openapi: 3.2.0 info: description: Welcome to Cloudflare's API documentation site. license: name: BSD-3-Clause url: https://opensource.org/licenses/BSD-3-Clause title: Cloudflare Recordings API version: 4.0.0 servers: - description: Client API url: https://api.cloudflare.com/client/v4 security: - api_email: [] api_key: [] - api_token: [] - user_service_key: [] tags: - name: Recordings paths: /accounts/{account_id}/realtime/kit/{app_id}/recordings: get: operationId: get_all_recordings summary: Fetch all recordings for an App description: Returns all recordings for an App. If the `meeting_id` parameter is passed, returns all recordings for the given meeting ID. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_account_identifier' - name: app_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_app_id' - name: meeting_id in: query description: ID of a meeting. Optional. Will limit results to only this meeting if passed. schema: type: string format: uuid - $ref: '#/components/parameters/realtimekit_pageNo' - $ref: '#/components/parameters/realtimekit_perPage' - name: expired in: query description: If passed, only shows expired/non-expired recordings on RealtimeKit's bucket schema: type: boolean - $ref: '#/components/parameters/realtimekit_search' - $ref: '#/components/parameters/realtimekit_recordingSortBy' - $ref: '#/components/parameters/realtimekit_sortOrder' - $ref: '#/components/parameters/realtimekit_startTime' - $ref: '#/components/parameters/realtimekit_endTime' - $ref: '#/components/parameters/realtimekit_recordingStatus' responses: '200': $ref: '#/components/responses/realtimekit_GetRecordings' security: - api_token: [] tags: - Recordings x-api-token-group: - Realtime Admin - Realtime x-fern-availability: beta x-fern-sdk-group-name: realtime.kit.recordings x-fern-sdk-method-name: list post: operationId: start_recording summary: Start recording a meeting description: Starts recording a meeting. The meeting can be started by an App admin directly, or a participant with permissions to start a recording, based on the type of authorization used. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_account_identifier' - name: app_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_app_id' requestBody: $ref: '#/components/requestBodies/realtimekit_StartRecording' responses: '200': $ref: '#/components/responses/realtimekit_GetRecording' security: - api_token: [] tags: - Recordings x-api-token-group: - Realtime Admin - Realtime x-fern-availability: beta x-fern-sdk-group-name: realtime.kit.recordings x-fern-sdk-method-name: start x-stability: beta /accounts/{account_id}/realtime/kit/{app_id}/recordings/active-recording/{meeting_id}: get: operationId: get_active_recording summary: Fetch active recording description: Returns the active recording details for the given meeting ID. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_account_identifier' - name: app_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_app_id' - name: meeting_id in: path description: ID of the meeting required: true schema: type: string responses: '200': $ref: '#/components/responses/realtimekit_GetActiveRecording' '404': $ref: '#/components/responses/realtimekit_GenericError' security: - api_token: [] tags: - Recordings x-api-token-group: - Realtime Admin - Realtime x-fern-availability: beta x-fern-sdk-group-name: realtime.kit.recordings.active x-fern-sdk-method-name: get /accounts/{account_id}/realtime/kit/{app_id}/recordings/track: post: operationId: startTrackRecordingForAMeeting summary: Start recording participant audio tracks description: Starts track recording for a meeting. Track recording currently records separate participant audio tracks as WebM files in the RealtimeKit bucket. Video track recording is in development. For more information, refer to Track recording. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_account_identifier' - name: app_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_app_id' requestBody: $ref: '#/components/requestBodies/realtimekit_StartTrackRecordingBody' responses: '200': description: OK content: application/json: schema: allOf: - $ref: '#/components/schemas/realtimekit_GenericSuccessResponse' - properties: data: type: object properties: recording: $ref: '#/components/schemas/realtimekit_Recording' required: - recording type: object security: - api_token: [] tags: - Recordings x-api-token-group: - Realtime Admin - Realtime x-fern-availability: beta x-fern-sdk-group-name: realtime.kit.recordings.tracks x-fern-sdk-method-name: start /accounts/{account_id}/realtime/kit/{app_id}/recordings/{recording_id}: get: operationId: get_one_recording summary: Fetch details of a recording description: Returns details of a recording for the given recording ID. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_account_identifier' - name: app_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_app_id' - name: recording_id in: path description: ID of the recording required: true schema: type: string format: uuid responses: '200': $ref: '#/components/responses/realtimekit_GetRecording' security: - api_token: [] tags: - Recordings x-api-token-group: - Realtime Admin - Realtime x-fern-availability: beta x-fern-sdk-group-name: realtime.kit.recordings x-fern-sdk-method-name: get x-stability: beta put: operationId: pause_resume_stop_recording summary: Pause/Resume/Stop recording description: Pause/Resume/Stop a given recording ID. parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_account_identifier' - name: app_id in: path required: true schema: $ref: '#/components/schemas/realtimekit_app_id' - name: recording_id in: path description: ID of the recording required: true schema: type: string format: uuid requestBody: required: true content: application/json: schema: type: object properties: action: type: string enum: - stop - pause - resume required: - action responses: '200': $ref: '#/components/responses/realtimekit_GetRecording' security: - api_token: [] tags: - Recordings x-api-token-group: - Realtime Admin - Realtime x-fern-availability: beta x-fern-sdk-group-name: realtime.kit.recordings x-fern-sdk-method-name: control x-stability: beta components: responses: realtimekit_GetActiveRecording: description: Success response content: application/json: schema: allOf: - $ref: '#/components/schemas/realtimekit_GenericSuccessResponse' - properties: data: $ref: '#/components/schemas/realtimekit_Recording' required: - data type: object realtimekit_GetRecordings: description: Success response content: application/json: schema: allOf: - $ref: '#/components/schemas/realtimekit_PagingResponse' - properties: data: type: array items: allOf: - $ref: '#/components/schemas/realtimekit_Recording' - properties: storage_config: $ref: '#/components/schemas/realtimekit_StorageConfig' type: object - properties: meeting: $ref: '#/components/schemas/realtimekit_Meeting' type: object type: object realtimekit_GetRecording: description: Success response content: application/json: schema: allOf: - $ref: '#/components/schemas/realtimekit_GenericSuccessResponse' - properties: data: allOf: - $ref: '#/components/schemas/realtimekit_Recording' - properties: start_reason: $ref: '#/components/schemas/realtimekit_startReason' stop_reason: $ref: '#/components/schemas/realtimekit_stopReason' storage_config: $ref: '#/components/schemas/realtimekit_StorageConfig' type: object type: object realtimekit_GenericError: description: Failure response content: application/json: schema: $ref: '#/components/schemas/realtimekit_GenericErrorResponse' schemas: realtimekit_LivestreamingConfig: type: object properties: rtmp_url: description: RTMP URL to stream to type: string format: uri example: rtmp://a.rtmp.youtube.com/live2 title: LivestreamingConfig realtimekit_StorageConfig: type: - object - 'null' properties: access_key: description: 'Access key of the storage medium. Access key is not required for the `gcs` storage media type. Note that this field is not readable by clients, only writeable.' type: string writeOnly: true x-sensitive: true auth_method: description: 'Authentication method used for "sftp" type