UI State as to whether a potential permissions upgrade has been dismissed. type: boolean example: false default: false vendor: $ref: '#/components/schemas/posture-api_Vendor' zt_enrollments: description: Zero Trust products associated with this integration. type: array items: $ref: '#/components/schemas/posture-api_ZeroTrustProduct' readOnly: true required: - created - last_hydrated - name - permissions - policy - status - updated - upgradable - vendor - zt_enrollments posture-api_FindingRemediation: description: Remediation guide information for a finding. type: - object - 'null' properties: frameworks: description: Relevant Compliance Frameworks. type: array items: type: string example: - SOC2 - ISO27001 readOnly: true guide: description: Remediation guide text. type: string example: To fix this issue, update the file permissions to remove public access. id: description: Remediation Id. type: string format: uuid example: a20895dd-9c3b-43bd-a608-71c98c6c2d94 readOnly: true impact: description: Description of the potential impact. type: string example: Publicly accessible files may expose sensitive information. locale: description: I18N Locale. type: string example: en-US readOnly: true threat: description: Description of the threat. type: string example: Data exposure and potential compliance violations. required: - frameworks - guide - id - impact - locale - threat posture-api_FindingInstance: description: A specific instance of a security finding. In the API interface, we refer to the 'finding' table in our DB as finding instances, optimized for the p99 use case. type: object properties: affliction_date: description: When this specific instance was identified. type: string format: date-time example: '2025-03-18T17:25:38.700541Z' asset: $ref: '#/components/schemas/posture-api_Asset' dlp_contexts: description: DLP context information if this is a content finding. type: array items: $ref: '#/components/schemas/posture-api_DlpContext' readOnly: true id: description: Unique identifier for the finding instance. type: string format: uuid example: 497f6eca-6276-4993-bfeb-53cbbbba6f08 is_archived: description: Whether this finding instance has been archived. type: boolean example: false default: false remediations: description: A list of the 10 most recent remediation jobs for this finding instance, ordered by creation time (most recent first). The 'stale' field indicates whether the remediation job was created before the finding instance's affliction_date (true) or after it (false). If there has never been a remediation job for this finding instance, this field will be an empty array. type: array items: $ref: '#/components/schemas/posture-api_RemediationJobSummary' webhooks: description: The most recent webhook job invocation for each webhook configuration associated with this finding instance. Each entry represents the latest job (any status) per webhook config. The 'stale' field indicates whether the job was invoked before the finding instance's current affliction_date. If no webhook jobs have been created, this field will be an empty array. type: array items: $ref: '#/components/schemas/posture-api_WebhookInvocationSummary' required: - affliction_date - asset - dlp_contexts - remediations - webhooks posture-api_AssetField: description: Additional field information for an asset. type: object properties: link: description: Optional link associated with the field. type: - string - 'null' format: uri example: https://example.com name: description: The name of the field. type: string example: File Name value: description: The value of the field. type: string example: sensitive-document.xlsx example: link: https://example.com name: Credential name value: Test asset 2 required: - name - value posture-api_FindingBulkActionRequest: description: Request body for bulk actions on findings. type: object properties: checks: description: A list of finding IDs to pass along. type: array items: maxLength: 512 minLength: 1 type: string example: - MDAwMDAwMDAtMDAwMC0wMDAwLTAwMDAtMDAwMDAwMDAwMDAxOjAwMDAwMDAwLTAwMDAtMDAwMC0wMDAwLTAwMDAwMDAwMDAwMgo= maxItems: 500 minItems: 1 required: - checks posture-api_Vendor: description: Information about a vendor/service provider. type: object properties: description: description: Detailed information about what kinds of issues are detected for this vendor. type: - string - 'null' example: Identify important security issues across your Google Workspace account ranging from shadow IT, misconfigurations, user access, and more. display_name: description: The display name of the vendor. type: string example: Google Workspace id: description: The id of the vendor. type: string example: R09PR0xFX1dPUktTUEFDRQ== logo: description: Logo URL for the vendor. type: string format: uri example: https://cdn.vectrix-infra.com/DetectionPack_Logos/GoogleWorkspace/g.png name: description: The name of the vendor. type: string example: GOOGLE_WORKSPACE policies: description: The policies related to the vendor. type: array items: additionalProperties: true type: object example: [] static_logo: description: Static logo URL for the vendor. type: string format: uri example: https://onprem.cloudflare.come/DetectionPack_Logos/GoogleWorkspace/g.png zt_enrollments: description: The vendor's compatible Zero Trust products. type: array items: type: string example: - casb required: - description - display_name - id - logo - name - static_logo - zt_enrollments posture-api_Finding: description: Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics. type: object properties: active_count: description: Number of active problematic instances identified in the security finding. type: integer example: 5 readOnly: true archived_count: description: Number of archived instances identified in the security finding. type: integer example: 2 readOnly: true finding: $ref: '#/components/schemas/posture-api_FindingType' id: description: Base64 encoded identifier of the security finding. type: string format: byte example: MDAwMDAwMDAtMDAwMC0wMDAwLTAwMDAtMDAwMDAwMDAwMDAxOjAwMDAwMDAwLTAwMDAtMDAwMC0wMDAwLTAwMDAwMDAwMDAwMgo= readOnly: true ignored: description: Determines if finding is currently ignored. type: boolean example: false readOnly: true instance_count: description: Number of total (Active or archived) problematic instances identified in the security finding. type: integer example: 7 readOnly: true integration: $ref: '#/components/schemas/posture-api_IntegrationSummary' latest_affliction_date: description: Timestamp of the latest affliction date of an active finding. type: string format: date-time example: '2025-03-18T17:25:38.700131Z' readOnly: true severity_override: $ref: '#/components/schemas/posture-api_FindingSeverityOverride' required: - active_count - archived_count - finding - id - ignored - instance_count - integration - latest_affliction_date posture-api_FindingInstanceBulkActionRequest: description: Request body for bulk actions on finding instances. type: object properties: check_instances: description: A list of finding instance IDs to pass along. type: array items: format: uuid type: string example: - 497f6eca-6276-4993-bfeb-53cbbbba6f08 required: - check_instances posture-api_ProductEnum: description: The product category. type: string example: SaaS enum: - SaaS - Cloud posture-api_ZeroTrustProduct: description: Information about a Zero Trust product integration. type: object properties: description: