openapi: 3.2.0 info: description: Welcome to Cloudflare's API documentation site. license: name: BSD-3-Clause url: https://opensource.org/licenses/BSD-3-Clause title: Cloudflare Policies API version: 4.0.0 servers: - description: Client API url: https://api.cloudflare.com/client/v4 security: - api_email: [] api_key: [] - api_token: [] - user_service_key: [] tags: - name: Policies paths: /accounts/{account_id}/data-security/posture/policies: get: operationId: ListPolicies summary: List policy configurations description: Returns a list of integration-scoped policy configurations for the given account. This endpoint supports cursor based pagination. By default, results are returned in sorted order based on created_at. parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - name: cursor in: query description: Cursor for pagination. Obtained from the `result_info.cursor` field of a previous response. schema: type: string responses: '200': description: 'OK: Policies retrieved successfully' content: application/json: schema: type: object allOf: - $ref: '#/components/schemas/posture-api_api-response-collection' - properties: result: type: array items: $ref: '#/components/schemas/posture-api_PolicyResponse' type: object '400': description: 'Bad Request: Invalid request parameters' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '401': description: 'Unauthorized: Authentication required' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '403': description: 'Forbidden: Insufficient permissions' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' security: - api_token: [] tags: - Policies x-api-token-group: - Zero Trust Read - Zero Trust Write x-fern-sdk-group-name: zero-trust.casb.policies x-fern-sdk-method-name: list post: operationId: CreatePolicy summary: Create a new policy configuration description: 'Creates a new policy configuration that defines automated actions to be executed when security findings are detected. A policy can include multiple remediation and/or webhook actions that will be triggered automatically.' parameters: - $ref: '#/components/parameters/posture-api_AccountTag' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/posture-api_CreatePolicyRequest' responses: '200': description: 'OK: Policy created successfully' content: application/json: schema: type: object allOf: - $ref: '#/components/schemas/posture-api_api-response-common' - properties: result: $ref: '#/components/schemas/posture-api_PolicyResponse' type: object '400': description: 'Bad Request: Invalid request parameters' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '401': description: 'Unauthorized: Authentication required' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '403': description: 'Forbidden: Insufficient permissions' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '404': description: 'Not Found: Integration, remediation type, or webhook config not found' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' security: - api_token: [] tags: - Policies x-api-token-group: - Zero Trust Write x-fern-sdk-group-name: zero-trust.casb.policies x-fern-sdk-method-name: create /accounts/{account_id}/data-security/posture/policies/logs: get: operationId: ListPolicyLogs summary: List policy invocation logs (deprecated) description: 'Deprecated: use `GET /accounts/{account_id}/data-security/posture/policy_logs`, which returns identical results. This path will be removed. Returns a list of policy invocation logs for the given account, sourced from ClickHouse via Ready Analytics. Each entry represents one execution of a policy against a finding instance, including the actions (remediation jobs and webhooks) it dispatched. Results are scoped to the requesting account''s CASB integrations. The `integration_id` query parameter, when supplied, is intersected against the account''s integration allowlist; values outside the allowlist are silently dropped. Pagination is offset-based. The response does not include a total row count; clients should treat a result with fewer than `per_page` entries as the end of the list.' parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - name: since in: query description: Lower bound on the log entry timestamp. Accepts ISO 8601 / RFC3339 or epoch seconds. Defaults to 7 days before `until`. The window between `since` and `until` cannot exceed 180 days. schema: type: string format: date-time example: '2026-04-01T00:00:00Z' - name: until in: query description: Upper bound on the log entry timestamp. Accepts ISO 8601 / RFC3339 or epoch seconds. Defaults to the current time. Must be greater than or equal to `since`. schema: type: string format: date-time example: '2026-04-08T00:00:00Z' - name: integration_id in: query description: Comma-separated list of CASB integration IDs to filter by. At most 100 values, each at most 128 characters. Values outside the account's tenancy allowlist are silently ignored. When omitted, results are scoped to the full allowlist. schema: type: string example: 497f6eca-6276-4993-bfeb-53cbbbba6f08 - name: policy_name in: query description: Comma-separated list of policy display names to filter by. At most 100 values, each at most 255 characters. schema: type: string example: Auto-remediate publicly shared files - $ref: '#/components/parameters/posture-api_Page' - $ref: '#/components/parameters/posture-api_PerPage' responses: '200': description: 'OK: Policy logs retrieved successfully' content: application/json: schema: type: object allOf: - $ref: '#/components/schemas/posture-api_api-response-collection' - properties: result: type: array items: $ref: '#/components/schemas/posture-api_PolicyLogResponse' type: object '400': description: 'Bad Request: Invalid query parameters' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '401': description: 'Unauthorized: Authentication required' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '403': description: 'Forbidden: Insufficient permissions' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '502': description: 'Bad Gateway: Policy logs backend (ClickHouse) is unavailable' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '504': description: 'Gateway Timeout: Policy logs query timed out' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' deprecated: true security: - api_token: [] tags: - Policies x-api-token-group: - Zero Trust Read - Zero Trust Write x-fern-ignore: true x-fern-sdk-group-name: zero-trust.casb.policies.logs x-fern-sdk-method-name: list /accounts/{account_id}/data-security/posture/policies/{policy_id}: delete: operationId: DeletePolicy summary: Delete a policy configuration description: Deletes a policy configuration. parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - $ref: '#/components/parameters/posture-api_PolicyId' responses: '200': description: 'OK: Policy deleted successfully' content: application/json: schema: type: object allOf: - $ref: '#/components/schemas/posture-api_api-response-common' - properties: result: $ref: '#/components/schemas/posture-api_DeletePolicyResponse' type: object '400': description: 'Bad Request: Invalid request parameters' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '401': description: 'Unauthorized: Authentication required' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '403': description: 'Forbidden: Insufficient permissions' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '404': description: 'Not Found: Policy not found' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' security: - api_token: [] tags: - Policies x-api-token-group: - Zero Trust Write x-fern-sdk-group-name: zero-trust.casb.policies x-fern-sdk-method-name: delete get: operationId: GetPolicyByID summary: Get a policy configuration by ID description: 'Retrieves the details of a specific policy configuration, including its associated remediation and webhook actions.' parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - name: policy_id in: path description: The UUID of the policy configuration to retrieve. required: true schema: type: string format: uuid example: 497f6eca-6276-4993-bfeb-53cbbbba6f08 responses: '200': description: 'OK: Policy retrieved successfully' content: application/json: schema: type: object allOf: - $ref: '#/components/schemas/posture-api_api-response-common' - properties: result: $ref: '#/components/schemas/posture-api_PolicyResponse' type: object '400': description: 'Bad Request: Invalid request parameters' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '401': description: 'Unauthorized: Authentication required' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '403': description: 'Forbidden: Insufficient permissions' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '404': description: 'Not Found: Policy config not found' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' security: - api_token: [] tags: - Policies x-api-token-group: - Zero Trust Read - Zero Trust Write x-fern-sdk-group-name: zero-trust.casb.policies x-fern-sdk-method-name: get put: operationId: UpdatePolicy summary: Update a policy configuration description: Updates an existing policy configuration and replaces its actions. parameters: - $ref: '#/components/parameters/posture-api_AccountTag' - name: policy_id in: path description: Policy configuration ID required: true schema: type: string format: uuid requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/posture-api_UpdatePolicyRequest' responses: '200': description: 'OK: Policy updated successfully' content: application/json: schema: type: object allOf: - $ref: '#/components/schemas/posture-api_api-response-common' - properties: result: $ref: '#/components/schemas/posture-api_PolicyResponse' type: object '400': description: 'Bad Request: Invalid request parameters' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '401': description: 'Unauthorized: Authentication required' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '403': description: 'Forbidden: Insufficient permissions' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' '404': description: 'Not Found: Policy, integration, remediation type, or webhook config not found' content: application/json: schema: $ref: '#/components/schemas/posture-api_error-response' security: - api_token: [] tags: - Policies x-api-token-group: - Zero Trust Write x-fern-sdk-group-name: zero-trust.casb.policies x-fern-sdk-method-name: update components: schemas: posture-api_PolicyLogActionsResponse: description: Actions dispatched by the policy consumer for this invocation. Both arrays are always present and may be empty. type: object properties: remediations: description: Remediation jobs spawned by this policy invocation. type: array items: $ref: '#/components/schemas/posture-api_PolicyLogRemediationResponse' webhooks: description: Webhook jobs dispatched by this policy invocation. type: array items: $ref: '#/components/schemas/posture-api_PolicyLogWebhookResponse' required: - remediations - webhooks posture-api_PolicyWebhookActionInput: description: A webhook action to be executed. type: object properties: webhook_config_id: description: The ID of the webhook configuration to use. type: string format: uuid example: 3f7b8c9d-6e5a-4f3b-9c2d-1e0a8b7c6d5e required: - webhook_config_id posture-api_error-response: description: Standard error response structure. type: object properties: errors: $ref: '#/components/schemas/posture-api_messages' messages: $ref: '#/components/schemas/posture-api_messages' success: description: Indicates the request failed. type: boolean example: false enum: - false required: - success - errors - messages posture-api_CreatePolicyRequest: description: Request body for creating a new policy configuration. type: object properties: actions: $ref: '#/components/schemas/posture-api_PolicyActionsInput' applies_to_all_integrations: description: When true, the policy applies to all integrations for the account. When false, integration_ids must be provided. type: boolean example: false description: description: Optional description of what this policy does. type: string example: Automatically remove public access from files when detected maxLength: 1000 x-stainless-terraform-configurability: computed_optional display_name: description: Display name for the policy configuration. type: string example: Auto-remediate public files maxLength: 255 enabled: description: Boolean specifying if the policy is enabled or disabled. type: boolean example: true finding_type_id: description: The finding type this policy is associated with. All remediation actions must match this finding type. type: string format: uuid example: 5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a integration_ids: description: The integrations this policy applies to. Required when applies_to_all_integrations is false. type: array items: format: uuid type: string example: - 497f6eca-6276-4993-bfeb-53cbbbba6f08 x-stainless-terraform-configurability: computed_optional required: - display_name - enabled - applies_to_all_integrations - finding_type_id - actions posture-api_PolicyLogTriggerResponse: description: The finding instance that caused the policy to fire. type: object properties: date_detected: description: When the finding was first detected, in ISO 8601 / RFC3339 format. type: string example: '2026-04-07T13:00:00Z' fields_of_interest: description: Free-form JSON object containing finding-type-specific context fields (e.g. file owner, sharing scope). Schema varies per finding type; consumers should treat unknown keys defensively. Null when the upstream row had no fields_of_interest. type: - object - 'null' example: owner: alice@company.com sharing: public additionalProperties: true finding_type_name: description: Display name of the finding type that triggered the policy. type: string example: 'GW: File publicly accessible' instance_asset: description: Name of the specific resource (file, drive item, etc.) the finding was raised against. type: string example: Q4_Financials.pdf integration_name: description: Display name of the CASB integration that produced the finding. type: string example: Finance GW integration_url: description: Path to the integration in the dashboard. type: string example: /one/casb/integrations/int_001 required: - finding_type_name - instance_asset - date_detected - integration_name - integration_url - fields_of_interest posture-api_api-response-collection: description: Response structure for paginated collections. type: object properties: errors: $ref: '#/components/schemas/posture-api_messages' messages: $ref: '#/components/schemas/posture-api_messages' result_info: $ref: '#/components/schemas/posture-api_result-info' success: description: Whether the API call was successful. type: boolean example: true required: - success - errors - messages - result_info posture-api_PolicyWebhookConfigResponse: description: A webhook configuration associated with the policy. type: object properties: display_name: description: Display name/label of the webhook configuration. type: string example: Send to Slack readOnly: true webhook_config_id: description: Unique identifier for the webhook configuration. type: string format: uuid example: 3f7b8c9d-6e5a-4f3b-9c2d-1e0a8b7c6d5e required: - webhook_config_id - display_name posture-api_PolicyLogResponse: description: A single policy invocation log entry. Each entry represents one execution of a policy against a finding instance. type: object properties: actions: $ref: '#/components/schemas/posture-api_PolicyLogActionsResponse' policy: $ref: '#/components/schemas/posture-api_PolicyLogPolicyResponse' timestamp: description: When the policy invocation was recorded by ClickHouse, in ClickHouse DateTime format (UTC). type: string example: '2026-04-07T13:00:00Z' trigger: $ref: '#/components/schemas/posture-api_PolicyLogTriggerResponse' required: - timestamp - policy - trigger - actions posture-api_PolicyActionsInput: description: 'Actions to execute when this policy is triggered, grouped by action type. A policy must contain at least one action across all groups and may include at most one remediation.' type: object properties: remediation_types: description: Remediation actions to execute (at most one). type: array items: $ref: '#/components/schemas/posture-api_PolicyRemediationActionInput' maxItems: 1 webhook_configs: description: Webhook actions to execute. type: array items: $ref: '#/components/schemas/posture-api_PolicyWebhookActionInput' minProperties: 1 posture-api_PolicyRemediationTypeResponse: description: A remediation type configured for the policy. type: object properties: display_name: description: Display name/label of the remediation type. type: string example: Remove Public Access readOnly: true remediation_type: description: The system name of the remediation type. type: string example: remove_public_access readOnly: true remediation_type_id: description: Unique identifier for the remediation type. type: string format: uuid example: 5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a required: - remediation_type_id - remediation_type - display_name posture-api_PolicyLogWebhookResponse: description: A webhook job dispatched during a policy invocation. type: object properties: nickname: description: User-set nickname of the webhook configuration that fired. type: string example: SOC alerting url: description: Path to the webhook configuration in the dashboard. type: string example: /one/casb/webhooks/wh_001 required: - nickname - url posture-api_api-response-common: description: Common response structure for all API endpoints. type: object properties: errors: $ref: '#/components/schemas/posture-api_messages' messages: $ref: '#/components/schemas/posture-api_messages' success: description: Whether the API call was successful. type: boolean example: true required: - success - errors - messages posture-api_PolicyRemediationActionInput: description: A remediation action to be executed. type: object properties: remediation_type_id: description: The ID of the remediation type to execute. type: string format: uuid example: 5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a required: - remediation_type_id posture-api_UpdatePolicyRequest: description: Request body for updating an existing policy configuration. type: object properties: actions: $ref: '#/components/schemas/posture-api_PolicyActionsInput' applies_to_all_integrations: description: When true, the policy applies to all integrations for the account. When false, integration_ids must be provided. type: boolean example: false description: description: Optional description of what this policy does. type: string example: Automatically remove public access from files when detected maxLength: 1000 x-stainless-terraform-configurability: computed_optional display_name: description: Display name for the policy configuration. type: string example: Auto-remediate public files maxLength: 255 enabled: description: Boolean specifying if the policy is enabled or disabled. type: boolean example: true integration_ids: description: The integrations this policy applies to. Required when applies_to_all_integrations is false. type: array items: format: uuid type: string example: - 497f6eca-6276-4993-bfeb-53cbbbba6f08 x-stainless-terraform-configurability: computed_optional required: - display_name - enabled - applies_to_all_integrations - actions posture-api_PolicyResponse: description: Response body for a policy configuration. type: object properties: actions: $ref: '#/components/schemas/posture-api_PolicyActionsResponse' applies_to_all_integrations: description: When true, the policy applies to all integrations for the account. When false, it applies only to the specified integration_ids. type: boolean example: false created_at: description: Timestamp when the policy was created. type: string format: date-time example: '2025-03-18T17:25:38.700541Z' readOnly: true description: description: User-set description of what this policy does. Limited to 1000 characters. type: string example: Automatically remove public access from files when detected disabled_at: description: 'Timestamp when the policy was disabled. Omitted from the response when the policy is enabled.' type: string format: date-time example: '2025-03-18T17:25:38.700541Z' readOnly: true display_name: description: Display name for the policy configuration. Limited to 255 characters. type: string example: Auto-remediate public files enabled: description: Whether the policy is enabled. Derived from disabled_at (enabled when disabled_at is unset). type: boolean example: true finding_type_id: description: The finding type this policy is associated with. Immutable after creation; changing it replaces the policy. type: string format: uuid example: 5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a id: description: Unique identifier for the policy configuration. type: string format: uuid example: 497f6eca-6276-4993-bfeb-53cbbbba6f08 readOnly: true integration_ids: description: The integrations this policy applies to. type: array items: format: uuid type: string example: - 497f6eca-6276-4993-bfeb-53cbbbba6f08 last_triggered_at: description: 'Timestamp of the most recent successful policy invocation. Omitted from the response when the policy has never been successfully triggered. Only populated on GET responses; absent on responses from create/update endpoints.' type: string format: date-time example: '2025-03-18T17:25:38.700541Z' readOnly: true updated_at: description: Timestamp when the policy was last updated. type: string format: date-time example: '2025-03-18T17:25:38.700541Z' readOnly: true required: - id - created_at - updated_at - integration_ids - applies_to_all_integrations - finding_type_id - display_name - description - enabled - actions posture-api_PolicyLogRemediationResponse: description: A remediation job dispatched during a policy invocation. type: object properties: id: description: Identifier of the remediation job, suitable for cross-referencing with the remediations API. type: string example: rj_001 type: description: Display name of the remediation type that ran. type: string example: Revoke External Sharing url: description: Path to the remediation job in the dashboard. type: string example: /one/casb/remediations/rj_001 required: - type - id - url posture-api_messages: type: array items: properties: code: description: Error or message code. type: integer example: 1000 minimum: 1000 documentation_url: description: Link to relevant documentation. type: string format: uri example: https://developers.cloudflare.com/api/operations/list-findings message: description: Human-readable message. type: string example: Request processed successfully source: type: object properties: pointer: description: JSON pointer to the source of the error. type: string example: /data/attributes/name required: - code - message type: object example: [] uniqueItems: true posture-api_PolicyActionsResponse: description: The actions configured for this policy. type: object properties: remediation_types: description: List of remediation types that will be executed. type: array items: $ref: '#/components/schemas/posture-api_PolicyRemediationTypeResponse' webhook_configs: description: List of webhook configurations that will be triggered. type: array items: $ref: '#/components/schemas/posture-api_PolicyWebhookConfigResponse' required: - remediation_types - webhook_configs posture-api_PolicyLogPolicyResponse: description: The policy configuration that fired. type: object properties: name: description: Display name of the policy at the time it ran. type: string example: Auto-remediate publicly shared files url: description: URL to the policy configuration in the dashboard. Currently always an empty string; populated in a future revision once the upstream view exposes the policy configuration ID. type: string example: '' required: - name - url posture-api_DeletePolicyResponse: description: Response from DeletePolicy operation. type: object properties: id: description: ID of the policy deleted. type: string format: uuid example: 3f7b8c9d-6e5a-4f3b-9c2d-1e0a8b7c6d5e required: - id posture-api_result-info: description: Pagination and result information. type: object properties: count: description: Total number of results for the requested service. type: integer example: 1 cursor: description: Cursor for cursor-based pagination. type: - string - 'null' example: eyJpZCI6IjAwMDAwMDAwLTAwMDAtMDAwMC0wMDAwLTAwMDAwMDAwMDAwMCIsImFmZmxpY3Rpb25fZGF0ZSI6IjE5NzAtMDEtMDFUMDA6MDA6MDAuMDAwMDAwWiJ9 next: description: URL to the next page of results. type: - string - 'null' format: uri page: description: Current page within paginated list of results. type: integer example: 1 per_page: description: Number of results per page of results. type: integer example: 20 previous: description: URL to the previous page of results. type: - string - 