storage medium ' type: string enum: - KEY - PASSWORD bucket: description: Name of the storage medium's bucket. type: string host: description: SSH destination server host for SFTP type storage medium type: string password: description: SSH destination server password for SFTP type storage medium when auth_method is "PASSWORD". If auth_method is "KEY", this specifies the password for the ssh private key. type: string writeOnly: true x-sensitive: true path: description: Path relative to the bucket root at which the recording will be placed. type: string port: description: SSH destination server port for SFTP type storage medium type: number private_key: description: Private key used to login to destination SSH server for SFTP type storage medium, when auth_method used is "KEY" type: string writeOnly: true x-sensitive: true region: description: Region of the storage medium. type: string example: us-east-1 secret: description: Secret key of the storage medium. Similar to `access_key`, it is only writeable by clients, not readable. type: string writeOnly: true x-sensitive: true type: description: Type of storage media. type: string enum: - aws - azure - digitalocean - gcs - sftp username: description: SSH destination server username for SFTP type storage medium type: string oneOf: - properties: type: enum: - gcs - properties: access_key: minLength: 1 region: minLength: 1 type: enum: - aws - azure - digitalocean required: - access_key - region - oneOf: - properties: auth_method: enum: - KEY required: - private_key - properties: auth_method: enum: - PASSWORD required: - password properties: access_key: minLength: 1 region: minLength: 1 type: enum: - sftp required: - access_key - region - auth_method - username - host - port required: - type - bucket title: StorageConfig realtimekit_RecordingConfig: description: 'Recording Configurations to be used for this meeting. This level of configs takes higher preference over App level configs on the RealtimeKit developer portal. ' type: object properties: audio_config: $ref: '#/components/schemas/realtimekit_AudioConfig' file_name_prefix: description: Adds a prefix to the beginning of the file name of the recording. type: string live_streaming_config: $ref: '#/components/schemas/realtimekit_LivestreamingConfig' max_seconds: description: Specifies the maximum duration for recording in seconds, ranging from a minimum of 60 seconds to a maximum of 24 hours. type: number maximum: 86400 minimum: 60 realtimekit_bucket_config: $ref: '#/components/schemas/realtimekit_realtimekitBucketConfig' storage_config: $ref: '#/components/schemas/realtimekit_StorageConfig' video_config: $ref: '#/components/schemas/realtimekit_VideoConfig' title: RecordingConfig realtimekit_startReason: type: object properties: caller: type: object properties: name: description: Name of the user who started the recording. type: string example: RealtimeKit_test type: description: The type can be an App or a user. If the type is `user`, then only the `user_Id` and `name` are returned. type: string enum: - ORGANIZATION - USER user_Id: description: The user ID of the person who started the recording. type: string format: uuid example: d61f6956-e68f-4375-bf10-c38a704d1bec reason: description: "Specifies if the recording was started using the \"Start a Recording\"API or using the parameter RECORD_ON_START in the \"Create a meeting\" API. \n\nIf the recording is initiated using the \"RECORD_ON_START\" parameter, the user details will not be populated." type: string enum: - API_CALL - RECORD_ON_START title: startReason realtimekit_TrackConfigLayer: type: object properties: file_name_prefix: description: A file name prefix to apply for files generated from this layer type: string pattern: ^[-\w\s]+$ media_kind: description: Media kind to record. Track recording currently supports audio only. type: string default: audio enum: - audio title: TrackLayerConfig realtimekit_stopReason: type: object properties: caller: type: object properties: name: description: Name of the user who stopped the recording. type: string example: RealtimeKit_test type: description: The type can be an App or a user. If the type is `user`, then only the `user_Id` and `name` are returned. type: string enum: - ORGANIZATION - USER user_Id: description: The user ID of the person who stopped the recording. type: string format: uuid example: d61f6956-e68f-4375-bf10-c38a704d1bec reason: description: Specifies the reason why the recording stopped. type: string enum: - API_CALL - INTERNAL_ERROR - ALL_PEERS_LEFT title: stopReason realtimekit_VideoConfig: type: object properties: codec: description: Codec using which the recording will be encoded. type: string default: H264 enum: - H264 - VP8 - VP9 export_file: description: Controls whether to export video file seperately type: boolean default: true height: description: Height of the recording video in pixels type: integer example: 720 default: 720 maximum: 1920 minimum: 1 watermark: description: Watermark to be added to the recording type: object properties: position: description: Position of the watermark type: string default: left top enum: - left top - right top - left bottom - right bottom size: description: Size of the watermark type: object properties: height: description: Height of the watermark in px type: integer minimum: 1 width: description: Width of the watermark in px type: integer minimum: 1 url: description: URL of the watermark image type: string format: uri width: description: Width of the recording video in pixels type: integer example: 1280 default: 1280 maximum: 1920 minimum: 1 title: VideoConfig realtimekit_PagingInfo: type: object properties: end_offset: type: number example: 30 start_offset: type: number example: 1 total_count: type: number example: 30 minimum: 0 required: - total_count - start_offset - end_offset title: PagingInfo realtimekit_account_identifier: description: The account identifier tag. type: string example: 023e105f4ecef8ad9ca31a8372d0c353 maxLength: 32 x-auditable: true realtimekit_InteractiveConfig: description: Allows you to add timed metadata to your recordings, which are digital markers inserted into a video file to provide contextual information at specific points in the content range. The ID3 tags containing this information are available to clients on the playback timeline in HLS format. The output files are generated in a compressed .tar format. type: object properties: type: description: The metadata is presented in the form of ID3 tags. type: string enum: - ID3 title: InteractiveConfig realtimekit_AudioConfig: description: Object containing configuration regarding the audio that is being recorded. type: object properties: channel: description: Audio signal pathway within an audio file that carries a specific sound source. type: string default: stereo enum: - mono - stereo codec: description: Codec using which the recording will be encoded. If VP8/VP9 is selected for videoConfig, changing audioConfig is not allowed. In this case, the codec in the audioConfig is automatically set to vorbis. type: string default: AAC enum: - MP3 - AAC export_file: description: Controls whether to export audio file seperately type: boolean default: true title: AudioConfig realtimekit_realtimekitBucketConfig: type: object properties: enabled: description: Controls whether recordings are uploaded to RealtimeKit's bucket. If set to false, `download_url`, `audio_download_url`, `download_url_expiry` won't be generated for a recording. type: boolean required: - enabled title: realtimekitBucketConfig realtimekit_Meeting: type: object properties: created_at: description: Timestamp the object was created at. The time is returned in ISO format. type: string format: date-time readOnly: true id: description: ID of the meeting. type: string format: uuid readOnly: true live_stream_on_start: description: Specifies if the meeting should start getting livestreamed on start. type: boolean persist_chat: description: Specifies if Chat within a meeting should persist for a week. type: boolean record_on_start: description: Specifies if the meeting should start getting recorded