description: Brief description of the Zero Trust Product. type: string example: example display_name: description: The verbose name of the Zero Trust Product. type: string example: Cloud Access Security Broker enabled: description: Flag to enable/disable access to the listed integration from the corresponding Cloudflare product. type: boolean example: true default: false id: description: The internal identifier of the Zero Trust Product. type: string example: casb example: description: example display_name: Cloud Access Security Broker enabled: true id: casb posture-api_TuneFindingSeverityRequest: description: Request body for updating a finding's severity. type: object properties: new_severity: description: The numeric severity value to apply to the finding. type: integer enum: - 1 - 2 - 3 - 4 required: - new_severity posture-api_messages: type: array items: properties: code: description: Error or message code. type: integer example: 1000 minimum: 1000 documentation_url: description: Link to relevant documentation. type: string format: uri example: https://developers.cloudflare.com/api/operations/list-findings message: description: Human-readable message. type: string example: Request processed successfully source: type: object properties: pointer: description: JSON pointer to the source of the error. type: string example: /data/attributes/name required: - code - message type: object example: [] uniqueItems: true posture-api_FindingSeverityOverride: description: Override information for finding severity. type: object properties: created_by: description: User ID who created the override. type: string example: '1234' severity: $ref: '#/components/schemas/posture-api_SeverityEnum' example: created_by: '1234' severity: Critical required: - created_by - severity posture-api_AssetCategory: description: Category information for an asset. type: object properties: id: description: Unique identifier for the asset category. type: string format: uuid example: 1a78cbf3-b98f-4289-b1f2-22db64130f4f service: description: The specific service within the vendor the asset is part of (often none). Example - AWS is the vendor, S3 is the service. type: - string - 'null' example: OneDrive type: description: The type of asset. type: string example: file vendor: description: The vendor the asset is part of. type: string example: Slack readOnly: true example: id: 1a78cbf3-b98f-4289-b1f2-22db64130f4f service: null type: file vendor: Slack required: - service - type - vendor posture-api_ObservationEnum: description: The type of the observation. type: string example: Issue enum: - Issue - Insight - Activity posture-api_WebhookInvocationSummary: description: Summary of the most recent webhook job invocation for a specific webhook configuration. type: object properties: latest_job: description: The most recent webhook job for this webhook configuration. type: object properties: created_at: description: When the webhook job was created. type: string format: date-time example: '2025-03-18T18:30:15.123456Z' id: description: Unique identifier for the webhook job. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 stale: description: Whether this webhook job is stale (created before the finding instance's current affliction_date). type: boolean example: false status: description: Current status of the webhook job. type: string example: pending enum: - pending - processing - completed required: - id - status - created_at - stale webhook_id: description: Unique identifier for the webhook configuration. type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 webhook_label: description: Account-specified display label for the webhook configuration. type: string example: Send to Gmail required: - webhook_id - webhook_label - latest_job posture-api_SeverityEnum: description: The severity level of a finding. type: string example: High enum: - Critical - High - Medium - Low posture-api_CredentialHealthStatusEnum: description: Health status of integration credentials. type: string example: Healthy enum: - Initializing - Healthy - Unhealthy posture-api_result-info: description: Pagination and result information. type: object properties: count: description: Total number of results for the requested service. type: integer example: 1 cursor: description: Cursor for cursor-based pagination. type: - string - 'null' example: eyJpZCI6IjAwMDAwMDAwLTAwMDAtMDAwMC0wMDAwLTAwMDAwMDAwMDAwMCIsImFmZmxpY3Rpb25fZGF0ZSI6IjE5NzAtMDEtMDFUMDA6MDA6MDAuMDAwMDAwWiJ9 next: description: URL to the next page of results. type: - string - 'null' format: uri page: description: Current page within paginated list of results. type: integer example: 1 per_page: description: Number of results per page of results. type: integer example: 20 previous: description: URL to the previous page of results. type: - string - 'null' format: uri total_count: description: Total results available without any search parameters. type: integer example: 2000 posture-api_Asset: description: Asset information including metadata and categorization. type: object properties: category: $ref: '#/components/schemas/posture-api_AssetCategory' external_id: description: External identifier from the source system. type: string example: external-file-id-123 maxLength: 512 fields: description: The fields associated with the asset. type: array items: $ref: '#/components/schemas/posture-api_AssetField' readOnly: true id: description: Unique identifier for the asset. type: string format: uuid example: 8a043daf-def4-403e-9d28-da2e93d9b824 link: description: Direct link to the asset. type: - string - 'null' format: uri example: https://slack-files.com/TYJH37DCK-E0238GG6B8-92fd5y5674 maxLength: 2048 name: description: Human-readable name of the asset. type: string example: Public.svg updated: description: Timestamp of the asset row version represented by this data. type: string format: date-time example: '2026-09-10T20:15:30.123456Z' example: external_id: external-file-id-123 id: 8a043daf-def4-403e-9d28-da2e93d9b824 link: https://slack-files.com/TYJH37DCK-E0238GG6B8-92fd5y5674 name: Public.svg required: - category - external_id - fields - name posture-api_paginated-finding-list: type: object allOf: - $ref: '#/components/schemas/posture-api_api-response-collection' - properties: result: description: Array of finding objects. type: array items: $ref: '#/components/schemas/posture-api_Finding' type: object parameters: posture-api_FindingOrder: description: Which field to use when ordering the findings. in: query name: order schema: type: string enum: - finding.name - instance_count - integration.name - latest_affliction_date - severity posture-api_Page: description: A page number within the paginated result set. in: query name: page schema: type: integer posture-api_Type: description: Filter by type of the finding in: query name: type schema: type: string enum: - Content - Posture posture-api_MaxAfflictionDate: description: Filter to view findings that occurred on or before the affliction date. Can be a date-time in ISO 8601 format or an epoch timestamp. in: query name: max_affliction_date schema: type: string format: date-time posture-api_Vendor: description: Filter by vendor in: query name: vendor schema: $ref: '#/components/schemas/posture-api_VendorsEnum' posture-api_AccountTag: description: Cloudflare account ID for the user making the request. example: 46148281d8a93d002ef242d8b0d5f9f6 in: path