openapi: 3.2.0 info: description: Welcome to Cloudflare's API documentation site. license: name: BSD-3-Clause url: https://opensource.org/licenses/BSD-3-Clause title: Cloudflare Rules API version: 4.0.0 servers: - description: Client API url: https://api.cloudflare.com/client/v4 security: - api_email: [] api_key: [] - api_token: [] - user_service_key: [] tags: - name: Rules paths: /accounts/{account_id}/cloudforce-one/rules: delete: operationId: cloudforce-one-delete-all-rules summary: Delete all rules description: Delete all rules in an account. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' responses: '200': description: All rules deleted. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_DeleteAllResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '409': description: Bulk delete blocked because email rules require individual approval. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules x-fern-sdk-method-name: deleteAll get: operationId: cloudforce-one-list-rules summary: List rules description: Returns all rules for an account with optional filtering. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: namespace in: query description: Selects namespaces. Repeat the parameter to select multiple namespaces (for example, namespace=foo&namespace=bar). schema: description: Selects namespaces. Repeat the parameter to select multiple namespaces (for example, namespace=foo&namespace=bar). example: - yara/workers - yara/dns_record anyOf: - type: string - items: type: string maxItems: 50 type: array - name: path in: query description: Selects paths with exact-match semantics. Omit the parameter to return rules from all paths. Pass an empty string (path=) to return only rules with an empty or uncategorized path. Pass a value (for example, path=yara) to match that exact path. Repeat the parameter (for example, path=yara&path=expr) to OR-match multiple paths with SQL `IN (...)` semantics. The `recursive` flag affects only customer-account namespace selection. schema: description: Selects paths with exact-match semantics. Omit the parameter to return rules from all paths. Pass an empty string (path=) to return only rules with an empty or uncategorized path. Pass a value (for example, path=yara) to match that exact path. Repeat the parameter (for example, path=yara&path=expr) to OR-match multiple paths with SQL `IN (...)` semantics. The `recursive` flag affects only customer-account namespace selection. example: - yara/workers anyOf: - type: string - items: type: string maxItems: 50 type: array - name: recursive in: query description: For customer accounts, true enables descendant matching for namespaces. Paths always use exact matching. schema: description: For customer accounts, true enables descendant matching for namespaces. Paths always use exact matching. type: string example: 'true' enum: - 'true' - 'false' - name: search in: query schema: type: string example: malicious - name: is_public in: query description: Limits rules to the specified public visibility. schema: description: Limits rules to the specified public visibility. type: string example: 'true' enum: - 'true' - 'false' - name: limit in: query schema: type: number example: 50 default: 50 maximum: 100 minimum: 1 - name: offset in: query schema: type: - number - 'null' example: 0 default: 0 minimum: 0 responses: '200': description: List of rules. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_RulesPreviewListResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules x-fern-sdk-method-name: list post: operationId: cloudforce-one-create-rule summary: Create a rule description: Create a new detection rule. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' requestBody: content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_CreateRule' responses: '201': description: Rule created (non-email customer accounts, or silent warning-free customer email rules). content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_Rule' '202': description: Rule pending approval (internal accounts, blocking customer email rules, and customer email rules with compiler warnings). content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ApprovalPendingResponse' '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules x-fern-sdk-method-name: create /accounts/{account_id}/cloudforce-one/rules/exemptions: delete: operationId: cloudforce-one-remove-account-exemptions summary: Remove patterns from exemption rules description: Remove regex patterns from per-account exemption rules. Missing keys leave that type untouched; non-existent patterns are silently skipped. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' requestBody: content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_PartialAccountExemptions' responses: '200': description: Full exemption state after the subtraction. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_AccountExemptions' '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '403': description: Forbidden. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.exemptions x-fern-sdk-method-name: delete get: operationId: cloudforce-one-get-exemptions summary: Get exemption rules for an account description: Get all exemption rule patterns for the account, grouped by type. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' responses: '200': description: Exemption rules grouped by type. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_AccountExemptions' '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '403': description: Forbidden. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.exemptions x-fern-sdk-method-name: get post: operationId: cloudforce-one-add-account-exemptions summary: Add patterns to exemption rules description: Add regex patterns to per-account exemption rules (union semantics). Missing keys leave that type untouched; duplicates are silently deduped. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' requestBody: content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_PartialAccountExemptions' responses: '200': description: Full exemption state after the union. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_AccountExemptions' '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '403': description: Forbidden. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.exemptions x-fern-sdk-method-name: create put: operationId: cloudforce-one-update-account-exemptions summary: Update exemption rule patterns description: Replace existing exemption patterns with new values. Each key maps to an array of {old_pattern, new_pattern} entries. Missing keys leave that type untouched. Fails if any old pattern is not found or any new pattern already exists. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' requestBody: content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_UpdateAccountExemptionsBody' responses: '200': description: Full exemption state after the updates. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_AccountExemptions' '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '403': description: Forbidden. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '404': description: Pattern not found. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '409': description: New pattern already exists. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.exemptions x-fern-sdk-method-name: update /accounts/{account_id}/cloudforce-one/rules/managed: get: operationId: cloudforce-one-get-managed-rules summary: Get managed rules description: Get DFP managed rule metadata (name and description) from YARA rules. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' responses: '200': description: Managed rules metadata. content: application/json: schema: type: object properties: metadata: type: object properties: fetched_at: type: string total_rules: type: number required: - total_rules - fetched_at rules: type: array items: properties: description: type: string name: type: string required: - name - description type: object required: - rules - metadata '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.managed x-fern-sdk-method-name: get /accounts/{account_id}/cloudforce-one/rules/search: get: operationId: cloudforce-one-search-rules summary: Search rules description: Search rules using hybrid, vector, keyword, or exact retrieval, backed by AI Search with a SQL fallback. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: namespace in: query description: Selects namespaces. Repeat the parameter to select multiple namespaces (for example, namespace=foo&namespace=bar). schema: description: Selects namespaces. Repeat the parameter to select multiple namespaces (for example, namespace=foo&namespace=bar). example: - yara/workers - yara/dns_record anyOf: - type: string - items: type: string maxItems: 50 type: array - name: path in: query description: Selects paths with exact-match semantics. Omit the parameter to return rules from all paths. Pass an empty string (path=) to return only rules with an empty or uncategorized path. Pass a value (for example, path=yara) to match that exact path. Repeat the parameter (for example, path=yara&path=expr) to OR-match multiple paths with SQL `IN (...)` semantics. The `recursive` flag affects only customer-account namespace selection. schema: description: Selects paths with exact-match semantics. Omit the parameter to return rules from all paths. Pass an empty string (path=) to return only rules with an empty or uncategorized path. Pass a value (for example, path=yara) to match that exact path. Repeat the parameter (for example, path=yara&path=expr) to OR-match multiple paths with SQL `IN (...)` semantics. The `recursive` flag affects only customer-account namespace selection. example: - yara/workers anyOf: - type: string - items: type: string maxItems: 50 type: array - name: recursive in: query description: For customer accounts, true enables descendant matching for namespaces. Paths always use exact matching. schema: description: For customer accounts, true enables descendant matching for namespaces. Paths always use exact matching. type: string example: 'true' enum: - 'true' - 'false' - name: search in: query schema: type: string example: malicious - name: is_public in: query description: Limits rules to the specified public visibility. schema: description: Limits rules to the specified public visibility. type: string example: 'true' enum: - 'true' - 'false' - name: limit in: query schema: type: number example: 50 default: 50 maximum: 100 minimum: 1 - name: offset in: query schema: type: - number - 'null' example: 0 default: 0 minimum: 0 - name: query in: query description: Natural-language or keyword search query. required: true schema: description: Natural-language or keyword search query. type: string example: obfuscated proxy worker maxLength: 500 minLength: 1 - name: mode in: query description: Retrieval strategy used for the query. schema: description: Retrieval strategy used for the query. type: string example: hybrid default: hybrid enum: - exact - hybrid - vector - keyword x-fern-parameter-name: search-mode - name: language in: query description: Limits results to the specified rule language. schema: description: Limits results to the specified rule language. type: string example: yara enum: - yara - js responses: '200': description: Hybrid and semantic rule search results. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_RulesSearchResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '503': description: AI Search unavailable. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules x-fern-sdk-method-name: search /accounts/{account_id}/cloudforce-one/rules/stats: get: operationId: cloudforce-one-get-rule-stats summary: Get dashboard stats description: Get statistics about rules for the dashboard. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' responses: '200': description: Dashboard statistics. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_StatsResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.stats x-fern-sdk-method-name: get /accounts/{account_id}/cloudforce-one/rules/structured: get: operationId: cloudforce-one-list-email-rules summary: List email rules description: Returns structured email rules. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: limit in: query schema: type: number default: 50 maximum: 100 minimum: 1 - name: offset in: query schema: type: - number - 'null' default: 0 minimum: 0 - name: search in: query schema: type: string responses: '200': description: List of rules. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_EmailRulesListResponse' '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.email x-fern-sdk-method-name: list post: operationId: cloudforce-one-create-email-rule summary: Create an email rule description: Create a structured email rule. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' requestBody: content: application/json: schema: type: object properties: condition: $ref: '#/components/schemas/cloudforce-one_EmailRuleConditionGroup' description: type: string maxLength: 1000 enabled: type: boolean default: true meta: type: array items: $ref: '#/components/schemas/cloudforce-one_MetaInputEntry' maxItems: 50 name: type: string maxLength: 255 minLength: 1 status: description: Disposition for matching email. This emits status metadata with the selected value. type: string default: silent enum: - silent - blocking strings: type: array items: properties: identifier: type: string maxLength: 128 minLength: 1 pattern: ^[a-zA-Z_][a-zA-Z0-9_]*$ match_type: type: string default: text enum: - text - hex - regex modifiers: type: array items: enum: - nocase - wide - ascii - fullword type: string default: [] type: type: string enum: - string_match value: type: string maxLength: 10000 minLength: 1 required: - type - identifier - value type: object default: [] maxItems: 50 required: - name - condition responses: '201': description: Email rule created immediately when submitted by a customer with silent status and no compiler warnings. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_RulePreview' '202': description: Rule pending approval (internal accounts, blocking customer rules, and customer rules with compiler warnings). content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ApprovalPendingResponse' '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.email x-fern-sdk-method-name: create /accounts/{account_id}/cloudforce-one/rules/structured/approvals/{id}: put: operationId: cloudforce-one-update-pending-email-rule-approval summary: Update a pending structured email rule approval description: Validate, compile, and replace the proposed structured email rule on a pending approval. Only the original requester may update it. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: id in: path description: The unique identifier for the approval. required: true schema: description: The unique identifier for the approval. type: string example: '1' - name: module in: query description: Structured rule module. schema: description: Structured rule module. type: string example: eml default: eml enum: - eml requestBody: content: application/json: schema: type: object properties: condition: $ref: '#/components/schemas/cloudforce-one_EmailRuleConditionGroup' description: type: string maxLength: 1000 enabled: type: boolean default: true meta: type: array items: $ref: '#/components/schemas/cloudforce-one_MetaInputEntry' maxItems: 50 name: type: string maxLength: 255 minLength: 1 status: description: Disposition for matching email. This emits status metadata with the selected value. type: string default: silent enum: - silent - blocking strings: type: array items: properties: identifier: type: string maxLength: 128 minLength: 1 pattern: ^[a-zA-Z_][a-zA-Z0-9_]*$ match_type: type: string default: text enum: - text - hex - regex modifiers: type: array items: enum: - nocase - wide - ascii - fullword type: string default: [] type: type: string enum: - string_match value: type: string maxLength: 10000 minLength: 1 required: - type - identifier - value type: object default: [] maxItems: 50 required: - name - condition responses: '200': description: Pending approval updated. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_EditApprovalResponse' '400': description: Structured rule validation or compilation failed. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '403': description: Not authorized to update this approval. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '404': description: Approval not found. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '409': description: Approval is not pending or is not a structured EML rule. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.email x-fern-sdk-method-name: updatePendingApproval x-forge-hidden: true /accounts/{account_id}/cloudforce-one/rules/structured/approvals/{id}/resubmit: post: operationId: cloudforce-one-resubmit-email-rule-approval summary: Revise and resubmit a rejected structured email rule approval description: Validates and compiles a complete structured email rule, then creates an immutable pending revision of its rejected approval. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: id in: path description: The unique identifier for the approval. required: true schema: description: The unique identifier for the approval. type: string example: '1' - name: module in: query description: Structured rule module. schema: description: Structured rule module. type: string example: eml default: eml enum: - eml requestBody: content: application/json: schema: type: object properties: condition: $ref: '#/components/schemas/cloudforce-one_EmailRuleConditionGroup' description: type: string maxLength: 1000 enabled: type: boolean default: true meta: type: array items: $ref: '#/components/schemas/cloudforce-one_MetaInputEntry' maxItems: 50 name: type: string maxLength: 255 minLength: 1 status: description: Disposition for matching email. This emits status metadata with the selected value. type: string default: silent enum: - silent - blocking strings: type: array items: properties: identifier: type: string maxLength: 128 minLength: 1 pattern: ^[a-zA-Z_][a-zA-Z0-9_]*$ match_type: type: string default: text enum: - text - hex - regex modifiers: type: array items: enum: - nocase - wide - ascii - fullword type: string default: [] type: type: string enum: - string_match value: type: string maxLength: 10000 minLength: 1 required: - type - identifier - value type: object default: [] maxItems: 50 required: - name - condition responses: '202': description: New approval revision submitted. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ResubmitApprovalResponse' '400': description: Structured rule validation or compilation failed. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '403': description: Not authorized to resubmit this approval. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '404': description: Approval or underlying rule not found. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '409': description: Approval is not rejected or was already superseded. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.email.approvals x-fern-sdk-method-name: resubmit x-forge-hidden: true /accounts/{account_id}/cloudforce-one/rules/structured/schema: get: operationId: cloudforce-one-get-email-rule-schema summary: Get email rule schema description: Get the field catalog for structured email rules. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' responses: '200': description: Email rule field catalog. content: application/json: schema: type: object properties: arrays: type: array items: properties: counter: type: string fields: type: array items: properties: name: type: string type: type: string enum: - string - integer - float - boolean required: - name - type type: object path: type: string required: - path - counter - fields type: object headers: type: object properties: fields: type: array items: properties: name: type: string type: type: string enum: - string - integer - float - boolean required: - name - type type: object path: type: string required: - path - fields operators: type: object properties: boolean: type: array items: type: string float: type: array items: type: string integer: type: array items: type: string string: type: array items: type: string required: - string - integer - float - boolean scalars: type: array items: properties: path: type: string type: type: string enum: - string - integer - float - boolean required: - path - type type: object string_arrays: type: array items: properties: counter: type: string path: type: string required: - path - counter type: object structs: type: array items: properties: fields: type: array items: properties: name: type: string type: type: string enum: - string - integer - float - boolean required: - name - type type: object path: type: string required: - path - fields type: object required: - scalars - structs - arrays - string_arrays - headers - operators '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.email.schema x-fern-sdk-method-name: get x-forge-hidden: true /accounts/{account_id}/cloudforce-one/rules/structured/validate: post: operationId: cloudforce-one-validate-email-rule summary: Validate an email rule description: Validates structured email rule syntax and metadata. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' requestBody: content: application/json: schema: type: object properties: condition: $ref: '#/components/schemas/cloudforce-one_EmailRuleConditionGroup' description: type: string maxLength: 1000 enabled: type: boolean default: true existing_rule_id: description: Existing rule ID to exclude from duplicate-name checks when validating an update. type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 meta: type: array items: $ref: '#/components/schemas/cloudforce-one_MetaInputEntry' maxItems: 50 name: type: string maxLength: 255 minLength: 1 status: description: Disposition for matching email. This emits status metadata with the selected value. type: string default: silent enum: - silent - blocking strings: type: array items: properties: identifier: type: string maxLength: 128 minLength: 1 pattern: ^[a-zA-Z_][a-zA-Z0-9_]*$ match_type: type: string default: text enum: - text - hex - regex modifiers: type: array items: enum: - nocase - wide - ascii - fullword type: string default: [] type: type: string enum: - string_match value: type: string maxLength: 10000 minLength: 1 required: - type - identifier - value type: object default: [] maxItems: 50 required: - name - condition responses: '200': description: Validation result. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_EmailRuleValidationResponse' '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.email x-fern-sdk-method-name: validate /accounts/{account_id}/cloudforce-one/rules/structured/{id}: delete: operationId: cloudforce-one-delete-email-rule summary: Delete an email rule description: Delete an existing structured email rule. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: id in: path description: The unique identifier for the rule. required: true schema: description: The unique identifier for the rule. type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 responses: '200': description: Email rule deleted. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_SuccessResponse' '202': description: Deletion pending approval (internal accounts and customer email rules). content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ApprovalPendingResponse' '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '404': description: Rule not found. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '409': description: Another approval is already pending for this rule. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ApprovalConflictResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.email x-fern-sdk-method-name: delete get: operationId: cloudforce-one-get-email-rule summary: Get an email rule description: Get a structured email rule by ID. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: id in: path description: The unique identifier for the rule. required: true schema: description: The unique identifier for the rule. type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 responses: '200': description: Rule details. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_RulePreview' '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '404': description: Rule not found. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.email x-fern-sdk-method-name: get put: operationId: cloudforce-one-update-email-rule summary: Update an email rule description: Updates an existing structured email rule. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: id in: path description: The unique identifier for the rule. required: true schema: description: The unique identifier for the rule. type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 requestBody: content: application/json: schema: type: object properties: condition: $ref: '#/components/schemas/cloudforce-one_EmailRuleConditionGroup' description: type: string maxLength: 1000 enabled: type: boolean meta: type: array items: $ref: '#/components/schemas/cloudforce-one_MetaInputEntry' maxItems: 50 name: type: string maxLength: 255 minLength: 1 status: description: Disposition for matching email. This emits status metadata with the selected value. type: string enum: - silent - blocking strings: type: array items: properties: identifier: type: string maxLength: 128 minLength: 1 pattern: ^[a-zA-Z_][a-zA-Z0-9_]*$ match_type: type: string default: text enum: - text - hex - regex modifiers: type: array items: enum: - nocase - wide - ascii - fullword type: string default: [] type: type: string enum: - string_match value: type: string maxLength: 10000 minLength: 1 required: - type - identifier - value type: object maxItems: 50 responses: '200': description: Rule updated immediately when submitted by a customer with silent status and no compiler warnings. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_RulePreview' '202': description: Update pending approval (internal accounts, blocking customer rules, and customer rules with compiler warnings). content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ApprovalPendingResponse' '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '404': description: Rule not found. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '409': description: Another approval is already pending for this rule. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ApprovalConflictResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.email x-fern-sdk-method-name: update /accounts/{account_id}/cloudforce-one/rules/structured/{id}/test: post: operationId: cloudforce-one-test-email-rule summary: Test an email rule description: Test a structured email rule against sample email JSON. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: id in: path description: The unique identifier for the rule. required: true schema: description: The unique identifier for the rule. type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 requestBody: content: application/json: schema: type: object properties: sample_json: type: string maxLength: 16777216 minLength: 1 required: - sample_json responses: '200': description: Test result. content: application/json: schema: type: object properties: error: type: string matched: type: boolean rules: type: array items: type: string required: - matched - rules '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '404': description: Rule not found. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.email x-fern-sdk-method-name: test /accounts/{account_id}/cloudforce-one/rules/tree: get: operationId: cloudforce-one-get-rule-tree summary: Get folder tree structure description: Get the folder tree structure for rules navigation. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' responses: '200': description: Folder tree structure. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_TreeResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules.tree x-fern-sdk-method-name: get /accounts/{account_id}/cloudforce-one/rules/validate: post: operationId: cloudforce-one-validate-rule summary: Validate rule with context description: Validates rule syntax, name uniqueness, namespace, and metadata. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' requestBody: content: application/json: schema: type: object properties: content: minLength: 1 type: string excludeRuleId: type: string format: uuid name: type: string maxLength: 255 minLength: 1 namespaces: type: array items: maxLength: 255 minLength: 1 type: string default: [] path: type: string minLength: 1 required: - name - content responses: '200': description: Validation result. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ValidationResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules x-fern-sdk-method-name: validate /accounts/{account_id}/cloudforce-one/rules/{id}: delete: operationId: cloudforce-one-delete-rule summary: Delete a rule description: Delete an existing rule. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: id in: path description: The unique identifier for the rule. required: true schema: description: The unique identifier for the rule. type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 requestBody: content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_DeleteRuleBody' responses: '200': description: Rule deleted (non-email customer accounts). content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_SuccessResponse' '202': description: Deletion pending approval (internal accounts and customer email rules). content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ApprovalPendingResponse' '400': description: Validation error (e.g. commit_message exceeds max length). content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '404': description: Rule not found. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '409': description: Another approval is already pending for this rule. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ApprovalConflictResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules x-fern-sdk-method-name: delete get: operationId: cloudforce-one-get-rule summary: Get a rule description: Get a single rule by ID. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: id in: path description: The unique identifier for the rule. required: true schema: description: The unique identifier for the rule. type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 responses: '200': description: Rule details. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_RulePreview' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '404': description: Rule not found. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules x-fern-sdk-method-name: get put: operationId: cloudforce-one-update-rule summary: Update a rule description: Updates an existing rule. parameters: - $ref: '#/components/parameters/cloudforce-one_account_id' - name: id in: path description: The unique identifier for the rule. required: true schema: description: The unique identifier for the rule. type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 requestBody: content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_UpdateRule' responses: '200': description: Rule updated (non-email customer accounts, or silent warning-free customer email rules). content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_RulePreview' '202': description: Update pending approval (internal accounts, blocking customer email rules, and customer email rules with compiler warnings). content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ApprovalPendingResponse' '401': description: Unauthorized. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '404': description: Rule not found. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ErrorResponse' '409': description: Another approval is already pending for this rule. content: application/json: schema: $ref: '#/components/schemas/cloudforce-one_ApprovalConflictResponse' security: - api_token: [] - api_email: [] api_key: [] tags: - Rules x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.rules x-fern-sdk-method-name: update components: schemas: cloudforce-one_RuleMetaEntry: type: object properties: key: type: string type: type: string enum: - string - bool - int value: anyOf: - type: string - type: boolean - type: number required: - key - value - type cloudforce-one_UpdateAccountExemptionsBody: type: object properties: namespace: type: array items: $ref: '#/components/schemas/cloudforce-one_ExemptionUpdateEntry' tag_match: type: array items: $ref: '#/components/schemas/cloudforce-one_ExemptionUpdateEntry' worker_name: type: array items: $ref: '#/components/schemas/cloudforce-one_ExemptionUpdateEntry' additionalProperties: false cloudforce-one_PendingApproval: type: object properties: audit_log_id: type: number example: 1 can_review: description: Whether the authenticated user may approve or reject this pending change. type: boolean example: true cancelled_at: description: Time at which the requester cancelled the approval. type: - number - 'null' example: 1679529600000 x-auditable: true cancelled_by: description: Requester who cancelled the pending approval. type: - string - 'null' example: requester@example.com x-auditable: true change_description: type: string example: Updated rule content change_type: type: string example: create enum: - create - update - delete - unresolved commit_message: description: The requester supplies this human-readable justification with the change. Internal-account mutations require it; customer accounts and sync-originated changes may omit it. type: - string - 'null' example: Tighten regex to reduce false positives on legit CI workers. id: type: number example: 12345 x-auditable: true proposed_changes: $ref: '#/components/schemas/cloudforce-one_ApprovalProposedChanges' rejection_reason: description: The reviewer may supply a reason when rejecting the change. type: - string - 'null' example: Narrow the hostname match to avoid false positives. x-auditable: true requested_at: type: number example: 1679529600000 x-auditable: true requested_by: type: string example: user@example.com x-auditable: true reviewed_at: type: - number - 'null' example: 1679529600000 x-auditable: true reviewed_by: type: - string - 'null' example: approver@example.com x-auditable: true reviewer_scope: description: 'Review policy: general Nomos approvers for default; general approvers or Phishguard for email.' type: string example: email enum: - default - email - unresolved revision_number: description: Revision number within this approval request chain. type: integer example: 2 exclusiveMinimum: 0 rule_id: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 x-auditable: true rule_name: type: string example: suspicious_email.yar source_account_id: description: Customer account that owns this approval when returned by the aggregated email queue. type: integer example: 12345678 exclusiveMinimum: 0 status: type: string example: pending enum: - pending - approved - rejected - cancelled superseded_by_approval_id: description: Newer approval revision that replaced this approval. type: - number - 'null' example: 12346 supersedes_approval_id: description: This approval replaces the referenced approval revision. type: - number - 'null' example: 12344 required: - id - rule_id - rule_name - audit_log_id - requested_by - requested_at - change_description - change_type - proposed_changes - status - reviewed_by - reviewed_at - rejection_reason - cancelled_by - cancelled_at - supersedes_approval_id - superseded_by_approval_id - revision_number - commit_message - reviewer_scope - can_review cloudforce-one_MetaInputEntry: description: A YARA meta entry. The server resolves its value type. The 'detection' key accepts MALICIOUS, SUSPICIOUS, SPAM, or SPOOF. type: object properties: key: type: string maxLength: 128 minLength: 1 pattern: ^[a-zA-Z_][a-zA-Z0-9_]*$ value: anyOf: - maxLength: 10000 type: string - type: number - type: boolean required: - key - value cloudforce-one_PartialAccountExemptions: type: object properties: namespace: type: array items: example: ^test-.