as soon as someone joins the meeting. type: boolean recording_config: $ref: '#/components/schemas/realtimekit_RecordingConfig' session_keep_alive_time_in_secs: description: Time in seconds, for which a session remains active, after the last participant has left the meeting. type: number default: 60 maximum: 600 minimum: 60 status: description: Whether the meeting is `ACTIVE` or `INACTIVE`. Users will not be able to join an `INACTIVE` meeting. type: string enum: - ACTIVE - INACTIVE summarize_on_end: description: Automatically generate summary of meetings using transcripts. Requires Transcriptions to be enabled, and can be retrieved via Webhooks or summary API. type: boolean title: description: Title of the meeting. type: string transcribe_on_end: description: Automatically generate transcripts when the meeting ends. type: boolean updated_at: description: Timestamp the object was updated at. The time is returned in ISO format. type: string format: date-time readOnly: true required: - id - created_at - updated_at realtimekit_Recording: type: object properties: audio_download_url: description: If the audio_config is passed, the URL for downloading the audio recording is returned. type: - string - 'null' format: uri readOnly: true download_url: description: URL where the recording can be downloaded. type: - string - 'null' format: uri readOnly: true download_url_expiry: description: Timestamp when the download URL expires. type: - string - 'null' format: date-time readOnly: true file_size: description: File size of the recording, in bytes. type: - number - 'null' readOnly: true id: description: ID of the recording type: string format: uuid readOnly: true invoked_time: description: Timestamp when this recording was invoked. type: string format: date-time output_file_name: description: File name of the recording. type: string recording_duration: description: Total recording time in seconds. type: integer session_id: description: ID of the meeting session this recording is for. type: - string - 'null' format: uuid readOnly: true started_time: description: Timestamp when this recording actually started after being invoked. Usually a few seconds after `invoked_time`. type: - string - 'null' format: date-time status: description: Current status of the recording. type: string enum: - INVOKED - RECORDING - UPLOADING - UPLOADED - ERRORED - PAUSED stopped_time: description: Timestamp when this recording was stopped. Optional; is present only when the recording has actually been stopped. type: - string - 'null' format: date-time required: - id - download_url - download_url_expiry - audio_download_url - file_size - session_id - output_file_name - status - invoked_time - started_time - stopped_time title: Recording realtimekit_GenericSuccessResponse: type: object properties: data: description: Data returned by the operation type: object success: description: Success status of the operation type: boolean default: true required: - success title: GenericSuccessResponse realtimekit_GenericErrorResponse: type: object properties: error: type: object properties: code: description: HTTP status code of the error. type: number message: description: Error message describing what went wrong. type: string required: - code - message success: description: Success status of the request. type: boolean default: false required: - success - error realtimekit_PagingResponse: type: object properties: data: type: array items: type: object paging: $ref: '#/components/schemas/realtimekit_PagingInfo' success: type: boolean example: true required: - success - data - paging title: PagingResponse realtimekit_app_id: description: The app identifier tag. type: string example: 14a396e7-ca44-4937-bf1f-050a69118543 parameters: realtimekit_search: description: The search query string. You can search using the meeting ID or title. in: query name: search schema: type: string realtimekit_startTime: description: The start time range for which you want to retrieve the meetings. The time must be specified in ISO format. in: query name: start_time schema: type: string format: date-time realtimekit_recordingSortBy: in: query name: sort_by schema: type: string enum: - invokedTime realtimekit_perPage: allowEmptyValue: true description: Number of results per page in: query name: per_page schema: type: number minimum: 0 realtimekit_endTime: description: The end time range for which you want to retrieve the meetings. The time must be specified in ISO format. in: query name: end_time schema: type: string format: date-time realtimekit_sortOrder: in: query name: sort_order schema: type: string enum: - ASC - DESC realtimekit_recordingStatus: description: Filter by one or more recording status explode: false in: query name: status schema: type: array items: enum: - INVOKED - RECORDING - UPLOADING - UPLOADED - ERRORED - PAUSED type: string realtimekit_pageNo: allowEmptyValue: true description: The page number from which you want your page search results to be displayed. in: query name: page_no schema: type: number minimum: 0 requestBodies: realtimekit_StartRecording: content: application/json: examples: Example 1: value: allow_multiple_recordings: false audio_config: channel: stereo codec: AAC export_file: true file_name_prefix: string interactive_config: type: ID3 max_seconds: 60 meeting_id: 97440c6a-140b-40a9-9499-b23fd7a3868a realtimekit_bucket_config: enabled: true video_config: codec: H264 export_file: true height: 720 watermark: position: left top size: height: 1 width: 1 url: http://example.com width: 1280 schema: type: object properties: allow_multiple_recordings: description: By default, a meeting allows only one recording to run at a time. Enabling the `allow_multiple_recordings` parameter to true allows you to initiate multiple recordings concurrently in the same meeting. This allows you to record separate videos of the same meeting with different configurations, such as portrait mode or landscape mode. type: boolean default: false audio_config: $ref: '#/components/schemas/realtimekit_AudioConfig' file_name_prefix: description: Update the recording file name. type: string interactive_config: $ref: '#/components/schemas/realtimekit_InteractiveConfig' max_seconds: description: Specifies the maximum duration for recording in seconds, ranging from a minimum of 60 seconds to a maximum of 24 hours. type: integer maximum: 86400 minimum: 60 meeting_id: description: ID of the meeting to record. type: string format: uuid realtimekit_bucket_config: $ref: '#/components/schemas/realtimekit_realtimekitBucketConfig' rtmp_out_config: $ref: '#/components/schemas/realtimekit_LivestreamingConfig' storage_config: $ref: '#/components/schemas/realtimekit_StorageConfig' url: description: Pass a custom url to record arbitary screen type: string format: uri video_config: $ref: '#/components/schemas/realtimekit_VideoConfig' required: - meeting_id required: true realtimekit_StartTrackRecordingBody: content: application/json: examples: Basic: value: meeting_id: 97440c6a-140b-40a9-9499-b23fd7a3868a With file name prefix: value: layers: default: file_name_prefix: speaker media_kind: audio meeting_id: 97440c6a-140b-40a9-9499-b23fd7a3868a schema: type: object properties: layers: description: Optional audio layer configuration. If omitted, RealtimeKit records all participant audio using the default file name prefix. type: object additionalProperties: $ref: '#/components/schemas/realtimekit_TrackConfigLayer' meeting_id: description: ID of the meeting to record. type: string format: uuid user_ids: description: Optional list of participant user IDs to record. Selective track recording (`user_ids`) is in early beta contact support to use this feature. type: array items: maxLength: 256 minLength: 1 type: string maxItems: 100 minItems: 1 required: - meeting_id description: Starts audio track recording for an active meeting. Use `layers` only when you need to set a file name prefix. Selective track recording (`user_ids`) is in early beta contact support to use this feature. required: true securitySchemes: api_email: in: header name: X-Auth-Email type: apiKey api_key: in: header name: X-Auth-Key type: apiKey api_token: scheme: bearer type: http user_service_key: in: header name: X-Auth-User-Service-Key type: apiKey externalDocs: description: Cloudflare Radar Documentation url: https://developers.cloudflare.com/radar/ x-forge-commands: abuse-reports: description: Submit and track abuse reports for phishing, malware, and other policy violations on Cloudflare-proxied sites groups: appeals: description: Appeal eligibility for abuse reports emails: description: Emails sent for abuse reports mitigations: description: Mitigation actions taken in response to abuse reports accounts: description: Account settings, members, roles, subscriptions, and API tokens for your Cloudflare account groups: applications: description: Applications operations categories: description: Categories operations organizations: description: Move accounts between organizations profile: description: View and manage the profile for a Cloudflare account roles: description: View the roles available for assigning to account members, each defining a set of permissions subscriptions: description: View and manage plan subscriptions attached to this account tokens: description: Create and manage scoped API tokens for programmatic access to the Cloudflare API ai-gateway: description: Proxy, cache, rate-limit, and observe requests to AI providers — OpenAI, Anthropic, Workers AI, and more groups: custom-domains: description: Manage custom hostnames that route requests through an AI Gateway custom-providers: description: Manage account-level custom AI providers and their endpoint settings datasets: description: 'Deprecated: manage filtered collections of gateway logs used by evaluations' dynamic-routing: description: Route requests across multiple AI providers with fallback, load-balancing, and versioned deployments dynamic-routing.deployments: description: Deploy dynamic route versions and view deployment history dynamic-routing.versions: description: Create and inspect saved versions of a dynamic route evaluation-types: description: 'Deprecated: list the evaluator types that evaluations can use' evaluations: description: 'Deprecated: score the logs in a dataset with selected evaluator types' gateways: description: Create and configure AI Gateways for an account gateways.providers: description: Store and rotate upstream AI provider keys for a gateway logs: description: Inspect, annotate, and delete gateway request logs stored by Legacy Logs ai-search: description: 'Managed search-as-a-service: crawl, index, and query content with AI-powered relevance and chat completions' groups: items: description: Content indexed by AI Search instances jobs: description: Indexing job lifecycle for AI Search instances namespace: description: Logical groupings for organizing AI Search instances tokens: description: Credentials used by AI Search instances ai-security: description: Detect prompt injection, PII, and unsafe topics in traffic to your AI applications groups: custom-topics: description: Organization-specific topic categories used by AI Security for Apps content detection analytics: description: Zone-level traffic analytics — dashboard summaries, per-colo breakdowns, and Argo latency metrics groups: colo: description: Per-data-center (colo) traffic analytics breakdown for the zone dashboard: description: Aggregated zone dashboard analytics — requests, bandwidth, threats, and page views latency: description: Argo Smart Routing latency analytics showing time-to-first-byte improvements argo: description: Network optimization features that speed up and improve reliability of traffic to your origins groups: smart-routing: description: Route traffic through the fastest network paths to your origin using real-time latency data tiered-caching: description: Reduce origin load by having upper-tier data centers serve cache misses before reaching your origin basin-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables billing: description: Account billing profiles and usage data for Cloudflare subscriptions and add-on services groups: profiles: description: Billing profile with payment method, address, and invoice preferences usage: description: Metered usage data for billed services — requests, bandwidth, and feature consumption botnet-feed: description: Botnet threat intelligence feeds — IP and ASN-level data on known command-and-control infrastructure groups: asn: description: ASN-level botnet activity data showing networks with known C2 infrastructure configs: description: Botnet feed subscription configuration and notification preferences builds: description: Build and deploy Workers from connected repositories, then inspect build status and logs. groups: deploy-hooks: description: Manage branch-specific HTTP hooks that start builds. limits: description: View build-minute availability and refresh information. logs: description: Retrieve build logs. repos: description: Manage source repository connections for Workers Builds. tokens: description: Manage credentials used by Workers Builds to deploy Workers. triggers: description: Configure how repository changes build and deploy Workers. versions: description: Find builds associated with Worker versions. workers: description: Manage repository-backed build configuration for Workers. cache: description: Purge cached content and configure Cache Reserve, tiered caching, and variant serving groups: origin-cloud-regions: description: Manage Origin Cloud Regions routing and failover configurations settings: description: Configure Cache Reserve, tiered caching, and variant serving settings.regional-tiered-cache: description: Restrict tiered cache topology to data centers within a specific geographic region settings.reserve: description: Persistent storage tier that keeps cached assets even after eviction from edge caches settings.smart-tiered-cache: description: Automatically determine the best upper-tier data centers for tiered cache topology settings.variants: description: Serve different cached versions of an image based on the Accept header (WebP, AVIF, etc.) client-side-security: description: Client-Side Security — monitor JavaScript, connections, and cookies on your pages for supply-chain attacks groups: connections: description: Third-party connections made by scripts on your pages — track data exfiltration risks cookies: description: Cookies set by your pages with classification and same-site attribute tracking policies: description: Content Security Policies that control which scripts and connections are allowed on your pages scripts: description: JavaScript files detected on your pages with change tracking and malicious code detection settings: description: Fine tune Client-Side Security behaviors cloud-connector: description: Route traffic from Cloudflare directly to cloud provider services (AWS, Azure, GCP) without origin servers groups: rules: description: Routing rules that map request patterns to cloud provider endpoints cloudforce-one: description: Detection rule management APIs groups: binary-storage: description: Upload and retrieve malware samples and suspicious binaries for analysis requests: description: Additional request operations — priority listing and asset creation rules: description: Rule management operations groups: approvals: description: Approval workflow operations email: description: Email rule operations exemptions: description: Exemption rule operations managed: description: Managed rule operations stats: description: Rule statistics operations tree: description: Rule navigation tree operations scans: description: Scan URLs, IPs, and domains for threat intelligence indicators containers: description: Deploy and manage Containers applications on Cloudflare's global network groups: applications: description: Manage Containers applications applications.instances: description: Inspect Containers instances belonging to applications applications.rollouts: description: Manage rollouts for scheduler-backed applications applications.versions: description: Inspect versions of scheduler-backed applications registries: description: Manage