name: account_id required: true schema: type: string posture-api_FindingTypeIds: description: A comma separated list of UUIDs identifying the finding type(s). example: 1bd08189-9871-43f9-b838-60338d1d2a15,d7446a0d-da76-4f05-9659-803d78b27b7d in: query name: finding_type_ids schema: type: string format: uuid posture-api_Severity: description: Filter by severity in: query name: severity schema: type: string enum: - Critical - High - Medium - Low posture-api_FindingInstanceOrder: description: 'Which field to use when ordering the Finding''s instances. When ordering by ''remediation.status'', only the most recent non-stale remediation job is considered. Stale jobs (created before the instance''s affliction_date) are treated as having no status for ordering purposes.' in: query name: order schema: type: string enum: - affliction_date - asset.name - remediation.status posture-api_Product: description: Filter by product category of the finding in: query name: product schema: type: string enum: - Cloud - Saas posture-api_RemediationStatuses: description: 'Filter finding instances by most recent remediation job status. Supports multiple comma-separated values. Use ''none'' to filter instances with no remediation jobs or instances where the most recent job is stale. Note: Stale jobs (created before the instance''s affliction_date) are ignored for filtering purposes, but are still included in the ''remediations'' array with stale=true.' example: - pending - completed - none explode: false in: query name: remediation_statuses schema: type: array items: enum: - none - pending - processing - validating - completed - failed type: string style: form posture-api_Ignored: description: Filter for only the ignored findings. Set to false to only see "active" items in: query name: ignored schema: type: boolean posture-api_Search: description: A search term. in: query name: search schema: type: string posture-api_AssetIds: description: Filter finding instances by an array of asset IDs. Supports multiple comma-separated values. example: - c416bc38-75db-425f-ae25-c37b5df5c37f - qw45mm66-75db-425f-ae25-c37b5df5c37f in: query name: asset_ids schema: type: array items: format: uuid type: string posture-api_PerPage: description: Number of results to return per page. in: query name: per_page schema: type: integer posture-api_Observation: description: Filter by observation type of the finding in: query name: observation schema: type: string enum: - Activity - Insight - Issue posture-api_FindingInstanceId: description: A uuid ID identifying this Finding instance. in: path name: instance_id required: true schema: type: string format: uuid posture-api_FindingInstanceIds: description: Filter finding instances by an array of finding instance IDs. Supports multiple comma-separated values. example: - c416bc38-75db-425f-ae25-c37b5df5c37f - b555bc38-75db-425f-ae25-c37b5df5c37f in: query name: finding_instance_ids schema: type: array items: format: uuid type: string posture-api_IntegrationId: description: Filter by an integration ID in: query name: integration_id schema: type: string format: uuid posture-api_Direction: description: Direction to order results. in: query name: direction schema: type: string enum: - asc - desc posture-api_MinAfflictionDate: description: Filter to view findings that occurred on or after the affliction date. Can be a date-time in ISO 8601 format or an epoch timestamp. in: query name: min_affliction_date schema: type: string format: date-time posture-api_Archived: description: Archived in: query name: archived schema: type: boolean posture-api_FindingIdByte: description: 'The `id` of a finding, as returned in each item of the List posture findings response. It is a base64-encoded identifier.' in: path name: finding_id required: true schema: type: string format: byte securitySchemes: api_email: in: header name: X-Auth-Email type: apiKey api_key: in: header name: X-Auth-Key type: apiKey api_token: scheme: bearer type: http user_service_key: in: header name: X-Auth-User-Service-Key type: apiKey externalDocs: description: Cloudflare Radar Documentation url: https://developers.cloudflare.com/radar/ x-forge-commands: abuse-reports: description: Submit and track abuse reports for phishing, malware, and other policy violations on Cloudflare-proxied sites groups: appeals: description: Appeal eligibility for abuse reports emails: description: Emails sent for abuse reports mitigations: description: Mitigation actions taken in response to abuse reports accounts: description: Account settings, members, roles, subscriptions, and API tokens for your Cloudflare account groups: applications: description: Applications operations categories: description: Categories operations organizations: description: Move accounts between organizations profile: description: View and manage the profile for a Cloudflare account roles: description: View the roles available for assigning to account members, each defining a set of permissions subscriptions: description: View and manage plan subscriptions attached to this account tokens: description: Create and manage scoped API tokens for programmatic access to the Cloudflare API ai-gateway: description: Proxy, cache, rate-limit, and observe requests to AI providers — OpenAI, Anthropic, Workers AI, and more groups: custom-domains: description: Manage custom hostnames that route requests through an AI Gateway custom-providers: description: Manage account-level custom AI providers and their endpoint settings datasets: description: 'Deprecated: manage filtered collections of gateway logs used by evaluations' dynamic-routing: description: Route requests across multiple AI providers with fallback, load-balancing, and versioned deployments dynamic-routing.deployments: description: Deploy dynamic route versions and view deployment history dynamic-routing.versions: description: Create and inspect saved versions of a dynamic route evaluation-types: description: 'Deprecated: list the evaluator types that evaluations can use' evaluations: description: 'Deprecated: score the logs in a dataset with selected evaluator types' gateways: description: Create and configure AI Gateways for an account gateways.providers: description: Store and rotate upstream AI provider keys for a gateway logs: description: Inspect, annotate, and delete gateway request logs stored by Legacy Logs ai-search: description: 'Managed search-as-a-service: crawl, index, and query content with AI-powered relevance and chat completions' groups: items: description: Content indexed by AI Search instances jobs: description: Indexing job lifecycle for AI Search instances namespace: description: Logical groupings for organizing AI Search instances tokens: description: Credentials used by AI Search instances ai-security: description: Detect prompt injection, PII, and unsafe topics in traffic to your AI applications groups: custom-topics: description: Organization-specific topic categories used by AI Security for Apps content detection analytics: description: Zone-level traffic analytics — dashboard summaries, per-colo breakdowns, and Argo latency metrics groups: colo: description: Per-data-center (colo) traffic analytics breakdown for the zone dashboard: description: Aggregated zone dashboard analytics — requests, bandwidth, threats, and page views latency: description: Argo Smart Routing latency analytics showing time-to-first-byte improvements