*$ minLength: 1 type: string tag_match: type: array items: example: ^test-.*$ minLength: 1 type: string worker_name: type: array items: example: ^test-.*$ minLength: 1 type: string additionalProperties: false cloudforce-one_ApprovalConflictResponse: type: object properties: approval_id: type: number example: 12345 code: type: string example: approval_pending enum: - approval_pending error: type: string example: An approval is already pending for this rule. required: - error - code - approval_id cloudforce-one_UpdateRule: type: object properties: commit_message: description: Human-readable justification for this change. Required for internal-account submissions; optional for customer accounts and automated sync. type: string example: Reduce false positives on legit CI workers. maxLength: 1000 content: example: 'rule example { condition: true }' minLength: 1 type: string description: description: Human-readable description of the rule. Auto-extracted from YARA meta if present. type: string example: Detects malicious proxy workers maxLength: 1000 enabled: description: Whether this rule is active for dice consumers. type: boolean example: true is_public: description: Whether this rule is visible to other internal accounts. type: boolean example: false x-auditable: true meta: description: Adds YARA meta entries to the rule's meta block and stores them in rule_meta alongside content metadata. Use valid YARA identifiers for keys; exclude 'name', 'enabled', and 'description'. You may repeat keys. type: array items: $ref: '#/components/schemas/cloudforce-one_MetaInputEntry' maxItems: 50 name: type: string example: block-malicious-workers maxLength: 255 minLength: 1 x-auditable: true namespaces: type: array items: maxLength: 255 minLength: 1 type: string example: - yara/workers x-auditable: true path: description: Path change goes through approval workflow. type: string example: yara/workers minLength: 1 x-auditable: true cloudforce-one_EditApprovalResponse: type: object properties: approval: allOf: - $ref: '#/components/schemas/cloudforce-one_PendingApproval' - properties: current_rule: anyOf: - $ref: '#/components/schemas/cloudforce-one_RulePreview' type: object required: - approval cloudforce-one_DeleteRuleBody: type: object properties: commit_message: description: Human-readable justification for the deletion. Required for internal-account submissions; optional for customer accounts and automated sync. type: string example: Rule superseded by yara/workers/tighter-panel.yar. maxLength: 1000 cloudforce-one_CreateRule: type: object properties: actions: type: array items: $ref: '#/components/schemas/cloudforce-one_RuleAction' commit_message: description: Human-readable justification for this change. Required for internal-account submissions; optional for customer accounts and automated sync. type: string example: Add worker rule to catch bpb-panel variants. maxLength: 1000 content: example: 'rule example { condition: true }' minLength: 1 type: string description: description: Human-readable description of the rule. Auto-extracted from YARA meta if present. type: string example: Detects malicious proxy workers maxLength: 1000 enabled: description: Whether this rule is active for dice consumers. type: boolean example: true default: true is_public: description: Whether this rule is visible to other internal accounts. type: boolean example: false default: false x-auditable: true meta: description: Adds YARA meta entries to the rule's meta block and stores them in rule_meta alongside content metadata. Use valid YARA identifiers for keys; exclude 'name', 'enabled', and 'description'. You may repeat keys. type: array items: $ref: '#/components/schemas/cloudforce-one_MetaInputEntry' maxItems: 50 name: type: string example: block-malicious-workers maxLength: 255 minLength: 1 x-auditable: true namespaces: description: Optional WfP deployment tags (customer rules only). Internal rules leave empty. type: array items: maxLength: 255 minLength: 1 type: string example: [] default: [] x-auditable: true path: type: string example: yara/workers minLength: 1 x-auditable: true required: - name - path - content cloudforce-one_EmailRulesListResponse: type: object properties: rules: type: array items: $ref: '#/components/schemas/cloudforce-one_RulePreview' total: type: number example: 100 required: - rules - total cloudforce-one_StatsResponse: type: object properties: pending_approvals: type: number example: 5 rules_by_namespace: type: object example: yara/dns_record: 12 yara/workers: 30 additionalProperties: type: number total_rules: type: number example: 42 required: - total_rules - rules_by_namespace - pending_approvals cloudforce-one_RulesSearchResponse: type: object properties: fallback: description: True when AI Search was unavailable and the response is from a fallback path. type: boolean example: false interpreted: description: Parsed natural-language interpretation of the query, when available. type: object properties: filters: description: Filters applied during retrieval (account ACL plus user-supplied facets). type: object additionalProperties: type: - object - 'null' retrieval_type: type: string required: - retrieval_type mode: description: Retrieval strategy actually used to produce results. type: string example: hybrid results: type: array items: $ref: '#/components/schemas/cloudforce-one_RuleSearchResult' total: type: integer example: 12 minimum: 0 required: - results - total - mode cloudforce-one_RuleSearchResult: allOf: - $ref: '#/components/schemas/cloudforce-one_RulePreview' - properties: score: description: Relevance score in [0,1]. Present only when AI Search powers the query. type: number example: 0.87 maximum: 1 minimum: 0 scoring_details: description: AI Search hybrid retrieval returns this per-component scoring breakdown. type: object properties: fusion_method: type: string keyword_rank: type: number keyword_score: type: number reranking_score: type: number vector_rank: type: number vector_score: type: number type: object cloudforce-one_AccountExemptions: type: object properties: namespace: type: array items: type: string example: - ^test-.*$ tag_match: type: array items: type: string example: - ^staging-.*$ worker_name: type: array items: type: string example: - ^demo-.*$ required: - namespace - tag_match - worker_name cloudforce-one_ErrorResponse: type: object properties: error: type: string example: Not found required: - error cloudforce-one_RulesPreviewListResponse: type: object properties: rules: type: array items: $ref: '#/components/schemas/cloudforce-one_RulePreview' total: type: number example: 100 required: - rules - total cloudforce-one_SuccessResponse: type: object properties: success: type: boolean example: true required: - success cloudforce-one_RulePreview: type: object properties: content: example: 'rule example { condition: true }' type: string created_at: type: number example: 1679529600000 x-auditable: true created_by: type: string example: user@example.com x-auditable: true description: type: string example: Detects malicious proxy workers enabled: description: Whether this rule is active for dice consumers. type: boolean example: true id: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 x-auditable: true is_public: description: Whether this rule is visible to other internal accounts. type: boolean example: false x-auditable: true meta: description: Structured meta entries for the rule (parsed from content plus any request-supplied meta). Returned in source order. type: array items: $ref: '#/components/schemas/cloudforce-one_RuleMetaEntry' name: type: string example: block-malicious-workers x-auditable: true namespaces: type: array items: type: string example: - yara/workers x-auditable: true path: type: string example: yara/workers x-auditable: true pending_approval_id: description: ID of an open approval workflow targeting this rule, or null if none is pending. type: - number - 'null' pending_change: $ref: '#/components/schemas/cloudforce-one_PendingRuleChange' structured_source: description: Original JSON payload for rules created via the structured rules API. Null for hand-written rules. type: - string - 'null' updated_at: type: number example: 1679529600000 x-auditable: true updated_by: type: string example: user@example.com x-auditable: true required: - id - name - path - description - namespaces - is_public - enabled - created_at - updated_at - created_by - updated_by - pending_approval_id - pending_change cloudforce-one_EmailRuleHeaderCondition: type: object properties: header_name: type: string maxLength: 256 minLength: 1 match_type: type: string enum: - any - all - first - last - count operator: type: string enum: - == - '!=' - '>' - '>=' - < - <= - contains - matches type: type: string enum: - header value: oneOf: - type: string - type: number required: - type - header_name - match_type - operator - value cloudforce-one_EmailRuleArrayCondition: type: object properties: conditions: type: array items: properties: operator: type: string enum: - == - '!=' - '>' - '>=' - < - <= - contains - matches subfield: type: string maxLength: 128 minLength: 1 value: oneOf: - type: string - type: number - type: boolean required: - subfield - operator - value type: object maxItems: 20 minItems: 1 field: type: string maxLength: 256 minLength: 1 quantifier: type: string default: any enum: - any - all type: type: string enum: - array required: - type - field - conditions cloudforce-one_EmailRuleScalarCondition: type: object properties: field: type: string maxLength: 256 minLength: 1 operator: type: string enum: - == - '!