Containers image registries registries.credentials: description: Generate image registry credentials content-scan: description: Malicious uploads detection, scan uploaded content in HTTP requests for malware and malicious payloads groups: expressions: description: Custom expressions that tell the scanner how to reach content objects it cannot parse on its own custom-pages: description: Manage custom error and challenge pages and their assets for accounts and zones groups: account-custom-pages: description: Manage account-level custom pages account-custom-pages.preview-tokens: description: Preview tokens for account-level custom pages assets: description: Manage account- and zone-level custom assets zone-custom-pages: description: Manage zone-level custom pages zone-custom-pages.preview-tokens: description: Preview tokens for zone-level custom pages d1: description: D1 is Cloudflare's managed, serverless database with SQLite's SQL semantics, built-in disaster recovery, and Worker and HTTP API access. groups: time-travel: description: use specific point-in-time backups of your D1 database x-forge-epilogue: For more information about Time Travel, see https://developers.cloudflare.com/d1/reference/time-travel diagnostics: description: Network diagnostic tools — traceroutes from Cloudflare's edge and endpoint health checks groups: endpoint-healthchecks: description: Monitor external endpoint availability with periodic HTTP/HTTPS health checks traceroutes: description: Run traceroutes from Cloudflare data centers to diagnose network path issues email-routing: description: Route incoming email to verified destination addresses or Workers with routing rules, catch-all behavior, and managed DNS records groups: addresses: description: Verified destination email addresses that can receive forwarded mail dns: description: Inspect or unlock the DNS records required by Email Routing rules: description: Match incoming email addresses and forward messages to destination mailboxes or Workers settings: description: Inspect and update Email Routing settings email-security: description: Cloud email security — investigate threats, manage allow/block policies, and detect phishing groups: analytics: description: Analytics and reporting — monthly report and per-day breakdowns of threat activity bulk-actions: description: Asynchronous jobs that move or release every message matching a search — create, monitor, and manage bulk jobs investigate: description: Search and investigate email messages — view detections, traces, raw content, and take remediation actions phishguard: description: PhishGuard user-reported phishing reports — view detected threats for a date range settings: description: Email security configuration — block senders, allow policies, content policies, domains, trusted domains, impersonation registry, and URL handling submissions: description: Reclassify submissions — track user and team reports of false positives and missed detections email-sending: description: Send transactional email and manage sending subdomains and their DNS configuration groups: limits: description: Inspect account-level sending quotas and current usage subdomains: description: Configure sending subdomains and keep their DNS records healthy suppressions: description: Prevent delivery to suppressed addresses and manage the account suppression list filters: description: Filter expressions used by legacy firewall rules to match requests — prefer Rulesets for new configurations firewall: description: Legacy firewall rules, zone lockdowns, access rules, user-agent blocking, and WAF packages groups: access-rules: description: IP-based access rules that allow, block, challenge, or whitelist traffic globally or per-zone lockdowns: description: Zone lockdown rules that restrict access to URLs by IP address or range rules: description: Legacy firewall rules with filter expressions — prefer Rulesets for new configurations ua-rules: description: Block or challenge requests based on the User-Agent header string waf: description: Legacy WAF managed rule packages, rule groups, individual rules, and override configurations zone-access-rules: description: Zone-scoped IP access rules for blocking or allowing traffic google-tag-gateway: description: Google Tag Gateway operations groups: config: description: Google Tag Gateway config operations healthchecks: description: Standalone health checks that monitor origin server availability from Cloudflare's edge groups: previews: description: Test a health check configuration before deploying it to production hyperdrive: description: Accelerate access to existing databases by caching queries and pooling connections at the edge iam: description: Identity and access management — permission groups, resource groups, user groups, and SSO connectors groups: permission-groups: description: View the permission groups that can be assigned to API tokens and policies resource-groups: description: Define scopes that limit which account resources a policy or token can access sso: description: Configure single sign-on connectors to authenticate account members through an external identity provider user-groups: description: Organize account members into groups for easier permission assignment images: description: Store, resize, and deliver optimized images globally — variants, signing keys, and direct uploads groups: flows: description: Zone-level transformation flows that control how images are resized and optimized on delivery import: description: Import images from S3 keys: description: Manage signing keys for generating private image URLs variants: description: Manage named resize variants for transforming images on delivery intel: description: Threat intelligence lookups — IP reputation, domain info, ASN details, WHOIS, and indicator feeds groups: asn: description: ASN intelligence — ownership, geolocation, and subnet details for autonomous systems attack-surface-report: description: Attack surface intelligence — exposed assets, vulnerabilities, and infrastructure mapping dns: description: Passive DNS data showing historical DNS resolution records for domains domain-history: description: Historical domain registration and categorization changes over time domains: description: Domain intelligence — risk scores, categories, and associated infrastructure indicator-feeds: description: Threat indicator feeds — subscribe to and manage curated lists of malicious IPs, domains, and URLs ip-lists: description: Curated IP lists used for threat detection and policy enforcement ips: description: IP address intelligence — geolocation, risk assessment, and hosting provider details miscategorizations: description: Report and track domain miscategorization corrections whois: description: WHOIS registration data for domains including registrant, registrar, and nameservers k2: description: Durable, ordered event streams that you produce records to and consume from with subscriptions groups: streams: description: K2 streams, their retention, and the HTTP and Workers binding inputs used to produce records streams.subscriptions: description: Subscriptions that consume a K2 stream, with committed-position lag leaked-credential-checks: description: Detect compromised credentials in login requests by checking against known breach databases groups: detections: description: Custom detection locations that tell the WAF where to find usernames and passwords in requests load-balancers: description: Distribute traffic across origin pools with health monitoring, geo-steering, and failover groups: monitor-groups: description: Group monitors together for shared configuration and bulk management monitor-groups.references: description: List references to monitor groups used by load balancer pools monitors: description: Health check configurations that probe origin servers and determine pool availability monitors.previews: description: Health check configurations that probe origin servers and determine pool availability monitors.references: description: Health check configurations that probe origin servers and determine pool availability