argo: description: Network optimization features that speed up and improve reliability of traffic to your origins groups: smart-routing: description: Route traffic through the fastest network paths to your origin using real-time latency data tiered-caching: description: Reduce origin load by having upper-tier data centers serve cache misses before reaching your origin basin-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables billing: description: Account billing profiles and usage data for Cloudflare subscriptions and add-on services groups: profiles: description: Billing profile with payment method, address, and invoice preferences usage: description: Metered usage data for billed services — requests, bandwidth, and feature consumption botnet-feed: description: Botnet threat intelligence feeds — IP and ASN-level data on known command-and-control infrastructure groups: asn: description: ASN-level botnet activity data showing networks with known C2 infrastructure configs: description: Botnet feed subscription configuration and notification preferences builds: description: Build and deploy Workers from connected repositories, then inspect build status and logs. groups: deploy-hooks: description: Manage branch-specific HTTP hooks that start builds. limits: description: View build-minute availability and refresh information. logs: description: Retrieve build logs. repos: description: Manage source repository connections for Workers Builds. tokens: description: Manage credentials used by Workers Builds to deploy Workers. triggers: description: Configure how repository changes build and deploy Workers. versions: description: Find builds associated with Worker versions. workers: description: Manage repository-backed build configuration for Workers. cache: description: Purge cached content and configure Cache Reserve, tiered caching, and variant serving groups: origin-cloud-regions: description: Manage Origin Cloud Regions routing and failover configurations settings: description: Configure Cache Reserve, tiered caching, and variant serving settings.regional-tiered-cache: description: Restrict tiered cache topology to data centers within a specific geographic region settings.reserve: description: Persistent storage tier that keeps cached assets even after eviction from edge caches settings.smart-tiered-cache: description: Automatically determine the best upper-tier data centers for tiered cache topology settings.variants: description: Serve different cached versions of an image based on the Accept header (WebP, AVIF, etc.) client-side-security: description: Client-Side Security — monitor JavaScript, connections, and cookies on your pages for supply-chain attacks groups: connections: description: Third-party connections made by scripts on your pages — track data exfiltration risks cookies: description: Cookies set by your pages with classification and same-site attribute tracking policies: description: Content Security Policies that control which scripts and connections are allowed on your pages scripts: description: JavaScript files detected on your pages with change tracking and malicious code detection settings: description: Fine tune Client-Side Security behaviors cloud-connector: description: Route traffic from Cloudflare directly to cloud provider services (AWS, Azure, GCP) without origin servers groups: rules: description: Routing rules that map request patterns to cloud provider endpoints cloudforce-one: description: Detection rule management APIs groups: binary-storage: description: Upload and retrieve malware samples and suspicious binaries for analysis requests: description: Additional request operations — priority listing and asset creation rules: description: Rule management operations groups: approvals: description: Approval workflow operations email: description: Email rule operations exemptions: description: Exemption rule operations managed: description: Managed rule operations stats: description: Rule statistics operations tree: description: Rule navigation tree operations scans: description: Scan URLs, IPs, and domains for threat intelligence indicators containers: description: Deploy and manage Containers applications on Cloudflare's global network groups: applications: description: Manage Containers applications applications.instances: description: Inspect Containers instances belonging to applications applications.rollouts: description: Manage rollouts for scheduler-backed applications applications.versions: description: Inspect versions of scheduler-backed applications registries: description: Manage Containers image registries registries.credentials: description: Generate image registry credentials content-scan: description: Malicious uploads detection, scan uploaded content in HTTP requests for malware and malicious payloads groups: expressions: description: Custom expressions that tell the scanner how to reach content objects it cannot parse on its own custom-pages: description: Manage custom error and challenge pages and their assets for accounts and zones groups: account-custom-pages: description: Manage account-level custom pages account-custom-pages.preview-tokens: description: Preview tokens for account-level custom pages assets: description: Manage account- and zone-level custom assets zone-custom-pages: description: Manage zone-level custom pages zone-custom-pages.preview-tokens: description: Preview tokens for zone-level custom pages d1: description: D1 is Cloudflare's managed, serverless database with SQLite's SQL semantics, built-in disaster recovery, and Worker and HTTP API access. groups: time-travel: description: use specific point-in-time backups of your D1 database x-forge-epilogue: For more information about Time Travel, see https://developers.cloudflare.com/d1/reference/time-travel diagnostics: description: Network diagnostic tools — traceroutes from Cloudflare's edge and endpoint health checks groups: endpoint-healthchecks: description: Monitor external endpoint availability with periodic HTTP/HTTPS health checks traceroutes: description: Run traceroutes from Cloudflare data centers to diagnose network path issues email-routing: description: Route incoming email to verified destination addresses or Workers with routing rules, catch-all behavior, and managed DNS records groups: addresses: description: Verified destination email addresses that can receive forwarded mail dns: description: Inspect or unlock the DNS records required by Email Routing rules: description: Match incoming email addresses and forward messages to destination mailboxes or Workers settings: description: Inspect and update Email Routing settings email-security: description: Cloud email security — investigate threats, manage allow/block policies, and detect phishing groups: analytics: description: Analytics and reporting — monthly report and per-day breakdowns of threat activity bulk-actions: description: Asynchronous jobs that move or release every message matching a search — create, monitor, and manage bulk jobs investigate: description: Search and investigate email messages — view detections, traces, raw content, and take remediation actions phishguard: description: PhishGuard user-reported phishing reports — view detected threats for a date range settings: description: Email security configuration — block senders, allow policies, content policies, domains, trusted