'null' format: uri total_count: description: Total results available without any search parameters. type: integer example: 2000 parameters: posture-api_Page: description: A page number within the paginated result set. in: query name: page schema: type: integer posture-api_PolicyId: description: A UUID identifying the policy. in: path name: policy_id required: true schema: type: string format: uuid posture-api_AccountTag: description: Cloudflare account ID for the user making the request. example: 46148281d8a93d002ef242d8b0d5f9f6 in: path name: account_id required: true schema: type: string posture-api_PerPage: description: Number of results to return per page. in: query name: per_page schema: type: integer securitySchemes: api_email: in: header name: X-Auth-Email type: apiKey api_key: in: header name: X-Auth-Key type: apiKey api_token: scheme: bearer type: http user_service_key: in: header name: X-Auth-User-Service-Key type: apiKey externalDocs: description: Cloudflare Radar Documentation url: https://developers.cloudflare.com/radar/ x-forge-commands: abuse-reports: description: Submit and track abuse reports for phishing, malware, and other policy violations on Cloudflare-proxied sites groups: appeals: description: Appeal eligibility for abuse reports emails: description: Emails sent for abuse reports mitigations: description: Mitigation actions taken in response to abuse reports accounts: description: Account settings, members, roles, subscriptions, and API tokens for your Cloudflare account groups: applications: description: Applications operations categories: description: Categories operations organizations: description: Move accounts between organizations profile: description: View and manage the profile for a Cloudflare account roles: description: View the roles available for assigning to account members, each defining a set of permissions subscriptions: description: View and manage plan subscriptions attached to this account tokens: description: Create and manage scoped API tokens for programmatic access to the Cloudflare API ai-gateway: description: Proxy, cache, rate-limit, and observe requests to AI providers — OpenAI, Anthropic, Workers AI, and more groups: custom-domains: description: Manage custom hostnames that route requests through an AI Gateway custom-providers: description: Manage account-level custom AI providers and their endpoint settings datasets: description: 'Deprecated: manage filtered collections of gateway logs used by evaluations' dynamic-routing: description: Route requests across multiple AI providers with fallback, load-balancing, and versioned deployments dynamic-routing.deployments: description: Deploy dynamic route versions and view deployment history dynamic-routing.versions: description: Create and inspect saved versions of a dynamic route evaluation-types: description: 'Deprecated: list the evaluator types that evaluations can use' evaluations: description: 'Deprecated: score the logs in a dataset with selected evaluator types' gateways: description: Create and configure AI Gateways for an account gateways.providers: description: Store and rotate upstream AI provider keys for a gateway logs: description: Inspect, annotate, and delete gateway request logs stored by Legacy Logs ai-search: description: 'Managed search-as-a-service: crawl, index, and query content with AI-powered relevance and chat completions' groups: items: description: Content indexed by AI Search instances jobs: description: Indexing job lifecycle for AI Search instances namespace: description: Logical groupings for organizing AI Search instances tokens: description: Credentials used by AI Search instances ai-security: description: Detect prompt injection, PII, and unsafe topics in traffic to your AI applications groups: custom-topics: description: Organization-specific topic categories used by AI Security for Apps content detection analytics: description: Zone-level traffic analytics — dashboard summaries, per-colo breakdowns, and Argo latency metrics groups: colo: description: Per-data-center (colo) traffic analytics breakdown for the zone dashboard: description: Aggregated zone dashboard analytics — requests, bandwidth, threats, and page views latency: description: Argo Smart Routing latency analytics showing time-to-first-byte improvements argo: description: Network optimization features that speed up and improve reliability of traffic to your origins groups: smart-routing: description: Route traffic through the fastest network paths to your origin using real-time latency data tiered-caching: description: Reduce origin load by having upper-tier data centers serve cache misses before reaching your origin basin-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables billing: description: Account billing profiles and usage data for Cloudflare subscriptions and add-on services groups: profiles: description: Billing profile with payment method, address, and invoice preferences usage: description: Metered usage data for billed services — requests, bandwidth, and feature consumption botnet-feed: description: Botnet threat intelligence feeds — IP and ASN-level data on known command-and-control infrastructure groups: asn: description: ASN-level botnet activity data showing networks with known C2 infrastructure configs: description: Botnet feed subscription configuration and notification preferences builds: description: Build and deploy Workers from connected repositories, then inspect build status and logs. groups: deploy-hooks: description: Manage branch-specific HTTP hooks that start builds. limits: description: View build-minute availability and refresh information. logs: description: Retrieve build logs. repos: description: Manage source repository connections for Workers Builds. tokens: description: Manage credentials used by Workers Builds to deploy Workers. triggers: description: Configure how repository changes build and deploy Workers. versions: description: Find builds associated with Worker versions. workers: description: Manage repository-backed build configuration for Workers. cache: description: Purge cached content and configure Cache Reserve, tiered caching, and variant serving groups: origin-cloud-regions: description: Manage Origin Cloud Regions routing and failover configurations settings: description: Configure Cache Reserve, tiered caching, and variant serving settings.regional-tiered-cache: description: Restrict tiered cache topology to data centers within a specific geographic region settings.reserve: description: Persistent storage tier that keeps cached assets even after eviction from edge caches settings.smart-tiered-cache: description: Automatically determine the best upper-tier data centers for tiered cache topology settings.variants: description: Serve different cached versions of an image based on the Accept header (WebP, AVIF, etc.) client-side-security: description: Client-Side Security — monitor JavaScript, connections, and cookies on your pages for supply-chain attacks groups: connections: description: Third-party connections made by scripts on your pages — track data exfiltration risks cookies: description: Cookies set by your pages with classification and same-site attribute tracking policies: description: Content Security Policies that control which scripts and connections are allowed on your pages scripts: description: JavaScript files detected on your pages with change tracking and malicious code detection settings: description: Fine tune Client-Side Security behaviors cloud-connector: description: Route traffic from Cloudflare directly to cloud provider services (AWS, Azure, GCP) without origin servers groups: rules: description: Routing rules that map request patterns to cloud provider endpoints cloudforce-one: description: Detection rule management APIs groups: binary-storage: description: Upload and retrieve malware samples and suspicious binaries for analysis requests: description: Additional request operations — priority listing and asset creation rules: description: Rule management operations groups: approvals: description: Approval workflow operations email: description: Email rule operations exemptions: description: Exemption rule operations managed: description: Managed rule operations stats: description: Rule statistics operations tree: description: Rule navigation tree operations scans: description: Scan URLs, IPs, and domains for threat intelligence indicators containers: description: Deploy and manage Containers applications on Cloudflare's global network groups: applications: description: Manage Containers applications applications.instances: description: Inspect Containers instances belonging to applications applications.rollouts: description: Manage rollouts for scheduler-backed applications applications.versions: description: Inspect versions of scheduler-backed applications registries: description: Manage Containers image registries registries.credentials: description: Generate image registry credentials content-scan: description: Malicious uploads detection, scan uploaded content in HTTP requests for malware and malicious payloads groups: expressions: description: Custom expressions that tell the scanner how to reach content objects it cannot parse on its own custom-pages: description: Manage custom error and challenge pages and their assets for accounts and zones groups: account-custom-pages: description: Manage account-level custom pages account-custom-pages.preview-tokens: description: Preview tokens for account-level custom pages assets: description: Manage account- and zone-level custom assets zone-custom-pages: description: Manage zone-level custom pages zone-custom-pages.preview-tokens: description: Preview tokens for zone-level custom pages d1: description: D1 is Cloudflare's managed, serverless database with SQLite's SQL semantics, built-in disaster recovery, and Worker and HTTP API access. groups: time-travel: description: use specific point-in-time backups of your D1 database x-forge-epilogue: For more information about Time Travel, see https://developers.cloudflare.com/d1/reference/time-travel diagnostics: description: Network diagnostic tools — traceroutes from Cloudflare's edge and endpoint health checks groups: endpoint-healthchecks: description: Monitor external endpoint availability with periodic HTTP/HTTPS health checks traceroutes: description: Run traceroutes from Cloudflare data centers to diagnose network path issues email-routing: description: Route incoming email to verified destination addresses or Workers with routing rules, catch-all behavior, and managed DNS records groups: addresses: description: Verified destination email addresses that can receive forwarded mail dns: description: Inspect or unlock the DNS records required by Email Routing rules: description: Match incoming email addresses and forward messages to destination mailboxes or Workers settings: description: Inspect and update Email Routing settings email-security: description: Cloud email security — investigate threats, manage allow/block policies, and detect phishing groups: analytics: description: Analytics and reporting — monthly report and per-day breakdowns of threat activity bulk-actions: description: Asynchronous jobs that move or release every message matching a search — create, monitor, and manage bulk jobs investigate: description: Search and investigate email messages — view detections, traces, raw content, and take remediation actions phishguard: description: PhishGuard user-reported phishing reports — view detected threats for a date range settings: description: Email security configuration — block senders, allow policies, content policies, domains, trusted domains, impersonation registry, and URL handling submissions: description: Reclassify submissions — track user and team reports of false positives and missed detections email-sending: description: Send transactional email and manage sending subdomains and their DNS configuration groups: limits: description: Inspect account-level sending quotas and current usage subdomains: description: Configure sending subdomains and keep their DNS records healthy suppressions: description: Prevent delivery to suppressed addresses and manage the account suppression list filters: description: Filter expressions used by legacy firewall rules to match requests — prefer Rulesets for new configurations firewall: description: Legacy firewall rules, zone lockdowns, access rules, user-agent blocking, and WAF packages groups: access-rules: description: IP-based access rules that allow, block, challenge, or whitelist traffic globally or per-zone lockdowns: description: Zone lockdown rules that restrict access to URLs by IP address or range rules: description: Legacy firewall rules with filter expressions — prefer Rulesets for new configurations ua-rules: description: Block or challenge requests based on the User-Agent header string waf: description: Legacy WAF managed rule packages, rule groups, individual rules, and override configurations zone-access-rules: description: Zone-scoped IP access rules for blocking or allowing traffic google-tag-gateway: description: Google Tag Gateway operations groups: config: description: Google Tag Gateway config operations healthchecks: description: Standalone health checks that monitor origin server availability from Cloudflare's edge groups: previews: description: Test a health check configuration before deploying it to production hyperdrive: description: Accelerate access to existing databases by caching queries and pooling connections at the edge iam: description: Identity and access management — permission groups, resource groups, user groups, and SSO connectors groups: permission-groups: description: View the permission groups that can be assigned to API tokens and policies resource-groups: description: Define scopes that limit which account resources a policy or token can access sso: description: Configure single sign-on connectors to authenticate account members through an external identity provider user-groups: description: Organize account members into groups for easier permission assignment images: description: Store, resize, and deliver optimized images globally — variants, signing keys, and direct uploads groups: flows: description: Zone-level transformation flows that control how images are resized and optimized on delivery import: description: Import images from S3 keys: description: Manage signing keys for generating private image URLs variants: description: Manage named resize variants for transforming images on delivery intel: description: Threat intelligence lookups — IP reputation, domain info, ASN details, WHOIS, and indicator feeds groups: asn: description: ASN intelligence — ownership, geolocation, and subnet details for autonomous systems attack-surface-report: description: Attack surface intelligence — exposed assets, vulnerabilities, and infrastructure mapping dns: description: Passive DNS data showing historical DNS resolution records for domains domain-history: description: Historical domain registration and categorization changes over time domains: description: Domain intelligence — risk scores, categories, and associated infrastructure indicator-feeds: description: Threat indicator feeds — subscribe to and manage curated lists of malicious IPs, domains, and URLs ip-lists: description: Curated IP lists used for threat detection and policy enforcement ips: description: IP address intelligence — geolocation, risk assessment, and hosting provider details miscategorizations: description: Report and track domain miscategorization corrections whois: description: WHOIS registration data for domains including registrant, registrar, and nameservers k2: description: Durable, ordered event streams that you produce records to and consume from with subscriptions groups: streams: description: K2 streams, their retention, and the HTTP and Workers binding inputs used to produce records streams.subscriptions: description: Subscriptions that consume a K2 stream, with committed-position lag leaked-credential-checks: description: Detect compromised credentials in login requests by checking against known breach databases groups: detections: description: Custom detection locations that tell the WAF where to find usernames and passwords in requests load-balancers: description: Distribute traffic across origin pools with health monitoring, geo-steering, and failover groups: monitor-groups: description: Group monitors together for shared