pools: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.health: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.references: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences previews: description: Preview the result of a health check monitor configuration before applying it regions: description: Geographic regions used for regional pool steering and traffic policies searches: description: Search across all load balancer resources (pools, monitors, load balancers) by name or reference logs: description: Log control, retention, and raw log access — CMB config, ray ID lookups, and received fields groups: control: description: Log control operations received: description: Received log operations magic-network-monitoring: description: Flow-based network traffic monitoring with configurable alerting rules and VPC flow ingestion groups: configs: description: Account-level monitoring configuration — sampling rates, thresholds, and notification settings rules: description: Monitoring rules that define traffic thresholds and trigger alerts or prefix advertisements vpc-flows: description: Ingest VPC flow logs from cloud providers for network visibility and anomaly detection magic-transit: description: DDoS-protected network transit — GRE/IPsec tunnels, static routes, Magic WAN sites, connectors, and packet captures groups: advanced-dns-protection: description: Advanced Dns Protection operations advanced-tcp-protection: description: Advanced Tcp Protection operations apps: description: Application-aware traffic policies for Magic WAN that steer traffic by app type bgp-filter-profiles: description: BGP filter profiles for controlling which routes are allowed or denied on Magic Transit tunnels bgp-settings: description: BGP settings for controlling default ASN and route redistribution on Magic Transit tunnels cf-interconnects: description: Cloudflare Network Interconnect (CNI) links for direct physical or virtual peering gre-tunnels: description: GRE tunnel endpoints that connect your network to Cloudflare for Magic Transit ipsec-tunnels: description: IPsec tunnel endpoints with pre-shared key management for encrypted transit pcaps: description: Packet capture requests for debugging traffic flowing through Magic Transit tunnels routes: description: Static routes that direct IP prefix traffic through specific GRE/IPsec tunnels sites: description: Magic WAN branch sites — base CRUD, LAN/WAN interface configuration, ACLs, connectors, app configuration, and NetFlow config mcp: description: Manage MCP portals and upstream MCP servers for Cloudflare Access AI controls groups: portals: description: Manage MCP portals, attached servers, and Code Mode settings servers: description: Manage upstream MCP servers, credentials, capabilities, and sync state network-interconnects: description: Physical and virtual private interconnects between your infrastructure and Cloudflare's network groups: cnis: description: Cloud Network Interconnect (CNI) connections — private links from cloud providers to Cloudflare interconnects: description: Physical cross-connect and partner interconnect sessions with LOA and status tracking settings: description: Account-level interconnect settings and default configurations slots: description: Available interconnect facility slots showing port capacity at Cloudflare data centers organizations: description: Multi-user organizations that group accounts, members, and shared settings under a single entity groups: account-organizations: description: List organizations associated with a specific account accounts: description: Accounts operations members: description: Members operations members-batch-create: description: Members Batch Create operations organization-profile: description: View and update the public profile information for an organization shares: description: Shares operations origin-post-quantum-encryption: description: Enable post-quantum key exchange for connections between Cloudflare and your origin server pages: description: Full-stack application hosting with Git-integrated builds, preview deployments, and custom domains groups: projects: description: Pages projects, deployments, build logs, and custom domain bindings pipelines: description: Ingest, transform, and route event streams into R2, analytics, or other destinations in real time groups: sinks: description: Destinations where pipeline data is written — R2 buckets, HTTP endpoints, or other storage streams: description: Inbound data streams that feed events into a pipeline for processing precursor: description: Precursor settings for a zone queues: description: Reliable message queuing between Workers — produce, consume, and batch-process messages at scale groups: consumers: description: Workers that automatically receive and process messages from a queue messages: description: Push messages to a queue and pull or acknowledge them from consumers purge: description: Remove all pending messages from a queue subscriptions: description: Manage queue subscriptions for event-driven message routing r2: description: S3-compatible object storage with zero egress fees — buckets, lifecycle rules, event notifications, and data migration groups: buckets: description: Create and configure R2 buckets including CORS, lifecycle, custom domains, event notifications, and object locks buckets.jobs: description: Create and inspect background jobs for an R2 bucket buckets.local-uploads: description: R2 bucket local upload configuration super-slurper: description: Migrate data from external S3-compatible storage into R2 buckets with resumable transfer jobs temporary-credentials: description: Generate short-lived S3-compatible credentials scoped to specific buckets and operations r2-data-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables radar: description: Internet-wide traffic intelligence — BGP, DNS, HTTP trends, attack data, and network quality insights groups: agent-readiness: description: Agent readiness summary statistics across the Cloudflare network ai: description: AI inference trends and model usage statistics across the Cloudflare network annotations: description: Radar annotations marking significant Internet events (outages, cable cuts, etc.) as112: description: AS112 DNS sinkhole statistics — reverse DNS query volumes for private address space attacks: description: DDoS and application-layer attack trends, vectors, and target analysis bgp: description: BGP routing data — prefix announcements, AS-level stats, route leaks, and hijack events bots: description: Internet-wide bot traffic trends, categories, and distribution statistics ct: description: Certificate Transparency log monitoring and newly-issued certificate discovery datasets: description: Downloadable Radar datasets for offline analysis and research dns: description: Global DNS query trends — top domains, resolver stats, and DNSSEC adoption email: description: Email security trends — DMARC/SPF/DKIM adoption, spam, and phishing statistics entities: description: Look up ASNs, IPs, domains, and locations with metadata and traffic summaries geolocations: description: Geographic location metadata used for regional traffic analysis http: description: HTTP protocol trends — TLS versions, HTTP versions, browser share, and OS distribution leaked-credentials: description: Leaked credential detection trends and exposure statistics netflows: description: Network-layer traffic flow data and volumetric trend analysis origins: description: Cloud and hosting origin providers (e.g. Amazon, by region) and their traffic metrics post-quantum: description: Post-quantum encryption adoption and deployment trends across the Internet quality: description: Internet connection quality metrics — speed, latency, and jitter by geography and ASN ranking: description: Top domain rankings based on DNS query popularity across the Cloudflare network robots-txt: description: Robots.txt adoption and crawler directive trends across the web search: description: Search Radar data across IPs, ASNs, domains, and locations tcp-resets-timeouts: description: TCP connection reset