domains, impersonation registry, and URL handling submissions: description: Reclassify submissions — track user and team reports of false positives and missed detections email-sending: description: Send transactional email and manage sending subdomains and their DNS configuration groups: limits: description: Inspect account-level sending quotas and current usage subdomains: description: Configure sending subdomains and keep their DNS records healthy suppressions: description: Prevent delivery to suppressed addresses and manage the account suppression list filters: description: Filter expressions used by legacy firewall rules to match requests — prefer Rulesets for new configurations firewall: description: Legacy firewall rules, zone lockdowns, access rules, user-agent blocking, and WAF packages groups: access-rules: description: IP-based access rules that allow, block, challenge, or whitelist traffic globally or per-zone lockdowns: description: Zone lockdown rules that restrict access to URLs by IP address or range rules: description: Legacy firewall rules with filter expressions — prefer Rulesets for new configurations ua-rules: description: Block or challenge requests based on the User-Agent header string waf: description: Legacy WAF managed rule packages, rule groups, individual rules, and override configurations zone-access-rules: description: Zone-scoped IP access rules for blocking or allowing traffic google-tag-gateway: description: Google Tag Gateway operations groups: config: description: Google Tag Gateway config operations healthchecks: description: Standalone health checks that monitor origin server availability from Cloudflare's edge groups: previews: description: Test a health check configuration before deploying it to production hyperdrive: description: Accelerate access to existing databases by caching queries and pooling connections at the edge iam: description: Identity and access management — permission groups, resource groups, user groups, and SSO connectors groups: permission-groups: description: View the permission groups that can be assigned to API tokens and policies resource-groups: description: Define scopes that limit which account resources a policy or token can access sso: description: Configure single sign-on connectors to authenticate account members through an external identity provider user-groups: description: Organize account members into groups for easier permission assignment images: description: Store, resize, and deliver optimized images globally — variants, signing keys, and direct uploads groups: flows: description: Zone-level transformation flows that control how images are resized and optimized on delivery import: description: Import images from S3 keys: description: Manage signing keys for generating private image URLs variants: description: Manage named resize variants for transforming images on delivery intel: description: Threat intelligence lookups — IP reputation, domain info, ASN details, WHOIS, and indicator feeds groups: asn: description: ASN intelligence — ownership, geolocation, and subnet details for autonomous systems attack-surface-report: description: Attack surface intelligence — exposed assets, vulnerabilities, and infrastructure mapping dns: description: Passive DNS data showing historical DNS resolution records for domains domain-history: description: Historical domain registration and categorization changes over time domains: description: Domain intelligence — risk scores, categories, and associated infrastructure indicator-feeds: description: Threat indicator feeds — subscribe to and manage curated lists of malicious IPs, domains, and URLs ip-lists: description: Curated IP lists used for threat detection and policy enforcement ips: description: IP address intelligence — geolocation, risk assessment, and hosting provider details miscategorizations: description: Report and track domain miscategorization corrections whois: description: WHOIS registration data for domains including registrant, registrar, and nameservers k2: description: Durable, ordered event streams that you produce records to and consume from with subscriptions groups: streams: description: K2 streams, their retention, and the HTTP and Workers binding inputs used to produce records streams.subscriptions: description: Subscriptions that consume a K2 stream, with committed-position lag leaked-credential-checks: description: Detect compromised credentials in login requests by checking against known breach databases groups: detections: description: Custom detection locations that tell the WAF where to find usernames and passwords in requests load-balancers: description: Distribute traffic across origin pools with health monitoring, geo-steering, and failover groups: monitor-groups: description: Group monitors together for shared configuration and bulk management monitor-groups.references: description: List references to monitor groups used by load balancer pools monitors: description: Health check configurations that probe origin servers and determine pool availability monitors.previews: description: Health check configurations that probe origin servers and determine pool availability monitors.references: description: Health check configurations that probe origin servers and determine pool availability pools: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.health: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.references: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences previews: description: Preview the result of a health check monitor configuration before applying it regions: description: Geographic regions used for regional pool steering and traffic policies searches: description: Search across all load balancer resources (pools, monitors, load balancers) by name or reference logs: description: Log control, retention, and raw log access — CMB config, ray ID lookups, and received fields groups: control: description: Log control operations received: description: Received log operations magic-network-monitoring: description: Flow-based network traffic monitoring with configurable alerting rules and VPC flow ingestion groups: configs: description: Account-level monitoring configuration — sampling rates, thresholds, and notification settings rules: description: Monitoring rules that define traffic thresholds and trigger alerts or prefix advertisements vpc-flows: description: Ingest VPC flow logs from cloud providers for network visibility and anomaly detection magic-transit: description: DDoS-protected network transit — GRE/IPsec tunnels, static routes, Magic WAN sites, connectors, and packet captures groups: advanced-dns-protection: description: Advanced Dns Protection operations advanced-tcp-protection: description: Advanced Tcp Protection operations apps: description: Application-aware traffic policies for Magic WAN that steer traffic by app type bgp-filter-profiles: description: BGP filter profiles for controlling which routes are allowed or denied on Magic Transit tunnels bgp-settings: description: BGP settings for controlling default ASN and route redistribution on Magic Transit tunnels cf-interconnects: description: Cloudflare Network Interconnect (CNI) links for direct physical or virtual peering gre-tunnels: description: GRE tunnel endpoints that connect your network to Cloudflare for Magic Transit ipsec-tunnels: description: IPsec tunnel endpoints