=' - '>' - '>=' - < - <= - contains - matches type: type: string enum: - scalar value: oneOf: - type: string - type: number - type: boolean required: - type - field - operator - value cloudforce-one_RuleAction: type: object properties: action_config: description: Action-specific configuration parameters. type: object additionalProperties: anyOf: - type: string - type: number - type: boolean - items: type: string type: array - additionalProperties: type: string type: object action_type: type: string example: alert_gchat enum: - alert_gchat - webhook - logging - email - pipeline - remediation - throttle - delete enabled: type: boolean default: true required: - action_type - action_config cloudforce-one_ApprovalPendingResponse: type: object properties: approval_id: type: number example: 1 message: type: string example: Rule creation pending approval required: - approval_id - message cloudforce-one_ValidationResponse: type: object properties: error: type: string example: Invalid YARA syntax valid: type: boolean example: true required: - valid cloudforce-one_TreeResponse: type: object properties: tree: type: array items: $ref: '#/components/schemas/cloudforce-one_TreeNode' required: - tree cloudforce-one_TreeNode: type: object properties: children: type: array items: $ref: '#/components/schemas/cloudforce-one_TreeNode' count: type: number example: 15 name: type: string example: workers path: type: string example: yara/workers required: - name - path - count - children cloudforce-one_EmailRuleCondition: discriminator: mapping: array: '#/components/schemas/cloudforce-one_EmailRuleArrayCondition' group: '#/components/schemas/cloudforce-one_EmailRuleConditionGroup' header: '#/components/schemas/cloudforce-one_EmailRuleHeaderCondition' scalar: '#/components/schemas/cloudforce-one_EmailRuleScalarCondition' propertyName: type oneOf: - $ref: '#/components/schemas/cloudforce-one_EmailRuleScalarCondition' - $ref: '#/components/schemas/cloudforce-one_EmailRuleArrayCondition' - $ref: '#/components/schemas/cloudforce-one_EmailRuleHeaderCondition' - $ref: '#/components/schemas/cloudforce-one_EmailRuleConditionGroup' cloudforce-one_ResubmitApprovalResponse: type: object properties: approval_id: type: number message: type: string requires_approval: type: boolean enum: - true revision_number: type: integer exclusiveMinimum: 0 supersedes_approval_id: type: number required: - message - approval_id - supersedes_approval_id - revision_number - requires_approval cloudforce-one_Rule: type: object properties: content: example: 'rule example { condition: true }' type: string created_at: type: number example: 1679529600000 x-auditable: true created_by: type: string example: user@example.com x-auditable: true description: type: string example: Detects malicious proxy workers enabled: description: Whether this rule is active for dice consumers. type: boolean example: true id: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 x-auditable: true is_public: description: Whether this rule is visible to other internal accounts. type: boolean example: false x-auditable: true meta: description: Structured meta entries for the rule (parsed from content plus any request-supplied meta). Returned in source order. type: array items: $ref: '#/components/schemas/cloudforce-one_RuleMetaEntry' name: type: string example: block-malicious-workers x-auditable: true namespaces: type: array items: type: string example: - yara/workers x-auditable: true path: type: string example: yara/workers x-auditable: true pending_approval_id: description: ID of an open approval workflow targeting this rule, or null if none is pending. type: - number - 'null' pending_change: $ref: '#/components/schemas/cloudforce-one_PendingRuleChange' structured_source: description: Original JSON payload for rules created via the structured rules API. Null for hand-written rules. type: - string - 'null' updated_at: type: number example: 1679529600000 x-auditable: true updated_by: type: string example: user@example.com x-auditable: true required: - id - name - path - description - namespaces - content - is_public - enabled - created_at - updated_at - created_by - updated_by - pending_approval_id - pending_change cloudforce-one_DeleteAllResponse: type: object properties: deleted: type: number example: 10 required: - deleted cloudforce-one_EmailRuleConditionGroup: description: Nested condition groups support up to 10 levels of depth. type: object properties: conditions: type: array items: $ref: '#/components/schemas/cloudforce-one_EmailRuleCondition' maxItems: 50 minItems: 1 operator: type: string enum: - and - or type: type: string enum: - group required: - type - operator - conditions cloudforce-one_ApprovalProposedChanges: description: Contains structured proposed rule changes, or null for unresolved persisted data. oneOf: - properties: content: type: string created_at: type: number created_by: type: string description: type: string enabled: type: boolean id: type: string is_public: type: boolean name: type: string namespaces: type: array items: type: string path: type: string minLength: 1 structured_source: type: - string - 'null' sync_message: type: string sync_source: type: string type: type: string enum: - create required: - type - id - name - path - description - namespaces - is_public - enabled - created_by - created_at type: object - properties: content: type: string description: type: string enabled: type: boolean is_public: type: boolean name: type: string namespaces: type: array items: type: string path: type: string minLength: 1 structured_source: type: - string - 'null' sync_message: type: string sync_source: type: string type: type: string enum: - update required: - type type: object - properties: id: type: string name: type: string sync_message: type: string sync_source: type: string type: type: string enum: - delete required: - type - id - name type: object cloudforce-one_PendingRuleChange: description: Proposed update or deletion awaiting approval. The other rule fields describe the currently applied version. type: - object - 'null' properties: approval_id: type: number example: 12345 requested_at: type: number example: 1679529600000 requested_by: type: string example: user@example.com type: type: string example: update enum: - update - delete required: - approval_id - type - requested_at - requested_by cloudforce-one_EmailRuleValidationResponse: type: object properties: compiled_yara: type: string error: type: string valid: type: boolean required: - valid cloudforce-one_ExemptionUpdateEntry: type: object properties: new_pattern: type: string example: ^test-.*$ minLength: 1 old_pattern: type: string example: ^test-.*$ minLength: 1 required: - old_pattern - new_pattern parameters: cloudforce-one_account_id: description: Cloudflare account ID. in: path name: account_id required: true schema: type: string example: 023e105f4ecef8ad9ca31a8372d0c353 securitySchemes: api_email: in: header name: X-Auth-Email type: apiKey api_key: in: header name: X-Auth-Key type: apiKey api_token: scheme: bearer type: http user_service_key: in: header name: X-Auth-User-Service-Key type: apiKey externalDocs: description: Cloudflare Radar Documentation url: https://developers.cloudflare.com/radar/ x-forge-commands: abuse-reports: description: Submit and track abuse reports for phishing, malware, and other policy violations on Cloudflare-proxied sites groups: appeals: description: Appeal eligibility for abuse reports emails: description: Emails sent for abuse reports mitigations: description: Mitigation actions taken in response to abuse reports accounts: description: Account settings, members, roles, subscriptions, and API tokens for your Cloudflare account groups: applications: description: Applications operations categories: description: Categories operations organizations: description: Move accounts between organizations profile: description: View and manage the profile for a Cloudflare account roles: description: View the roles available for assigning to account members, each defining a set of permissions subscriptions: description: View and manage plan subscriptions attached to this account tokens: description: Create and manage scoped API tokens for programmatic access to the Cloudflare API ai-gateway: description: Proxy, cache, rate-limit, and observe requests to AI providers — OpenAI, Anthropic, Workers AI, and more groups: custom-domains: description: Manage custom hostnames that route requests through an AI Gateway custom-providers: description: Manage account-level custom AI providers and their endpoint settings datasets: description: 'Deprecated: manage filtered collections of gateway logs used by evaluations' dynamic-routing: description: Route requests across multiple AI providers with fallback, load-balancing, and versioned deployments dynamic-routing.deployments: description: Deploy dynamic route versions and view deployment history dynamic-routing.versions: description: Create and inspect saved versions of a dynamic route evaluation-types: description: 'Deprecated: list the evaluator types that evaluations can use' evaluations: description: 'Deprecated: score the logs in a dataset with selected evaluator types' gateways: description: Create and configure AI Gateways for an account gateways.providers: description: Store and rotate upstream AI provider keys for a gateway logs: description: Inspect, annotate, and delete gateway request logs stored by Legacy Logs ai-search: description: 'Managed search-as-a-service: crawl, index, and query content with AI-powered relevance and chat completions' groups: items: description: Content indexed by AI Search instances jobs: description: Indexing job lifecycle for AI Search instances namespace: description: Logical groupings for organizing AI Search instances tokens: description: Credentials used by AI Search instances ai-security: description: Detect prompt injection, PII, and unsafe topics in traffic to your AI applications groups: custom-topics: description: Organization-specific topic categories used by AI Security for Apps content detection analytics: description: Zone-level traffic analytics — dashboard summaries, per-colo breakdowns, and Argo latency metrics groups: colo: description: Per-data-center (colo) traffic analytics breakdown for the zone dashboard: description: Aggregated zone dashboard analytics — requests, bandwidth, threats, and page views latency: description: Argo Smart Routing latency analytics showing time-to-first-byte improvements argo: description: Network optimization features that speed up and improve reliability of traffic to your origins groups: smart-routing: description: Route traffic through the fastest network paths to your origin using real-time latency data tiered-caching: description: Reduce origin load by having upper-tier data centers serve cache misses before reaching your origin basin-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables billing: description: Account billing profiles and usage data for Cloudflare subscriptions and add-on services groups: profiles: description: Billing profile with payment method, address, and invoice preferences usage: description: Metered usage data for billed services — requests, bandwidth, and feature consumption botnet-feed: description: Botnet threat intelligence feeds — IP and ASN-level data on known command-and-control infrastructure groups: asn: description: ASN-level botnet activity data showing networks with known C2 infrastructure configs: description: Botnet feed subscription configuration and notification preferences builds: description: Build and deploy Workers from connected repositories, then inspect build status and logs. groups: deploy-hooks: description: Manage branch-specific HTTP hooks that start builds. limits: description: View build-minute availability and refresh information. logs: description: Retrieve build logs. repos: description: Manage source repository connections for Workers Builds. tokens: description: Manage credentials used by Workers Builds to deploy Workers. triggers: description: Configure how repository changes build and deploy Workers. versions: description: Find builds associated with Worker versions. workers: description: Manage repository-backed build configuration for Workers. cache: description: Purge cached content and configure Cache Reserve, tiered caching, and variant serving groups: origin-cloud-regions: description: Manage Origin Cloud Regions routing and failover configurations settings: description: Configure Cache Reserve, tiered