APIs.io Engineering Platform Access Applications API

The Access Applications API from APIs.io Engineering Platform — 4 operation(s) for access applications.

Operations 7

GET /accounts/{account_id}/access/apps APIs.io Engineering Platform List Access applications #
POST /accounts/{account_id}/access/apps APIs.io Engineering Platform Add an Access application #
DELETE /accounts/{account_id}/access/apps/{app_id} APIs.io Engineering Platform Delete an Access application #
GET /accounts/{account_id}/access/apps/{app_id} APIs.io Engineering Platform Get an Access application #
PUT /accounts/{account_id}/access/apps/{app_id} APIs.io Engineering Platform Update an Access application #
POST /accounts/{account_id}/access/apps/{app_id}/revoke_tokens APIs.io Engineering Platform Revoke application tokens #
GET /accounts/{account_id}/access/apps/{app_id}/user_policy_checks APIs.io Engineering Platform Test Access policies #

Documentation

Specifications

Other Resources

🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-1ab188a6-cc1f-490d-9413-9c6da20918d0?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-0e94f581-cbc1-48e0-b594-1f6b3d07a328?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-4517d93a-e7f7-4dc2-b572-06762bbe14de?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-88f9ddbb-3115-47dc-b6e5-7fc6f1d2a190?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-3a12caae-4945-4df4-8ab9-bb6219ba7a9f?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-863b18f0-c2f2-4e32-a5fa-0d1e6ccf77a9?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-189876d1-f207-49a2-a4bc-5c67ae78cd19?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-c1e74fd9-3f84-4d95-943d-d645d6cb82f7?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-b002164d-6e8a-4b6d-b409-4929476e7818?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-508660fd-30b8-4c9c-aede-8edbac8a514d?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-da35e0ba-f1a9-42fe-a77a-56ff0a47e341?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-1d4df7d0-9c92-4fa8-946f-2110c2b3b48d?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-2af6f54f-d259-46c0-8f86-78856f5885cd?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-cc203f31-e7f6-42ec-ad34-c5c4cde58904?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-f19285da-48dd-4691-bbdf-f7d6bec157a3?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-aa69cacc-4bbf-4724-a1d4-78cdad57fee8?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-a5858f86-04d3-4e15-ae11-b42c7516688b?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-c2052341-766c-43c7-b1dc-ed4985e4606b?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-aa777c90-8271-4809-8eac-3ec39a9a899c?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-4d5957dc-df05-4216-a5fc-d46b3ba811d8?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-28d97617-fdba-46a5-ac3e-40f3d2e0fa57?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-7429b451-d812-4abc-b497-b763372cf5c5?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-b0eafdd0-adaa-48a2-a855-6a31beb86d83?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-209f34ef-13c1-400c-bca8-fcddb304aff5?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-fb2bbbb8-d4cc-48b1-a660-c8e158bfbbea?action=share&creator=35240

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/engineering-platform-access-applications-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

engineering-platform-access-applications-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: 'To get started using Cloudflare''s products and services via the API, refer to [how to interact with Cloudflare](https://developers.cloudflare.com/fundamentals/basic-tasks/interact-with-cloudflare/), which covers using tools like [Terraform](https://developers.cloudflare.com/terraform/#cloudflare-terraform) and the [official SDKs](https://developers.cloudflare.com/fundamentals/api/reference/sdks/) to maintain your Cloudflare resources.


    Using the Cloudflare API requires authentication so that Cloudflare knows who is making requests and what permissions you have. Create an API token to grant access to the API to perform actions.


    To create an API token, from the Cloudflare dashboard, go to My Profile > API Tokens and select Create Token. For more information on how to create and troubleshoot API tokens, refer to

    our [API fundamentals](https://developers.cloudflare.com/fundamentals/api/).