with pre-shared key management for encrypted transit pcaps: description: Packet capture requests for debugging traffic flowing through Magic Transit tunnels routes: description: Static routes that direct IP prefix traffic through specific GRE/IPsec tunnels sites: description: Magic WAN branch sites — base CRUD, LAN/WAN interface configuration, ACLs, connectors, app configuration, and NetFlow config mcp: description: Manage MCP portals and upstream MCP servers for Cloudflare Access AI controls groups: portals: description: Manage MCP portals, attached servers, and Code Mode settings servers: description: Manage upstream MCP servers, credentials, capabilities, and sync state network-interconnects: description: Physical and virtual private interconnects between your infrastructure and Cloudflare's network groups: cnis: description: Cloud Network Interconnect (CNI) connections — private links from cloud providers to Cloudflare interconnects: description: Physical cross-connect and partner interconnect sessions with LOA and status tracking settings: description: Account-level interconnect settings and default configurations slots: description: Available interconnect facility slots showing port capacity at Cloudflare data centers organizations: description: Multi-user organizations that group accounts, members, and shared settings under a single entity groups: account-organizations: description: List organizations associated with a specific account accounts: description: Accounts operations members: description: Members operations members-batch-create: description: Members Batch Create operations organization-profile: description: View and update the public profile information for an organization shares: description: Shares operations origin-post-quantum-encryption: description: Enable post-quantum key exchange for connections between Cloudflare and your origin server pages: description: Full-stack application hosting with Git-integrated builds, preview deployments, and custom domains groups: projects: description: Pages projects, deployments, build logs, and custom domain bindings pipelines: description: Ingest, transform, and route event streams into R2, analytics, or other destinations in real time groups: sinks: description: Destinations where pipeline data is written — R2 buckets, HTTP endpoints, or other storage streams: description: Inbound data streams that feed events into a pipeline for processing precursor: description: Precursor settings for a zone queues: description: Reliable message queuing between Workers — produce, consume, and batch-process messages at scale groups: consumers: description: Workers that automatically receive and process messages from a queue messages: description: Push messages to a queue and pull or acknowledge them from consumers purge: description: Remove all pending messages from a queue subscriptions: description: Manage queue subscriptions for event-driven message routing r2: description: S3-compatible object storage with zero egress fees — buckets, lifecycle rules, event notifications, and data migration groups: buckets: description: Create and configure R2 buckets including CORS, lifecycle, custom domains, event notifications, and object locks buckets.jobs: description: Create and inspect background jobs for an R2 bucket buckets.local-uploads: description: R2 bucket local upload configuration super-slurper: description: Migrate data from external S3-compatible storage into R2 buckets with resumable transfer jobs temporary-credentials: description: Generate short-lived S3-compatible credentials scoped to specific buckets and operations r2-data-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables radar: description: Internet-wide traffic intelligence — BGP, DNS, HTTP trends, attack data, and network quality insights groups: agent-readiness: description: Agent readiness summary statistics across the Cloudflare network ai: description: AI inference trends and model usage statistics across the Cloudflare network annotations: description: Radar annotations marking significant Internet events (outages, cable cuts, etc.) as112: description: AS112 DNS sinkhole statistics — reverse DNS query volumes for private address space attacks: description: DDoS and application-layer attack trends, vectors, and target analysis bgp: description: BGP routing data — prefix announcements, AS-level stats, route leaks, and hijack events bots: description: Internet-wide bot traffic trends, categories, and distribution statistics ct: description: Certificate Transparency log monitoring and newly-issued certificate discovery datasets: description: Downloadable Radar datasets for offline analysis and research dns: description: Global DNS query trends — top domains, resolver stats, and DNSSEC adoption email: description: Email security trends — DMARC/SPF/DKIM adoption, spam, and phishing statistics entities: description: Look up ASNs, IPs, domains, and locations with metadata and traffic summaries geolocations: description: Geographic location metadata used for regional traffic analysis http: description: HTTP protocol trends — TLS versions, HTTP versions, browser share, and OS distribution leaked-credentials: description: Leaked credential detection trends and exposure statistics netflows: description: Network-layer traffic flow data and volumetric trend analysis origins: description: Cloud and hosting origin providers (e.g. Amazon, by region) and their traffic metrics post-quantum: description: Post-quantum encryption adoption and deployment trends across the Internet quality: description: Internet connection quality metrics — speed, latency, and jitter by geography and ASN ranking: description: Top domain rankings based on DNS query popularity across the Cloudflare network robots-txt: description: Robots.txt adoption and crawler directive trends across the web search: description: Search Radar data across IPs, ASNs, domains, and locations tcp-resets-timeouts: description: TCP connection reset and timeout statistics indicating network health issues tlds: description: Top-level domain (TLD) metadata and performance trends traffic-anomalies: description: Detected traffic anomalies and unusual patterns in Internet traffic flows verified-bots: description: Catalog of known good bots (Googlebot, Bingbot, etc.) and their traffic patterns rate-limits: description: Legacy per-zone rate limiting rules — prefer Advanced Rate Limiting in Rulesets for new configurations realtime: description: Real-time audio, video, and data services on Cloudflare's global network groups: kit: description: SDK-backed meetings, participants, recordings, livestreams, and webhooks kit.analytics: description: Usage and livestream analytics for RealtimeKit applications kit.analytics.livestreams: description: Livestream analytics for RealtimeKit applications kit.analytics.livestreams.daily: description: Daily livestream analytics for RealtimeKit applications kit.analytics.usage: description: Usage analytics for RealtimeKit applications kit.apps: description: RealtimeKit applications that group meetings, sessions, and configuration kit.livestreams: description: Independent and meeting-based livestreams and their sessions kit.livestreams.sessions: description: Sessions for RealtimeKit livestreams kit.meetings: description: Meetings, participants, access tokens, and meeting livestreams kit.meetings.active: description: Live meeting state and participant controls kit.meetings.active.polls: description: Polls for active meeting sessions kit.meetings.livestream: description: Livestream operations associated with RealtimeKit meetings kit.meetings.participants: description: Participants in RealtimeKit meetings kit.meetings.participants.tokens: description: Access tokens for RealtimeKit meeting participants kit.presets: description: Reusable meeting configuration for media, permissions, and interface behavior kit.recordings: description: Meeting and participant-track recordings and recording controls kit.recordings.active: description: Active recordings for RealtimeKit meetings kit.recordings.tracks: description: Participant-track recordings for RealtimeKit meetings kit.sessions: description: Historical session data, participants, chat, transcripts, and summaries kit.sessions.chat: description: Chat messages from historical RealtimeKit sessions kit.sessions.livestreams: description: Livestreams associated with historical RealtimeKit sessions kit.sessions.participants: description: Participants in historical RealtimeKit sessions kit.sessions.peers: description: Peer details from historical RealtimeKit sessions kit.sessions.summaries: description: Summaries of historical RealtimeKit sessions kit.sessions.transcripts: description: Transcripts from historical RealtimeKit sessions kit.webhooks: description: Webhook endpoints and supported events for RealtimeKit notifications kit.webhooks.events: description: Supported events for RealtimeKit webhooks moq: description: MoQ relays for publishing and subscribing to media streams moq.relays: description: Relays are isolated MoQ scopes that carry media between publishers and subscribers moq.relays.tokens: description: Tokens that authorize publishers and subscribers to connect to a relay sfu: description: SFU apps that route WebRTC media and data between participants sfu.apps: description: SFU application namespaces for sessions and tracks turn: description: TURN keys that help clients traverse NATs and firewalls turn.keys: description: Keys used to generate short-lived TURN credentials request-tracers: description: Trace how a request would be processed through Cloudflare's rules and configuration pipeline groups: traces: description: Simulate request processing to debug rule matches, transforms, and routing decisions resource-sharing: description: Share Cloudflare resources (zones, accounts) across organizations with granular access controls groups: recipients: description: Update share recipients resources: description: Individual resources (zones, configs) that have been shared with recipients rules: description: Resources used by Cloudflare rules and rulesets groups: lists: description: Custom account-level lists of IPs, hostnames, ASNs, or redirects used in rule expressions rum: description: Real User Measurement (Web Analytics) — track page loads, Core Web Vitals, and visitor metrics groups: rules: description: Rules that control which pages and paths are tracked by Web Analytics site-info: description: Web Analytics sites — register domains and get the JavaScript beacon snippet scim: description: SCIM 2.0 provisioning — manage users, groups, and identity provider sync for your account groups: groups: description: Groups operations resource-types: description: Resource Types operations schemas: description: Schemas operations service-provider-config: description: Service Provider Config operations users: description: Users operations secrets-store: description: Centralized secret management — store API keys, tokens, and credentials for use across Workers and other products groups: quota: description: Account quota limits for secrets stores, secrets count, and storage capacity secrets: description: Encrypted key-value secrets within a store. Pass --store-id to scope. stores: description: Secret stores that hold encrypted key-value secrets accessible by Workers and services security-center: description: Security posture dashboard — view and manage security insights, misconfigurations, and vulnerabilities groups: insights: description: Security findings and recommendations across your account — DNS, SSL, WAF misconfigurations, etc. zone-insights: description: Zone-scoped security insights — counts by class, severity, type, and dismissal security-txt: description: Manage the /.well-known/security.txt file that tells security researchers how to report vulnerabilities smart-shield: description: Smart Shield settings, health checks, and cache reserve management groups: cache-reserve-clear: description: Cache Reserve Clear operations health-checks: description: Health checks operations spectrum: description: Proxy and protect arbitrary TCP/UDP applications through Cloudflare's network with DDoS mitigation groups: analytics: description: Real-time and historical connection analytics for Spectrum applications apps: description: Spectrum application configurations that map protocols and ports to origin servers speed: description: Observatory speed tests — run Lighthouse audits, track performance trends, and schedule recurring tests groups: availabilities: description: Check which speed test regions and configurations are available for your zone pages: description: Tested pages with their performance history, trends, and individual test results schedule: description: Scheduled recurring speed tests that automatically run at regular intervals ssl: description: SSL/TLS certificate management — certificate packs, Universal SSL, verification, and TLS mode recommendations groups: automatic-upgrader: description: SSL automatic mode enrollment — get or update automatic SSL/TLS upgrader settings recommendations: description: Get the recommended SSL/TLS encryption mode based on your origin server's certificate configuration stream: description: Video encoding, storage, and delivery — upload, live-stream, clip, caption, and embed video at scale groups: audio-tracks: description: Add, edit, or remove additional audio tracks on a video captions: description: Upload, generate, or retrieve captions and subtitles for videos in multiple languages clip: description: Create a new video clip from an existing video by specifying start and end times copy: description: Import a video from a URL into Stream for processing and delivery direct-upload: description: Generate a tokenized URL that lets end-users upload video directly to Stream downloads: description: Create downloadable MP4 renditions of a video for offline viewing embed: description: Retrieve the HTML embed code snippet for a video keys: description: Signing keys used to generate short-lived signed URLs for private video playback live-inputs: description: Enable and disable live input streams token: description: Generate short-lived signed URL tokens for secure private video playback typed-downloads: description: Type-specific stream download creation and deletion videos: description: Aggregate video storage usage statistics for the account watermarks: description: Watermark profiles that overlay an image on every video in the account webhooks: description: Webhook notifications for video lifecycle events (ready, error, etc.) tenants: description: Multi-tenant account management — manage tenant accounts, entitlements, and memberships groups: account-types: description: Account Types operations accounts: description: Accounts