configuration and bulk management monitor-groups.references: description: List references to monitor groups used by load balancer pools monitors: description: Health check configurations that probe origin servers and determine pool availability monitors.previews: description: Health check configurations that probe origin servers and determine pool availability monitors.references: description: Health check configurations that probe origin servers and determine pool availability pools: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.health: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.references: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences previews: description: Preview the result of a health check monitor configuration before applying it regions: description: Geographic regions used for regional pool steering and traffic policies searches: description: Search across all load balancer resources (pools, monitors, load balancers) by name or reference logs: description: Log control, retention, and raw log access — CMB config, ray ID lookups, and received fields groups: control: description: Log control operations received: description: Received log operations magic-network-monitoring: description: Flow-based network traffic monitoring with configurable alerting rules and VPC flow ingestion groups: configs: description: Account-level monitoring configuration — sampling rates, thresholds, and notification settings rules: description: Monitoring rules that define traffic thresholds and trigger alerts or prefix advertisements vpc-flows: description: Ingest VPC flow logs from cloud providers for network visibility and anomaly detection magic-transit: description: DDoS-protected network transit — GRE/IPsec tunnels, static routes, Magic WAN sites, connectors, and packet captures groups: advanced-dns-protection: description: Advanced Dns Protection operations advanced-tcp-protection: description: Advanced Tcp Protection operations apps: description: Application-aware traffic policies for Magic WAN that steer traffic by app type bgp-filter-profiles: description: BGP filter profiles for controlling which routes are allowed or denied on Magic Transit tunnels bgp-settings: description: BGP settings for controlling default ASN and route redistribution on Magic Transit tunnels cf-interconnects: description: Cloudflare Network Interconnect (CNI) links for direct physical or virtual peering gre-tunnels: description: GRE tunnel endpoints that connect your network to Cloudflare for Magic Transit ipsec-tunnels: description: IPsec tunnel endpoints with pre-shared key management for encrypted transit pcaps: description: Packet capture requests for debugging traffic flowing through Magic Transit tunnels routes: description: Static routes that direct IP prefix traffic through specific GRE/IPsec tunnels sites: description: Magic WAN branch sites — base CRUD, LAN/WAN interface configuration, ACLs, connectors, app configuration, and NetFlow config mcp: description: Manage MCP portals and upstream MCP servers for Cloudflare Access AI controls groups: portals: description: Manage MCP portals, attached servers, and Code Mode settings servers: description: Manage upstream MCP servers, credentials, capabilities, and sync state network-interconnects: description: Physical and virtual private interconnects between your infrastructure and Cloudflare's network groups: cnis: description: Cloud Network Interconnect (CNI) connections — private links from cloud providers to Cloudflare interconnects: description: Physical cross-connect and partner interconnect sessions with LOA and status tracking settings: description: Account-level interconnect settings and default configurations slots: description: Available interconnect facility slots showing port capacity at Cloudflare data centers organizations: description: Multi-user organizations that group accounts, members, and shared settings under a single entity groups: account-organizations: description: List organizations associated with a specific account accounts: description: Accounts operations members: description: Members operations members-batch-create: description: Members Batch Create operations organization-profile: description: View and update the public profile information for an organization shares: description: Shares operations origin-post-quantum-encryption: description: Enable post-quantum key exchange for connections between Cloudflare and your origin server pages: description: Full-stack application hosting with Git-integrated builds, preview deployments, and custom domains groups: projects: description: Pages projects, deployments, build logs, and custom domain bindings pipelines: description: Ingest, transform, and route event streams into R2, analytics, or other destinations in real time groups: sinks: description: Destinations where pipeline data is written — R2 buckets, HTTP endpoints, or other storage streams: description: Inbound data streams that feed events into a pipeline for processing precursor: description: Precursor settings for a zone queues: description: Reliable message queuing between Workers — produce, consume, and batch-process messages at scale groups: consumers: description: Workers that automatically receive and process messages from a queue messages: description: Push messages to a queue and pull or acknowledge them from consumers purge: description: Remove all pending messages from a queue subscriptions: description: Manage queue subscriptions for event-driven message routing r2: description: S3-compatible object storage with zero egress fees — buckets, lifecycle rules, event notifications, and data migration groups: buckets: description: Create and configure R2 buckets including CORS, lifecycle, custom domains, event notifications, and object locks buckets.jobs: description: Create and inspect background jobs for an R2 bucket buckets.local-uploads: description: R2 bucket local upload configuration super-slurper: description: Migrate data from external S3-compatible storage into R2 buckets with resumable transfer jobs temporary-credentials: description: Generate short-lived S3-compatible credentials scoped to specific buckets and operations r2-data-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables radar: description: Internet-wide traffic intelligence — BGP, DNS, HTTP trends, attack data, and network quality insights groups: agent-readiness: description: Agent readiness summary statistics across the Cloudflare network ai: description: AI inference trends and model usage statistics across the Cloudflare network annotations: description: Radar annotations marking significant Internet events (outages, cable cuts, etc.) as112: description: AS112 DNS sinkhole statistics — reverse DNS query volumes for private address space attacks: description: DDoS and application-layer attack trends, vectors, and target analysis bgp: description: BGP routing data — prefix announcements, AS-level stats, route leaks, and hijack events bots: description: Internet-wide bot traffic trends, categories, and distribution statistics ct: description: Certificate Transparency log monitoring and newly-issued certificate discovery datasets: description: Downloadable Radar datasets for offline analysis and research dns: description: Global DNS query trends — top domains, resolver stats, and DNSSEC adoption email: description: Email security trends — DMARC/SPF/DKIM adoption, spam, and phishing statistics entities: description: Look up ASNs, IPs, domains, and locations with metadata and traffic summaries geolocations: description: Geographic location metadata used for regional traffic analysis http: description: HTTP protocol trends — TLS versions, HTTP versions, browser share, and OS distribution leaked-credentials: description: Leaked credential detection trends and exposure statistics netflows: description: Network-layer traffic flow data and volumetric trend analysis origins: description: Cloud and hosting origin providers (e.g. Amazon, by region) and their traffic metrics post-quantum: description: Post-quantum encryption adoption and deployment trends across the Internet quality: description: Internet connection quality metrics — speed, latency, and jitter by geography and ASN ranking: description: Top domain rankings based on DNS query popularity across the Cloudflare network robots-txt: description: Robots.txt adoption and crawler directive trends across the web search: description: Search Radar data across IPs, ASNs, domains, and locations tcp-resets-timeouts: description: TCP connection reset and timeout statistics indicating network health issues tlds: description: Top-level domain (TLD) metadata and performance trends traffic-anomalies: description: Detected traffic anomalies and unusual patterns in Internet traffic flows verified-bots: description: Catalog of known good bots (Googlebot, Bingbot, etc.) and their traffic patterns rate-limits: description: Legacy per-zone rate limiting rules — prefer Advanced Rate Limiting in Rulesets for new configurations realtime: description: Real-time audio, video, and data services on Cloudflare's global network groups: kit: description: SDK-backed meetings, participants, recordings, livestreams, and webhooks kit.analytics: description: Usage and livestream analytics for RealtimeKit applications kit.analytics.livestreams: description: Livestream analytics for RealtimeKit applications kit.analytics.livestreams.daily: description: Daily livestream analytics for RealtimeKit applications kit.analytics.usage: description: Usage analytics for RealtimeKit applications kit.apps: description: RealtimeKit applications that group meetings, sessions, and configuration kit.livestreams: description: Independent and meeting-based livestreams and their sessions kit.livestreams.sessions: description: Sessions for RealtimeKit livestreams kit.meetings: description: Meetings, participants, access tokens, and meeting livestreams kit.meetings.active: description: Live meeting state and participant controls kit.meetings.active.polls: description: Polls for active meeting sessions kit.meetings.livestream: description: Livestream operations associated with RealtimeKit meetings kit.meetings.participants: description: Participants in RealtimeKit meetings kit.meetings.participants.tokens: description: Access tokens for RealtimeKit meeting participants kit.presets: description: Reusable meeting configuration for media, permissions, and interface behavior kit.recordings: description: Meeting and participant-track recordings and recording controls kit.recordings.active: description: Active recordings for RealtimeKit meetings kit.recordings.tracks: description: Participant-track recordings for RealtimeKit meetings kit.sessions: description: Historical session data, participants, chat, transcripts, and summaries kit.sessions.chat: description: Chat messages from historical RealtimeKit sessions kit.sessions.livestreams: description: Livestreams associated with historical RealtimeKit sessions kit.sessions.participants: description: Participants in historical RealtimeKit sessions kit.sessions.peers: description: Peer details from historical RealtimeKit sessions kit.sessions.summaries: description: Summaries of historical RealtimeKit sessions kit.sessions.transcripts: description: Transcripts from historical RealtimeKit sessions kit.webhooks: description: Webhook endpoints and supported events for RealtimeKit notifications kit.webhooks.events: description: Supported events for RealtimeKit webhooks moq: description: MoQ relays for publishing and subscribing to media streams moq.relays: description: Relays are isolated MoQ scopes that carry media between publishers and subscribers moq.relays.tokens: description: Tokens that authorize publishers and subscribers to connect to a relay sfu: description: SFU apps that route WebRTC media and data between participants sfu.apps: description: SFU application namespaces for sessions and tracks turn: description: TURN keys that help clients traverse NATs and firewalls turn.keys: description: Keys used to generate short-lived TURN credentials request-tracers: description: Trace how a request would be processed through Cloudflare's rules and configuration pipeline groups: traces: description: Simulate request processing to debug rule matches, transforms, and routing decisions resource-sharing: description: Share Cloudflare resources (zones, accounts) across organizations with granular access controls groups: recipients: description: Update share recipients resources: description: Individual resources (zones, configs) that have been shared with recipients rules: description: Resources used by Cloudflare rules and rulesets groups: lists: description: Custom account-level lists of IPs, hostnames, ASNs, or redirects used in rule expressions rum: description: Real User Measurement (Web Analytics) — track page loads, Core Web Vitals, and visitor metrics groups: rules: description: Rules that control which pages and paths are tracked by Web Analytics site-info: description: Web Analytics sites — register domains and get the JavaScript beacon snippet scim: description: SCIM 2.0 provisioning — manage users, groups, and identity provider sync for your account groups: groups: description: Groups operations resource-types: description: Resource Types operations schemas: description: Schemas operations service-provider-config: description: Service Provider Config operations users: description: Users operations secrets-store: description: Centralized secret management — store API keys, tokens, and credentials for use across Workers and other products groups: quota: description: Account quota limits for secrets stores, secrets count, and storage capacity secrets: description: Encrypted key-value secrets within a store. Pass --store-id to scope. stores: description: Secret stores that hold encrypted key-value secrets accessible by Workers and services security-center: description: Security posture dashboard — view and manage security insights, misconfigurations, and vulnerabilities groups: insights: description: Security findings and recommendations across your account — DNS, SSL, WAF misconfigurations, etc. zone-insights: description: Zone-scoped security insights — counts by class, severity, type, and dismissal security-txt: description: Manage the /.well-known/security.txt file that tells security researchers how to report vulnerabilities smart-shield: description: Smart Shield settings, health checks, and cache reserve management groups: cache-reserve-clear: description: Cache Reserve Clear operations health-checks: description: Health checks operations spectrum: description: Proxy and protect arbitrary TCP/UDP applications through Cloudflare's network with DDoS mitigation groups: analytics: description: Real-time and historical connection analytics for Spectrum applications apps: description: Spectrum application configurations that map protocols and ports to origin servers speed: description: Observatory speed tests — run Lighthouse audits, track performance trends, and schedule recurring tests groups: availabilities: description: Check which speed test regions and configurations are available for your zone pages: description: Tested pages with their performance history, trends, and individual test results schedule: description: Scheduled recurring speed tests that automatically run at regular intervals ssl: description: SSL/TLS certificate management — certificate packs, Universal SSL, verification, and TLS mode recommendations groups: automatic-upgrader: description: SSL automatic mode enrollment — get or update automatic SSL/TLS upgrader settings recommendations: description: Get the recommended SSL/TLS encryption mode based on your origin server's certificate configuration stream: description: Video encoding, storage, and delivery — upload, live-stream, clip, caption, and embed video at scale groups: audio-tracks: description: Add, edit, or remove additional audio tracks on a video captions: description: Upload, generate, or retrieve captions and subtitles for videos in multiple languages clip: description: Create a new video clip from an existing video by specifying start and end times copy: description: Import a video from a URL into Stream for processing and delivery direct-upload: description: Generate a tokenized URL that lets end-users upload video directly to Stream downloads: description: Create downloadable MP4 renditions of a video for offline viewing embed: description: Retrieve the HTML embed code snippet for a video keys: description: Signing keys used to generate short-lived signed URLs for private video playback live-inputs: description: Enable and disable live input streams token: description: Generate short-lived signed URL tokens for secure private video playback typed-downloads: description: Type-specific stream download creation and deletion videos: description: Aggregate video storage usage statistics for the account watermarks: description: Watermark profiles that overlay an image on every video in the account webhooks: description: Webhook notifications for video lifecycle events (ready, error, etc.) tenants: description: Multi-tenant account management — manage tenant accounts, entitlements, and memberships groups: account-types: description: Account Types operations accounts: description: Accounts operations entitlements: description: Entitlements operations memberships: description: Memberships operations turnstile: description: CAPTCHA-free bot verification widgets that protect forms and APIs without degrading user experience groups: widgets: description: Turnstile widget configurations — site keys, secret rotation, and challenge mode settings url-scanner: description: Scan URLs for phishing, malware, and other threats — submit scans and retrieve detailed results groups: response: description: Response operations responses: description: Raw HTTP response data captured during URL scans scan: description: Scan operations scans: description: URL scan requests and results — submit URLs for analysis and retrieve threat verdicts user: description: Your Cloudflare user profile, invitations, organizations, billing, and personal API tokens groups: billing: description: View billing history and payment profile for your user (deprecated — prefer account-level billing) firewall: description: Firewall operations load-balancers.monitors: description: Load Balancers operations load-balancers.monitors.preview: description: Load Balancers operations load-balancers.monitors.references: description: Load Balancers operations load-balancers.pools: description: Load Balancers operations load-balancers.pools.edit.pools: description: Load Balancers operations load-balancers.pools.health: description: Load Balancers operations load-balancers.pools.preview: description: Load Balancers operations load-balancers.pools.references: description: Load Balancers operations load-balancers.preview: description: Load Balancers operations load-balancing-analytics.events: description: Load Balancing Analytics operations subscriptions: description: View and manage zone-level plan subscriptions owned by your user tenants: description: Tenants operations tokens: description: Create and manage personal API tokens scoped to your user for programmatic API access user.analytics: description: User-level traffic analytics — aggregated totals and timeseries across all zones vectorize: description: Globally distributed vector database for building semantic search, recommendations, and RAG applications on Workers groups: deprecated-indexes: description: Deprecated v1 Vectorize index operations metadata-index: description: Metadata indexes for filtered vector search waiting-rooms: description: Virtual queues that throttle traffic to your site during peak demand with customizable waiting pages groups: account-waiting-rooms: description: Account-scoped waiting room listing events: description: Scheduled events that temporarily override waiting room settings for sales, launches, etc. page: description: Custom HTML waiting page templates and preview rendering rules: description: Rules that bypass or modify waiting room behavior for specific request patterns settings: description: Zone-level waiting room defaults and cookie configuration statuses: description: Real-time queue status showing active users, queued users, and estimated wait times workflows: description: Durable, multi-step workflows that run on Workers with automatic retries and state persistence groups: instances: description: Workflow instance operations versions: description: Workflow version operations zaraz: description: Server-side tag manager — load third-party tools (analytics, pixels, etc.) from Cloudflare's edge without client-side JS groups: config: description: Full Zaraz configuration including tools, triggers, and variables for the zone default: description: Default Zaraz configuration template used as a starting point for new zones export: description: Export the current Zaraz configuration as a portable JSON document history: description: Configuration version history — browse and restore previous Zaraz configurations publish: description: Publish pending Zaraz configuration changes to make them live on the zone workflow: description: Workflow state for Zaraz configuration changes (draft vs. published) zero-trust: description: Cloudflare's SASE platform — secure access, device posture, DLP, tunnels, gateway policies, and network segmentation groups: dex: description: Digital Experience Monitoring — synthetic tests, fleet-wide device metrics, and network path diagnostics dlp.custom-prompt-topics: description: Data Loss Prevention - manage custom prompt topics for AI-based content detection dlp.data-classes: description: Data Loss Prevention - manage data classes used to classify sensitive information dlp.data-tag-categories: description: Data Loss Prevention - manage categories that organize data tags dlp.data-tag-category-templates: description: Data Loss Prevention - browse templates for creating data tag categories dlp.data-tags: description: Data Loss Prevention - manage tags used to classify and organize sensitive data dlp.datasets: description: Data Loss Prevention - manage datasets, versions, and uploads dlp.document-fingerprints: description: Data Loss Prevention - manage document fingerprints for detecting matching documents dlp.email.account-mapping: description: Data Loss Prevention - configure account mappings for outbound email scanning dlp.email.rules: description: Data Loss Prevention - manage outbound email scanning rules and their priorities dlp.entries: description: Data Loss Prevention - list and manage detection entries dlp.limits: description: Data Loss Prevention - view account limits and resource quotas dlp.patterns: description: Data Loss Prevention - validate regular expressions used for content detection dlp.profiles: description: Data Loss Prevention - list and retrieve profiles dlp.profiles.custom: description: Data Loss Prevention - manage custom profiles dlp.profiles.predefined: description: Data Loss Prevention - manage predefined profiles dlp.sensitivity-group-templates: description: Data Loss Prevention - browse templates for creating sensitivity groups dlp.sensitivity-groups: description: Data Loss Prevention - manage sensitivity groups and their level ordering dlp.sensitivity-levels: description: Data Loss Prevention - manage sensitivity levels within sensitivity groups dlp.settings: description: Data Loss Prevention - manage account-level settings dlp.validators: description: Data Loss Prevention - list and retrieve content validators dlp.validators.proximity-words: description: Data Loss Prevention - manage proximity-word validators risk-scoring: description: User Risk Scoring - retrieve and reset user risk scores risk-scoring.behaviours: description: User Risk Scoring - manage behaviors used to calculate user risk scores risk-scoring.integrations: description: User Risk Scoring - manage integrations that provide risk score signals risk-scoring.integrations.references: description: User Risk Scoring - retrieve integrations by external reference risk-scoring.summary: description: User Risk Scoring - retrieve account risk score summaries zones: description: Zones are domains on Cloudflare — list, create, and configure domain settings groups: aegis: description: Aegis operations fonts: description: Fonts operations origin-h2-max-streams: description: Origin H2 Max Streams operations origin-max-http-version: description: Origin Max Http Version operations origin-tls-compliance-modes: description: Manage zone Origin TLS Compliance Modes setting rum: description: Rum operations speed-brain: description: Speed Brain operations