and timeout statistics indicating network health issues tlds: description: Top-level domain (TLD) metadata and performance trends traffic-anomalies: description: Detected traffic anomalies and unusual patterns in Internet traffic flows verified-bots: description: Catalog of known good bots (Googlebot, Bingbot, etc.) and their traffic patterns rate-limits: description: Legacy per-zone rate limiting rules — prefer Advanced Rate Limiting in Rulesets for new configurations realtime: description: Real-time audio, video, and data services on Cloudflare's global network groups: kit: description: SDK-backed meetings, participants, recordings, livestreams, and webhooks kit.analytics: description: Usage and livestream analytics for RealtimeKit applications kit.analytics.livestreams: description: Livestream analytics for RealtimeKit applications kit.analytics.livestreams.daily: description: Daily livestream analytics for RealtimeKit applications kit.analytics.usage: description: Usage analytics for RealtimeKit applications kit.apps: description: RealtimeKit applications that group meetings, sessions, and configuration kit.livestreams: description: Independent and meeting-based livestreams and their sessions kit.livestreams.sessions: description: Sessions for RealtimeKit livestreams kit.meetings: description: Meetings, participants, access tokens, and meeting livestreams kit.meetings.active: description: Live meeting state and participant controls kit.meetings.active.polls: description: Polls for active meeting sessions kit.meetings.livestream: description: Livestream operations associated with RealtimeKit meetings kit.meetings.participants: description: Participants in RealtimeKit meetings kit.meetings.participants.tokens: description: Access tokens for RealtimeKit meeting participants kit.presets: description: Reusable meeting configuration for media, permissions, and interface behavior kit.recordings: description: Meeting and participant-track recordings and recording controls kit.recordings.active: description: Active recordings for RealtimeKit meetings kit.recordings.tracks: description: Participant-track recordings for RealtimeKit meetings kit.sessions: description: Historical session data, participants, chat, transcripts, and summaries kit.sessions.chat: description: Chat messages from historical RealtimeKit sessions kit.sessions.livestreams: description: Livestreams associated with historical RealtimeKit sessions kit.sessions.participants: description: Participants in historical RealtimeKit sessions kit.sessions.peers: description: Peer details from historical RealtimeKit sessions kit.sessions.summaries: description: Summaries of historical RealtimeKit sessions kit.sessions.transcripts: description: Transcripts from historical RealtimeKit sessions kit.webhooks: description: Webhook endpoints and supported events for RealtimeKit notifications kit.webhooks.events: description: Supported events for RealtimeKit webhooks moq: description: MoQ relays for publishing and subscribing to media streams moq.relays: description: Relays are isolated MoQ scopes that carry media between publishers and subscribers moq.relays.tokens: description: Tokens that authorize publishers and subscribers to connect to a relay sfu: description: SFU apps that route WebRTC media and data between participants sfu.apps: description: SFU application namespaces for sessions and tracks turn: description: TURN keys that help clients traverse NATs and firewalls turn.keys: description: Keys used to generate short-lived TURN credentials request-tracers: description: Trace how a request would be processed through Cloudflare's rules and configuration pipeline groups: traces: description: Simulate request processing to debug rule matches, transforms, and routing decisions resource-sharing: description: Share Cloudflare resources (zones, accounts) across organizations with granular access controls groups: recipients: description: Update share recipients resources: description: Individual resources (zones, configs) that have been shared with recipients rules: description: Resources used by Cloudflare rules and rulesets groups: lists: description: Custom account-level lists of IPs, hostnames, ASNs, or redirects used in rule expressions rum: description: Real User Measurement (Web Analytics) — track page loads, Core Web Vitals, and visitor metrics groups: rules: description: Rules that control which pages and paths are tracked by Web Analytics site-info: description: Web Analytics sites — register domains and get the JavaScript beacon snippet scim: description: SCIM 2.0 provisioning — manage users, groups, and identity provider sync for your account groups: groups: description: Groups operations resource-types: description: Resource Types operations schemas: description: Schemas operations service-provider-config: description: Service Provider Config operations users: description: Users operations secrets-store: description: Centralized secret management — store API keys, tokens, and credentials for use across Workers and other products groups: quota: description: Account quota limits for secrets stores, secrets count, and storage capacity secrets: description: Encrypted key-value secrets within a store. Pass --store-id to scope. stores: description: Secret stores that hold encrypted key-value secrets accessible by Workers and services security-center: description: Security posture dashboard — view and manage security insights, misconfigurations, and vulnerabilities groups: insights: description: Security findings and recommendations across your account — DNS, SSL, WAF misconfigurations, etc. zone-insights: description: Zone-scoped security insights — counts by class, severity, type, and dismissal security-txt: description: Manage the /.well-known/security.txt file that tells security researchers how to report vulnerabilities smart-shield: description: Smart Shield settings, health checks, and cache reserve management groups: cache-reserve-clear: description: Cache Reserve Clear operations health-checks: description: Health checks operations spectrum: description: Proxy and protect arbitrary TCP/UDP applications through Cloudflare's network with DDoS mitigation groups: analytics: description: Real-time and historical connection analytics for Spectrum applications apps: description: Spectrum application configurations that map protocols and ports to origin servers speed: description: Observatory speed tests — run Lighthouse audits, track performance trends, and schedule recurring tests groups: availabilities: description: Check which speed test regions and configurations are available for your zone pages: description: Tested pages with their performance history, trends, and individual test results schedule: description: Scheduled recurring speed tests that automatically run at regular intervals ssl: description: SSL/TLS certificate management — certificate packs, Universal SSL, verification, and TLS mode recommendations groups: automatic-upgrader: description: SSL automatic mode enrollment — get or update automatic SSL/TLS upgrader settings recommendations: description: Get the recommended SSL/TLS encryption mode based on your origin server's certificate configuration stream: description: Video encoding, storage, and delivery — upload, live-stream, clip, caption, and embed video at scale groups: audio-tracks: description: Add, edit, or remove additional audio tracks on a video captions: description: Upload, generate, or retrieve captions and subtitles for videos in multiple languages clip: description: Create a new video clip from an existing video by specifying start and end times copy: description: Import a video from a URL into Stream for processing and delivery direct-upload: description: Generate a tokenized URL that lets end-users upload video directly to Stream downloads: description: Create downloadable MP4 renditions of a video for offline viewing embed: description: Retrieve the HTML embed code snippet for a video keys: description: Signing keys used to generate short-lived signed URLs for private video playback