operations entitlements: description: Entitlements operations memberships: description: Memberships operations turnstile: description: CAPTCHA-free bot verification widgets that protect forms and APIs without degrading user experience groups: widgets: description: Turnstile widget configurations — site keys, secret rotation, and challenge mode settings url-scanner: description: Scan URLs for phishing, malware, and other threats — submit scans and retrieve detailed results groups: response: description: Response operations responses: description: Raw HTTP response data captured during URL scans scan: description: Scan operations scans: description: URL scan requests and results — submit URLs for analysis and retrieve threat verdicts user: description: Your Cloudflare user profile, invitations, organizations, billing, and personal API tokens groups: billing: description: View billing history and payment profile for your user (deprecated — prefer account-level billing) firewall: description: Firewall operations load-balancers.monitors: description: Load Balancers operations load-balancers.monitors.preview: description: Load Balancers operations load-balancers.monitors.references: description: Load Balancers operations load-balancers.pools: description: Load Balancers operations load-balancers.pools.edit.pools: description: Load Balancers operations load-balancers.pools.health: description: Load Balancers operations load-balancers.pools.preview: description: Load Balancers operations load-balancers.pools.references: description: Load Balancers operations load-balancers.preview: description: Load Balancers operations load-balancing-analytics.events: description: Load Balancing Analytics operations subscriptions: description: View and manage zone-level plan subscriptions owned by your user tenants: description: Tenants operations tokens: description: Create and manage personal API tokens scoped to your user for programmatic API access user.analytics: description: User-level traffic analytics — aggregated totals and timeseries across all zones vectorize: description: Globally distributed vector database for building semantic search, recommendations, and RAG applications on Workers groups: deprecated-indexes: description: Deprecated v1 Vectorize index operations metadata-index: description: Metadata indexes for filtered vector search waiting-rooms: description: Virtual queues that throttle traffic to your site during peak demand with customizable waiting pages groups: account-waiting-rooms: description: Account-scoped waiting room listing events: description: Scheduled events that temporarily override waiting room settings for sales, launches, etc. page: description: Custom HTML waiting page templates and preview rendering rules: description: Rules that bypass or modify waiting room behavior for specific request patterns settings: description: Zone-level waiting room defaults and cookie configuration statuses: description: Real-time queue status showing active users, queued users, and estimated wait times workflows: description: Durable, multi-step workflows that run on Workers with automatic retries and state persistence groups: instances: description: Workflow instance operations versions: description: Workflow version operations zaraz: description: Server-side tag manager — load third-party tools (analytics, pixels, etc.) from Cloudflare's edge without client-side JS groups: config: description: Full Zaraz configuration including tools, triggers, and variables for the zone default: description: Default Zaraz configuration template used as a starting point for new zones export: description: Export the current Zaraz configuration as a portable JSON document history: description: Configuration version history — browse and restore previous Zaraz configurations publish: description: Publish pending Zaraz configuration changes to make them live on the zone workflow: description: Workflow state for Zaraz configuration changes (draft vs. published) zero-trust: description: Cloudflare's SASE platform — secure access, device posture, DLP, tunnels, gateway policies, and network segmentation groups: dex: description: Digital Experience Monitoring — synthetic tests, fleet-wide device metrics, and network path diagnostics dlp.custom-prompt-topics: description: Data Loss Prevention - manage custom prompt topics for AI-based content detection dlp.data-classes: description: Data Loss Prevention - manage data classes used to classify sensitive information dlp.data-tag-categories: description: Data Loss Prevention - manage categories that organize data tags dlp.data-tag-category-templates: description: Data Loss Prevention - browse templates for creating data tag categories dlp.data-tags: description: Data Loss Prevention - manage tags used to classify and organize sensitive data dlp.datasets: description: Data Loss Prevention - manage datasets, versions, and uploads dlp.document-fingerprints: description: Data Loss Prevention - manage document fingerprints for detecting matching documents dlp.email.account-mapping: description: Data Loss Prevention - configure account mappings for outbound email scanning dlp.email.rules: description: Data Loss Prevention - manage outbound email scanning rules and their priorities dlp.entries: description: Data Loss Prevention - list and manage detection entries dlp.limits: description: Data Loss Prevention - view account limits and resource quotas dlp.patterns: description: Data Loss Prevention - validate regular expressions used for content detection dlp.profiles: description: Data Loss Prevention - list and retrieve profiles dlp.profiles.custom: description: Data Loss Prevention - manage custom profiles dlp.profiles.predefined: description: Data Loss Prevention - manage predefined profiles dlp.sensitivity-group-templates: description: Data Loss Prevention - browse templates for creating sensitivity groups dlp.sensitivity-groups: description: Data Loss Prevention - manage sensitivity groups and their level ordering dlp.sensitivity-levels: description: Data Loss Prevention - manage sensitivity levels within sensitivity groups dlp.settings: description: Data Loss Prevention - manage account-level settings dlp.validators: description: Data Loss Prevention - list and retrieve content validators dlp.validators.proximity-words: description: Data Loss Prevention - manage proximity-word validators risk-scoring: description: User Risk Scoring - retrieve and reset user risk scores risk-scoring.behaviours: description: User Risk Scoring - manage behaviors used to calculate user risk scores risk-scoring.integrations: description: User Risk Scoring - manage integrations that provide risk score signals risk-scoring.integrations.references: description: User Risk Scoring - retrieve integrations by external reference risk-scoring.summary: description: User Risk Scoring - retrieve account risk score summaries zones: description: Zones are domains on Cloudflare — list, create, and configure domain settings groups: aegis: description: Aegis operations fonts: description: Fonts operations origin-h2-max-streams: description: Origin H2 Max Streams operations origin-max-http-version: description: Origin Max Http Version operations origin-tls-compliance-modes: description: Manage zone Origin TLS Compliance Modes setting rum: description: Rum operations speed-brain: description: Speed Brain operations