caching, and variant serving settings.regional-tiered-cache: description: Restrict tiered cache topology to data centers within a specific geographic region settings.reserve: description: Persistent storage tier that keeps cached assets even after eviction from edge caches settings.smart-tiered-cache: description: Automatically determine the best upper-tier data centers for tiered cache topology settings.variants: description: Serve different cached versions of an image based on the Accept header (WebP, AVIF, etc.) client-side-security: description: Client-Side Security — monitor JavaScript, connections, and cookies on your pages for supply-chain attacks groups: connections: description: Third-party connections made by scripts on your pages — track data exfiltration risks cookies: description: Cookies set by your pages with classification and same-site attribute tracking policies: description: Content Security Policies that control which scripts and connections are allowed on your pages scripts: description: JavaScript files detected on your pages with change tracking and malicious code detection settings: description: Fine tune Client-Side Security behaviors cloud-connector: description: Route traffic from Cloudflare directly to cloud provider services (AWS, Azure, GCP) without origin servers groups: rules: description: Routing rules that map request patterns to cloud provider endpoints cloudforce-one: description: Detection rule management APIs groups: binary-storage: description: Upload and retrieve malware samples and suspicious binaries for analysis requests: description: Additional request operations — priority listing and asset creation rules: description: Rule management operations groups: approvals: description: Approval workflow operations email: description: Email rule operations exemptions: description: Exemption rule operations managed: description: Managed rule operations stats: description: Rule statistics operations tree: description: Rule navigation tree operations scans: description: Scan URLs, IPs, and domains for threat intelligence indicators containers: description: Deploy and manage Containers applications on Cloudflare's global network groups: applications: description: Manage Containers applications applications.instances: description: Inspect Containers instances belonging to applications applications.rollouts: description: Manage rollouts for scheduler-backed applications applications.versions: description: Inspect versions of scheduler-backed applications registries: description: Manage Containers image registries registries.credentials: description: Generate image registry credentials content-scan: description: Malicious uploads detection, scan uploaded content in HTTP requests for malware and malicious payloads groups: expressions: description: Custom expressions that tell the scanner how to reach content objects it cannot parse on its own custom-pages: description: Manage custom error and challenge pages and their assets for accounts and zones groups: account-custom-pages: description: Manage account-level custom pages account-custom-pages.preview-tokens: description: Preview tokens for account-level custom pages assets: description: Manage account- and zone-level custom assets zone-custom-pages: description: Manage zone-level custom pages zone-custom-pages.preview-tokens: description: Preview tokens for zone-level custom pages d1: description: D1 is Cloudflare's managed, serverless database with SQLite's SQL semantics, built-in disaster recovery, and Worker and HTTP API access. groups: time-travel: description: use specific point-in-time backups of your D1 database x-forge-epilogue: For more information about Time Travel, see https://developers.cloudflare.com/d1/reference/time-travel diagnostics: description: Network diagnostic tools — traceroutes from Cloudflare's edge and endpoint health checks groups: endpoint-healthchecks: description: Monitor external endpoint availability with periodic HTTP/HTTPS health checks traceroutes: description: Run traceroutes from Cloudflare data centers to diagnose network path issues email-routing: description: Route incoming email to verified destination addresses or Workers with routing rules, catch-all behavior, and managed DNS records groups: addresses: description: Verified destination email addresses that can receive forwarded mail dns: description: Inspect or unlock the DNS records required by Email Routing rules: description: Match incoming email addresses and forward messages to destination mailboxes or Workers settings: description: Inspect and update Email Routing settings email-security: description: Cloud email security — investigate threats, manage allow/block policies, and detect phishing groups: analytics: description: Analytics and reporting — monthly report and per-day breakdowns of threat activity bulk-actions: description: Asynchronous jobs that move or release every message matching a search — create, monitor, and manage bulk jobs investigate: description: Search and investigate email messages — view detections, traces, raw content, and take remediation actions phishguard: description: PhishGuard user-reported phishing reports — view detected threats for a date range settings: description: Email security configuration — block senders, allow policies, content policies, domains, trusted domains, impersonation registry, and URL handling submissions: description: Reclassify submissions — track user and team reports of false positives and missed detections email-sending: description: Send transactional email and manage sending subdomains and their DNS configuration groups: limits: description: Inspect account-level sending quotas and current usage subdomains: description: Configure sending subdomains and keep their DNS records healthy suppressions: description: Prevent delivery to suppressed addresses and manage the account suppression list filters: description: Filter expressions used by legacy firewall rules to match requests — prefer Rulesets for new configurations firewall: description: Legacy firewall rules, zone lockdowns, access rules, user-agent blocking, and WAF packages groups: access-rules: description: IP-based access rules that allow, block, challenge, or whitelist traffic globally or per-zone lockdowns: description: Zone lockdown rules that restrict access to URLs by IP address or range rules: description: Legacy firewall rules with filter expressions — prefer Rulesets for new configurations ua-rules: description: Block or challenge requests based on the User-Agent header string waf: description: Legacy WAF managed rule packages, rule groups, individual rules, and override configurations zone-access-rules: description: Zone-scoped IP access rules for blocking or allowing traffic google-tag-gateway: description: Google Tag Gateway operations groups: config: description: Google Tag Gateway config operations healthchecks: description: Standalone health checks that monitor origin server availability from Cloudflare's edge groups: previews: description: Test a health check configuration before deploying it to production hyperdrive: description: Accelerate access to existing databases by caching queries and pooling connections at the edge iam: description: Identity and access management — permission groups, resource groups, user groups, and SSO connectors groups: permission-groups: description: View the permission groups that can be assigned to API tokens and policies resource-groups: description: Define scopes that limit which account resources a policy or token can access sso: description: Configure single sign-on connectors to authenticate account members through an external identity provider user-groups: description: Organize account members into groups for easier permission assignment images: description: Store, resize, and deliver optimized images globally — variants, signing keys, and direct uploads groups: flows: description: Zone-level transformation flows that control how images are resized and optimized on delivery import: description: Import images from S3 keys: description: Manage signing keys for generating private image URLs variants: description: Manage named resize variants for transforming images on delivery intel: description: Threat intelligence lookups — IP reputation, domain info, ASN details, WHOIS, and indicator feeds groups: asn: description: ASN intelligence — ownership, geolocation, and subnet details for autonomous systems attack-surface-report: description: Attack surface intelligence — exposed assets, vulnerabilities, and infrastructure mapping dns: description: Passive DNS data showing historical DNS resolution records for domains domain-history: description: Historical domain registration and categorization changes over time domains: description: Domain intelligence — risk scores, categories, and associated infrastructure indicator-feeds: description: Threat indicator feeds — subscribe to and manage curated lists of malicious IPs, domains, and URLs ip-lists: description: Curated IP lists used for threat detection and policy enforcement ips: description: IP address intelligence — geolocation, risk assessment, and hosting provider details miscategorizations: description: Report and track domain miscategorization corrections whois: description: WHOIS registration data for domains including registrant, registrar, and nameservers k2: description: Durable, ordered event streams that you produce records to and consume from with subscriptions groups: streams: description: K2 streams, their retention, and the HTTP and Workers binding inputs used to produce records streams.subscriptions: description: Subscriptions that consume a K2 stream, with committed-position lag leaked-credential-checks: description: Detect compromised credentials in login requests by checking against known breach databases groups: detections: description: Custom detection locations that tell the WAF where to find usernames and passwords in requests load-balancers: description: Distribute traffic across origin pools with health monitoring, geo-steering, and failover groups: monitor-groups: description: Group monitors together for shared configuration and bulk management monitor-groups.references: description: List references to monitor groups used by load balancer pools monitors: description: Health check configurations that probe origin servers and determine pool availability monitors.previews: description: Health check configurations that probe origin servers and determine pool availability monitors.references: description: Health check configurations that probe origin servers and determine pool availability pools: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.health: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.references: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences previews: description: Preview the result of a health check monitor configuration before applying it regions: description: Geographic regions used for regional pool steering and traffic policies searches: description: Search across all load balancer resources (pools, monitors, load balancers) by name or reference logs: description: Log control, retention, and raw log access — CMB config, ray ID lookups, and received fields groups: control: description: Log control operations received: description: Received log operations magic-network-monitoring: description: Flow-based network traffic monitoring with configurable alerting rules and VPC flow ingestion groups: configs: description: Account-level monitoring configuration — sampling rates, thresholds, and notification settings rules: description: Monitoring rules that define traffic thresholds and trigger alerts or prefix advertisements vpc-flows: description: Ingest VPC flow logs from cloud providers for network visibility and anomaly detection magic-transit: description: DDoS-protected network transit — GRE/IPsec tunnels, static routes, Magic WAN sites, connectors, and packet captures groups: advanced-dns-protection: description: Advanced Dns Protection operations advanced-tcp-protection: description: Advanced Tcp Protection operations apps: description: Application-aware traffic policies for Magic WAN that steer traffic by app type bgp-filter-profiles: description: BGP filter profiles for controlling which routes are allowed or denied on Magic Transit tunnels bgp-settings: description: BGP settings for controlling default ASN and route redistribution on Magic Transit tunnels cf-interconnects: description: Cloudflare Network Interconnect (CNI) links for direct physical or virtual peering gre-tunnels: description: GRE tunnel endpoints that connect your network to Cloudflare for Magic Transit ipsec-tunnels: description: IPsec tunnel endpoints with pre-shared key management for encrypted transit pcaps: description: Packet capture requests for debugging traffic flowing through Magic Transit tunnels routes: description: Static routes that direct IP prefix traffic through specific GRE/IPsec tunnels sites: description: Magic WAN branch sites — base CRUD, LAN/WAN interface configuration, ACLs, connectors, app configuration, and NetFlow config mcp: description: Manage MCP portals and upstream MCP servers for Cloudflare Access AI controls groups: portals: description: Manage MCP portals, attached servers, and Code Mode settings servers: description: Manage upstream MCP servers, credentials, capabilities, and sync state network-interconnects: description: Physical and virtual private interconnects between your infrastructure and Cloudflare's network groups: cnis: description: Cloud Network Interconnect (CNI) connections — private links from cloud providers to Cloudflare interconnects: description: Physical cross-connect and partner interconnect sessions with LOA and status tracking settings: description: Account-level interconnect settings and default configurations slots: description: Available interconnect facility slots showing port capacity at Cloudflare data centers organizations: description: Multi-user organizations that group accounts, members, and shared settings under a single entity groups: account-organizations: description: List organizations associated with a specific account accounts: description: Accounts operations members: description: Members operations members-batch-create: description: Members Batch Create operations organization-profile: description: View and update the public profile information for an organization shares: description: Shares operations origin-post-quantum-encryption: description: Enable post-quantum key exchange for connections between Cloudflare and your origin server pages: description: Full-stack application hosting with Git-integrated builds, preview deployments, and custom domains groups: projects: description: Pages projects, deployments, build logs, and custom domain bindings pipelines: description: Ingest, transform, and route event streams into R2, analytics, or other destinations in real time groups: sinks: description: Destinations where pipeline data is written — R2 buckets, HTTP endpoints, or other storage streams: description: Inbound data streams that feed events into a pipeline for processing precursor: description: Precursor settings for a zone queues: description: Reliable message queuing between Workers — produce, consume, and batch-process messages at scale groups: consumers: description: Workers that automatically receive and process messages from a queue messages: description: Push messages to a queue and pull or acknowledge them from consumers purge: description: Remove all pending messages from a queue subscriptions: description: Manage queue subscriptions for event-driven message routing r2: description: S3-compatible object storage with zero egress fees — buckets, lifecycle rules, event notifications, and data migration groups: buckets: description: Create and configure R2 buckets including CORS, lifecycle, custom domains, event notifications, and object locks buckets.jobs: description: Create and inspect background jobs for an R2 bucket buckets.local-uploads: description: R2 bucket local upload configuration super-slurper: description: Migrate data from external S3-compatible storage into R2 buckets with resumable transfer jobs temporary-credentials: description: Generate short-lived S3-compatible credentials scoped to specific buckets and operations r2-data-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables radar: description: Internet-wide traffic intelligence — BGP, DNS, HTTP trends, attack data, and network quality insights groups: agent-readiness: description: Agent readiness summary statistics across the Cloudflare network ai: description: AI inference trends and model usage statistics across the Cloudflare network annotations: description: Radar annotations marking significant Internet events (outages, cable cuts, etc.) as112: description: AS112 DNS sinkhole statistics — reverse DNS query volumes for private address space attacks: description: DDoS and application-layer attack trends, vectors, and target analysis bgp: description: BGP routing data — prefix announcements, AS-level stats, route leaks, and hijack events bots: description: Internet-wide bot traffic trends, categories, and distribution statistics ct: description: Certificate Transparency log monitoring and newly-issued certificate discovery datasets: description: Downloadable Radar datasets for offline analysis and research dns: description: Global DNS query trends — top domains, resolver stats, and DNSSEC adoption email: description: Email security trends — DMARC/SPF/DKIM adoption, spam, and phishing statistics entities: description: Look up ASNs, IPs, domains, and locations with metadata and traffic summaries geolocations: description: Geographic location metadata used for regional traffic analysis http: description: HTTP protocol trends — TLS versions, HTTP versions, browser share, and OS distribution leaked-credentials: description: Leaked credential detection trends and exposure statistics netflows: description: Network-layer traffic flow data and volumetric trend analysis origins: description: Cloud and hosting origin providers (e.g. Amazon, by region) and their traffic metrics post-quantum: description: Post-quantum encryption adoption and deployment trends across the Internet quality: description: Internet connection quality metrics — speed, latency, and jitter by geography and ASN ranking: description: Top domain rankings based on DNS query popularity across the Cloudflare network robots-txt: description: Robots.txt adoption and crawler directive trends across the web search: description: Search Radar data across IPs, ASNs, domains, and locations tcp-resets-timeouts: description: TCP connection reset and timeout statistics indicating network health issues tlds: description: Top-level domain (TLD) metadata and performance trends traffic-anomalies: description: Detected traffic anomalies and unusual patterns in Internet traffic flows verified-bots: description: Catalog of known good bots (Googlebot, Bingbot, etc.) and their traffic patterns rate-limits: description: Legacy per-zone rate limiting rules — prefer Advanced Rate Limiting in Rulesets for new configurations realtime: description: Real-time audio, video, and data services on Cloudflare's global network groups: kit: description: SDK-backed meetings, participants, recordings, livestreams, and webhooks kit.analytics: description: Usage and livestream analytics for RealtimeKit applications kit.analytics.livestreams: description: Livestream analytics for RealtimeKit applications kit.analytics.livestreams.daily: description: Daily livestream analytics for RealtimeKit applications kit.analytics.usage: description: Usage analytics for RealtimeKit applications kit.apps: description: RealtimeKit applications that group meetings, sessions, and configuration kit.livestreams: description: Independent and meeting-based livestreams and their sessions kit.livestreams.sessions: description: Sessions for RealtimeKit livestreams kit.meetings: description: Meetings, participants, access tokens, and meeting livestreams kit.meetings.active: description: Live meeting state and participant controls kit.meetings.active.polls: description: Polls for active meeting sessions kit.meetings.livestream: description: Livestream operations associated with RealtimeKit meetings kit.meetings.participants: description: Participants in RealtimeKit meetings kit.meetings.participants.tokens: description: Access tokens for RealtimeKit meeting participants kit.presets: description: Reusable meeting configuration for media, permissions, and interface behavior kit.recordings: description: Meeting and participant-track recordings and recording controls kit.recordings.active: description: Active recordings for RealtimeKit meetings kit.recordings.tracks: description: Participant-track recordings for RealtimeKit meetings kit.sessions: description: Historical session data, participants, chat, transcripts, and summaries kit.sessions.chat: description: Chat messages from historical RealtimeKit sessions kit.sessions.livestreams: description: Livestreams associated with historical RealtimeKit sessions kit.sessions.participants: description: Participants in historical RealtimeKit sessions kit.sessions.peers: description: Peer details from historical RealtimeKit sessions kit.sessions.summaries: description: Summaries of historical RealtimeKit sessions kit.sessions.transcripts: description: Transcripts from historical RealtimeKit sessions kit.webhooks: description: Webhook endpoints and supported events for RealtimeKit notifications kit.webhooks.events: description: Supported events for RealtimeKit webhooks moq: description: MoQ relays for publishing and subscribing to media streams moq.relays: description: Relays are isolated MoQ scopes that carry media between publishers and subscribers moq.relays.tokens: description: Tokens that authorize publishers and subscribers to connect to a relay sfu: description: SFU apps that route WebRTC media and data between participants sfu.apps: description: SFU application namespaces for sessions and tracks turn: description: TURN keys that help clients traverse NATs and firewalls turn.keys: description: Keys used to generate short-lived TURN credentials request-tracers: description: Trace how a request would be processed through Cloudflare's rules and configuration pipeline groups: traces: description: Simulate request processing to debug rule matches, transforms, and routing decisions resource-sharing: description: Share Cloudflare resources (zones, accounts) across organizations with granular access controls groups: recipients: description: Update share recipients resources: description: Individual resources (zones, configs) that have been shared with recipients rules: description: Resources used by Cloudflare rules and rulesets groups: lists: description: Custom account-level lists of IPs, hostnames, ASNs, or redirects used in rule expressions rum: description: Real User Measurement (Web Analytics) — track page loads, Core Web Vitals, and visitor metrics groups: rules: description: Rules that control which pages and paths are tracked by Web Analytics site-info: description: Web Analytics sites — register domains and get the JavaScript