live-inputs: description: Enable and disable live input streams token: description: Generate short-lived signed URL tokens for secure private video playback typed-downloads: description: Type-specific stream download creation and deletion videos: description: Aggregate video storage usage statistics for the account watermarks: description: Watermark profiles that overlay an image on every video in the account webhooks: description: Webhook notifications for video lifecycle events (ready, error, etc.) tenants: description: Multi-tenant account management — manage tenant accounts, entitlements, and memberships groups: account-types: description: Account Types operations accounts: description: Accounts operations entitlements: description: Entitlements operations memberships: description: Memberships operations turnstile: description: CAPTCHA-free bot verification widgets that protect forms and APIs without degrading user experience groups: widgets: description: Turnstile widget configurations — site keys, secret rotation, and challenge mode settings url-scanner: description: Scan URLs for phishing, malware, and other threats — submit scans and retrieve detailed results groups: response: description: Response operations responses: description: Raw HTTP response data captured during URL scans scan: description: Scan operations scans: description: URL scan requests and results — submit URLs for analysis and retrieve threat verdicts user: description: Your Cloudflare user profile, invitations, organizations, billing, and personal API tokens groups: billing: description: View billing history and payment profile for your user (deprecated — prefer account-level billing) firewall: description: Firewall operations load-balancers.monitors: description: Load Balancers operations load-balancers.monitors.preview: description: Load Balancers operations load-balancers.monitors.references: description: Load Balancers operations load-balancers.pools: description: Load Balancers operations load-balancers.pools.edit.pools: description: Load Balancers operations load-balancers.pools.health: description: Load Balancers operations load-balancers.pools.preview: description: Load Balancers operations load-balancers.pools.references: description: Load Balancers operations load-balancers.preview: description: Load Balancers operations load-balancing-analytics.events: description: Load Balancing Analytics operations subscriptions: description: View and manage zone-level plan subscriptions owned by your user tenants: description: Tenants operations tokens: description: Create and manage personal API tokens scoped to your user for programmatic API access user.analytics: description: User-level traffic analytics — aggregated totals and timeseries across all zones vectorize: description: Globally distributed vector database for building semantic search, recommendations, and RAG applications on Workers groups: deprecated-indexes: description: Deprecated v1 Vectorize index operations metadata-index: description: Metadata indexes for filtered vector search waiting-rooms: description: Virtual queues that throttle traffic to your site during peak demand with customizable waiting pages groups: account-waiting-rooms: description: Account-scoped waiting room listing events: description: Scheduled events that temporarily override waiting room settings for sales, launches, etc. page: description: Custom HTML waiting page templates and preview rendering rules: description: Rules that bypass or modify waiting room behavior for specific request patterns settings: description: Zone-level waiting room defaults and cookie configuration statuses: description: Real-time queue status showing active users, queued users, and estimated wait times workflows: description: Durable, multi-step workflows that run on Workers with automatic retries and state persistence groups: instances: description: Workflow instance operations versions: description: Workflow version operations zaraz: description: Server-side tag manager — load third-party tools (analytics, pixels, etc.) from Cloudflare's edge without client-side JS groups: config: description: Full Zaraz configuration including tools, triggers, and variables for the zone default: description: Default Zaraz configuration template used as a starting point for new zones export: description: Export the current Zaraz configuration as a portable JSON document history: description: Configuration version history — browse and restore previous Zaraz configurations publish: description: Publish pending Zaraz configuration changes to make them live on the zone workflow: description: Workflow state for Zaraz configuration changes (draft vs. published) zero-trust: description: Cloudflare's SASE platform — secure access, device posture, DLP, tunnels, gateway policies, and network segmentation groups: dex: description: Digital Experience Monitoring — synthetic tests, fleet-wide device metrics, and network path diagnostics dlp.custom-prompt-topics: description: Data Loss Prevention - manage custom prompt topics for AI-based content detection dlp.data-classes: description: Data Loss Prevention - manage data classes used to classify sensitive information dlp.data-tag-categories: description: Data Loss Prevention - manage categories that organize data tags dlp.data-tag-category-templates: description: Data Loss Prevention - browse templates for creating data tag categories dlp.data-tags: description: Data Loss Prevention - manage tags used to classify and organize sensitive data dlp.datasets: description: Data Loss Prevention - manage datasets, versions, and uploads dlp.document-fingerprints: description: Data Loss Prevention - manage document fingerprints for detecting matching documents dlp.email.account-mapping: description: Data Loss Prevention - configure account mappings for outbound email scanning dlp.email.rules: description: Data Loss Prevention - manage outbound email scanning rules and their priorities dlp.entries: description: Data Loss Prevention - list and manage detection entries dlp.limits: description: Data Loss Prevention - view account limits and resource quotas dlp.patterns: description: Data Loss Prevention - validate regular expressions used for content detection dlp.profiles: description: Data Loss Prevention - list and retrieve profiles dlp.profiles.custom: description: Data Loss Prevention - manage custom profiles dlp.profiles.predefined: description: Data Loss Prevention - manage predefined profiles dlp.sensitivity-group-templates: description: Data Loss Prevention - browse templates for creating sensitivity groups dlp.sensitivity-groups: description: Data Loss Prevention - manage sensitivity groups and their level ordering dlp.sensitivity-levels: description: Data Loss Prevention - manage sensitivity levels within sensitivity groups dlp.settings: description: Data Loss Prevention - manage account-level settings dlp.validators: description: Data Loss Prevention - list and retrieve content validators dlp.validators.proximity-words: description: Data Loss Prevention - manage proximity-word validators risk-scoring: description: User Risk Scoring - retrieve and reset user risk scores risk-scoring.behaviours: description: User Risk Scoring - manage behaviors used to calculate user risk scores risk-scoring.integrations: description: User Risk Scoring - manage integrations that provide risk score signals risk-scoring.integrations.references: description: User Risk Scoring - retrieve integrations by external reference risk-scoring.summary: description: User Risk Scoring - retrieve account risk score summaries zones: description: Zones are domains on Cloudflare — list, create, and configure domain settings groups: aegis: description: Aegis operations fonts: description: Fonts operations origin-h2-max-streams: description: Origin H2 Max Streams operations origin-max-http-version: description: Origin Max Http Version operations origin-tls-compliance-modes: description: Manage zone Origin TLS Compliance Modes setting rum: description: Rum operations speed-brain: description: Speed Brain operations