OptionalaccountOptionalallowWhen set to true, users can authenticate via WARP for any application in your organization. Application settings will take precedence over this value.
OptionalauthThe unique subdomain assigned to your Zero Trust organization.
OptionalautoWhen set to true, users skip the identity provider selection step during login.
OptionalcustomOptionaldenyDetermines whether to deny all requests to Cloudflare-protected resources that lack an associated Access application. If enabled, you must explicitly configure an Access application and policy to allow traffic to your Cloudflare-protected resources. For domains you want to be public across all subdomains, add the domain to the denyUnmatchedRequestsExemptedZoneNames array.
OptionaldenyContains zone names to exempt from the denyUnmatchedRequests feature. Requests to a subdomain in an exempted zone will block unauthenticated traffic by default if there is a configured Access application and policy that matches the request.
OptionalisLock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled.
OptionalloginOptionalmfaConfigures multi-factor authentication (MFA) settings for an organization.
OptionalmfaIndicates if this organization can enforce multi-factor authentication (MFA) requirements at the application and policy level.
OptionalmfaDetermines whether global MFA settings apply to applications by default. The organization must have MFA enabled with at least one authentication method and a session duration configured.
OptionalnameThe name of your Zero Trust organization.
OptionalsessionThe amount of time that tokens issued for applications will be valid. Must be in the format 300ms or 2h45m. Valid time units are: ns, us (or µs), ms, s, m, h.
OptionaluiA description of the reason why the UI read only field is being toggled.
OptionaluserThe amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and no longer counts against your Teams seat count. Minimum value for this setting is 1 month (730h). Must be in the format 300ms or 2h45m. Valid time units are: ns, us (or µs), ms, s, m, h.
OptionalwarpThe amount of time that tokens issued for applications will be valid. Must be in the format 30m or 2h45m. Valid time units are: m, h.
OptionalzoneThe Zone ID to use for this endpoint. Mutually exclusive with the Account ID.
The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.