beacon snippet scim: description: SCIM 2.0 provisioning — manage users, groups, and identity provider sync for your account groups: groups: description: Groups operations resource-types: description: Resource Types operations schemas: description: Schemas operations service-provider-config: description: Service Provider Config operations users: description: Users operations secrets-store: description: Centralized secret management — store API keys, tokens, and credentials for use across Workers and other products groups: quota: description: Account quota limits for secrets stores, secrets count, and storage capacity secrets: description: Encrypted key-value secrets within a store. Pass --store-id to scope. stores: description: Secret stores that hold encrypted key-value secrets accessible by Workers and services security-center: description: Security posture dashboard — view and manage security insights, misconfigurations, and vulnerabilities groups: insights: description: Security findings and recommendations across your account — DNS, SSL, WAF misconfigurations, etc. zone-insights: description: Zone-scoped security insights — counts by class, severity, type, and dismissal security-txt: description: Manage the /.well-known/security.txt file that tells security researchers how to report vulnerabilities smart-shield: description: Smart Shield settings, health checks, and cache reserve management groups: cache-reserve-clear: description: Cache Reserve Clear operations health-checks: description: Health checks operations spectrum: description: Proxy and protect arbitrary TCP/UDP applications through Cloudflare's network with DDoS mitigation groups: analytics: description: Real-time and historical connection analytics for Spectrum applications apps: description: Spectrum application configurations that map protocols and ports to origin servers speed: description: Observatory speed tests — run Lighthouse audits, track performance trends, and schedule recurring tests groups: availabilities: description: Check which speed test regions and configurations are available for your zone pages: description: Tested pages with their performance history, trends, and individual test results schedule: description: Scheduled recurring speed tests that automatically run at regular intervals ssl: description: SSL/TLS certificate management — certificate packs, Universal SSL, verification, and TLS mode recommendations groups: automatic-upgrader: description: SSL automatic mode enrollment — get or update automatic SSL/TLS upgrader settings recommendations: description: Get the recommended SSL/TLS encryption mode based on your origin server's certificate configuration stream: description: Video encoding, storage, and delivery — upload, live-stream, clip, caption, and embed video at scale groups: audio-tracks: description: Add, edit, or remove additional audio tracks on a video captions: description: Upload, generate, or retrieve captions and subtitles for videos in multiple languages clip: description: Create a new video clip from an existing video by specifying start and end times copy: description: Import a video from a URL into Stream for processing and delivery direct-upload: description: Generate a tokenized URL that lets end-users upload video directly to Stream downloads: description: Create downloadable MP4 renditions of a video for offline viewing embed: description: Retrieve the HTML embed code snippet for a video keys: description: Signing keys used to generate short-lived signed URLs for private video playback live-inputs: description: Enable and disable live input streams token: description: Generate short-lived signed URL tokens for secure private video playback typed-downloads: description: Type-specific stream download creation and deletion videos: description: Aggregate video storage usage statistics for the account watermarks: description: Watermark profiles that overlay an image on every video in the account webhooks: description: Webhook notifications for video lifecycle events (ready, error, etc.) tenants: description: Multi-tenant account management — manage tenant accounts, entitlements, and memberships groups: account-types: description: Account Types operations accounts: description: Accounts operations entitlements: description: Entitlements operations memberships: description: Memberships operations turnstile: description: CAPTCHA-free bot verification widgets that protect forms and APIs without degrading user experience groups: widgets: description: Turnstile widget configurations — site keys, secret rotation, and challenge mode settings url-scanner: description: Scan URLs for phishing, malware, and other threats — submit scans and retrieve detailed results groups: response: description: Response operations responses: description: Raw HTTP response data captured during URL scans scan: description: Scan operations scans: description: URL scan requests and results — submit URLs for analysis and retrieve threat verdicts user: description: Your Cloudflare user profile, invitations, organizations, billing, and personal API tokens groups: billing: description: View billing history and payment profile for your user (deprecated — prefer account-level billing) firewall: description: Firewall operations load-balancers.monitors: description: Load Balancers operations load-balancers.monitors.preview: description: Load Balancers operations load-balancers.monitors.references: description: Load Balancers operations load-balancers.pools: description: Load Balancers operations load-balancers.pools.edit.pools: description: Load Balancers operations load-balancers.pools.health: description: Load Balancers operations load-balancers.pools.preview: description: Load Balancers operations load-balancers.pools.references: description: Load Balancers operations load-balancers.preview: description: Load Balancers operations load-balancing-analytics.events: description: Load Balancing Analytics operations subscriptions: description: View and manage zone-level plan subscriptions owned by your user tenants: description: Tenants operations tokens: description: Create and manage personal API tokens scoped to your user for programmatic API access user.analytics: description: User-level traffic analytics — aggregated totals and timeseries across all zones vectorize: description: Globally distributed vector database for building semantic search, recommendations, and RAG applications on Workers groups: deprecated-indexes: description: Deprecated v1 Vectorize index operations metadata-index: description: Metadata indexes for filtered vector search waiting-rooms: description: Virtual queues that throttle traffic to your site during peak demand with customizable waiting pages groups: account-waiting-rooms: description: Account-scoped waiting room listing events: description: Scheduled events that temporarily override waiting room settings for sales, launches, etc. page: description: Custom HTML waiting page templates and preview rendering rules: description: Rules that bypass or modify waiting room behavior for specific request patterns settings: description: Zone-level waiting room defaults and cookie configuration statuses: description: Real-time queue status showing active users, queued users, and estimated wait times workflows: description: Durable, multi-step workflows that run on Workers with automatic retries and state persistence groups: instances: description: Workflow instance operations versions: description: Workflow version operations zaraz: description: Server-side tag manager — load third-party tools (analytics, pixels, etc.) from Cloudflare's edge without client-side JS groups: config: description: Full Zaraz configuration including tools, triggers, and variables for the zone default: description: Default Zaraz configuration template used as a starting point for new zones export: description: Export the current Zaraz configuration as a portable JSON document history: description: Configuration version history — browse and restore previous Zaraz configurations publish: description: Publish pending Zaraz configuration changes to make them live on the zone workflow: description: Workflow state for Zaraz configuration changes (draft vs. published) zero-trust: description: Cloudflare's SASE platform — secure access, device posture, DLP, tunnels, gateway policies, and network segmentation groups: dex: description: Digital Experience Monitoring — synthetic tests, fleet-wide device metrics, and network path diagnostics dlp.custom-prompt-topics: description: Data Loss Prevention - manage custom prompt topics for AI-based content detection dlp.data-classes: description: Data Loss Prevention - manage data classes used to classify sensitive information dlp.data-tag-categories: description: Data Loss Prevention - manage categories that organize data tags dlp.data-tag-category-templates: description: Data Loss Prevention - browse templates for creating data tag categories dlp.data-tags: description: Data Loss Prevention - manage tags used to classify and organize sensitive data dlp.datasets: description: Data Loss Prevention - manage datasets, versions, and uploads dlp.document-fingerprints: description: Data Loss Prevention - manage document fingerprints for detecting matching documents dlp.email.account-mapping: description: Data Loss Prevention - configure account mappings for outbound email scanning dlp.email.rules: description: Data Loss Prevention - manage outbound email scanning rules and their priorities dlp.entries: description: Data Loss Prevention - list and manage detection entries dlp.limits: description: Data Loss Prevention - view account limits and resource quotas dlp.patterns: description: Data Loss Prevention - validate regular expressions used for content detection dlp.profiles: description: Data Loss Prevention - list and retrieve profiles dlp.profiles.custom: description: Data Loss Prevention - manage custom profiles dlp.profiles.predefined: description: Data Loss Prevention - manage predefined profiles dlp.sensitivity-group-templates: description: Data Loss Prevention - browse templates for creating sensitivity groups dlp.sensitivity-groups: description: Data Loss Prevention - manage sensitivity groups and their level ordering dlp.sensitivity-levels: description: Data Loss Prevention - manage sensitivity levels within sensitivity groups dlp.settings: description: Data Loss Prevention - manage account-level settings dlp.validators: description: Data Loss Prevention - list and retrieve content validators dlp.validators.proximity-words: description: Data Loss Prevention - manage proximity-word validators risk-scoring: description: User Risk Scoring - retrieve and reset user risk scores risk-scoring.behaviours: description: User Risk Scoring - manage behaviors used to calculate user risk scores risk-scoring.integrations: description: User Risk Scoring - manage integrations that provide risk score signals risk-scoring.integrations.references: description: User Risk Scoring - retrieve integrations by external reference risk-scoring.summary: description: User Risk Scoring - retrieve account risk score summaries zones: description: Zones are domains on Cloudflare — list, create, and configure domain settings groups: aegis: description: Aegis operations fonts: description: Fonts operations origin-h2-max-streams: description: Origin H2 Max Streams operations origin-max-http-version: description: Origin Max Http Version operations origin-tls-compliance-modes: description: Manage zone Origin TLS Compliance Modes setting rum: description: Rum operations speed-brain: description: Speed Brain operations