    Totally new to Cloudflare? [Start here](https://developers.cloudflare.com/fundamentals/get-started/).'
  license:
    name: BSD-3-Clause
    url: https://opensource.org/licenses/BSD-3-Clause
  title: APIs.io Engineering Platform Cloudflare Access Applications API
  version: 4.0.0
tags:
- name: Access Applications
paths:
  /accounts/{account_id}/access/apps:
    get:
      description: Lists all Access applications in an account.
      operationId: access-applications-list-access-applications
      parameters:
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: List Access applications response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_apps_components-schemas-response_collection'
          description: List Access applications response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform List Access applications
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Revoke'
      - 'Access: Apps and Policies Write'
      - 'Access: Apps and Policies Read'
    post:
      description: Adds a new application to Access.
      operationId: access-applications-add-an-application
      parameters:
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/access_app_request'
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Add an Access application response failure
        '201':
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/access_apps_components-schemas-single_response'
                - properties:
                    result:
                      $ref: '#/components/schemas/access_app_response'
          description: Add an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Add an Access application
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
  /accounts/{account_id}/access/apps/{app_id}:
    delete:
      description: Deletes an application from Access.
      operationId: access-applications-delete-an-access-application
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Delete an Access application response failure
        '202':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_id_response'
          description: Delete an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Delete an Access application
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
    get:
      description: Fetches information about an Access application.
      operationId: access-applications-get-an-access-application
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Get an Access application response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_apps_components-schemas-single_response'
          description: Get an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Get an Access application
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
      - 'Access: Apps and Policies Read'
    put:
      description: Updates an Access application.
      operationId: access-applications-update-an-access-application
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/access_app_request'
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Update an Access application response failure
        '200':
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/access_apps_components-schemas-single_response'
                - properties:
                    result:
                      $ref: '#/components/schemas/access_app_response'
          description: Update an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Update an Access application
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
  /accounts/{account_id}/access/apps/{app_id}/revoke_tokens:
    post:
      description: Revokes all tokens issued for an application.
      operationId: access-applications-revoke-service-tokens
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Revoke application tokens response failure
        '202':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_schemas-empty_response'
          description: Revoke application tokens response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Revoke application tokens
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Revoke'
      - 'Access: Apps and Policies Write'
  /accounts/{account_id}/access/apps/{app_id}/user_policy_checks:
    get:
      description: Tests if a specific user has permission to access an application.
      operationId: access-applications-test-access-policies
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Test Access policies response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_policy_check_response'
          description: Test Access policies response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Test Access policies
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
      - 'Access: Apps and Policies Read'
components:
  schemas:
    access_schemas-allow_authenticate_via_warp:
      description: When set to true, users can authenticate to this application using their WARP session.  When set to false this application will always require direct IdP authentication. This setting always overrides the organization setting for WARP authentication.
      example: true
      type: boolean
    access_tags:
      description: The tags you want assigned to an application. Tags are used to filter applications in the App Launcher dashboard.
      items:
        description: The tag associated with an application.
        example: engineers
        type: string
      type: array
    access_timestamp:
      example: '2014-01-01T05:20:00.12345Z'
      format: date-time
      type: string
    access_api-response-collection:
      allOf:
      - $ref: '#/components/schemas/access_api-response-common'
      - properties:
          result_info:
            $ref: '#/components/schemas/access_result_info'
      type: object
    access_approval_required:
      default: false
      description: Requires the user to request access from an administrator at the start of each session.
      example: true
      type: boolean
    access_bookmark_props:
      properties:
        app_launcher_visible:
          $ref: '#/components/schemas/access_app_launcher_visible'
        domain:
          description: The URL or domain of the bookmark.
          example: https://mybookmark.com
          type: string
        logo_url:
          $ref: '#/components/schemas/access_logo_url'
        name:
          $ref: '#/components/schemas/access_apps_components-schemas-name'
        tags:
          $ref: '#/components/schemas/access_tags'
        type:
          description: The application type.
          example: bookmark
          type: string
      title: Bookmark application
      type: object
    access_policy_req:
      properties:
        approval_groups:
          $ref: '#/components/schemas/access_approval_groups'
        approval_required:
          $ref: '#/components/schemas/access_approval_required'
        decision:
          $ref: '#/components/schemas/access_decision'
        exclude:
          $ref: '#/components/schemas/access_schemas-exclude'
        include:
          $ref: '#/components/schemas/access_include'
        isolation_required:
          $ref: '#/components/schemas/access_isolation_required'
        name:
          $ref: '#/components/schemas/access_policy_components-schemas-name'
        purpose_justification_prompt:
          $ref: '#/components/schemas/access_purpose_justification_prompt'
        purpose_justification_required:
          $ref: '#/components/schemas/access_purpose_justification_required'
        require:
          $ref: '#/components/schemas/access_schemas-require'
        session_duration:
          $ref: '#/components/schemas/access_components-schemas-session_duration'
      required:
      - name
      - decision
      - include
      type: object
    access_app_launcher_props:
      allOf:
      - $ref: '#/components/schemas/access_feature_app_props'
      - properties:
          domain:
            example: authdomain.cloudflareaccess.com
            readOnly: true
          name:
            default: App Launcher
            example: App Launcher
            readOnly: true
          type:
            description: The application type.
            example: app_launcher
            type: string
    access_vnc_props:
      allOf:
      - $ref: '#/components/schemas/access_self_hosted_props'
      - properties:
          type:
            description: The application type.
            example: vnc
            type: string
    access_allowed_origins:
      description: Allowed origins.
      example:
      - https://example.com
      items:
        type: string
      type: array
    access_messages:
      example: []
      items:
        properties:
          code:
            minimum: 1000
            type: integer
          message:
            type: string
        required:
        - code
        - message
        type: object
        uniqueItems: true
      type: array
    access_rule:
      oneOf:
      - $ref: '#/components/schemas/access_email_rule'
      - $ref: '#/components/schemas/access_email_list_rule'
      - $ref: '#/components/schemas/access_domain_rule'
      - $ref: '#/components/schemas/access_everyone_rule'
      - $ref: '#/components/schemas/access_ip_rule'
      - $ref: '#/components/schemas/access_ip_list_rule'
      - $ref: '#/components/schemas/access_certificate_rule'
      - $ref: '#/components/schemas/access_access_group_rule'
      - $ref: '#/components/schemas/access_azure_group_rule'
      - $ref: '#/components/schemas/access_github_organization_rule'
      - $ref: '#/components/schemas/access_gsuite_group_rule'
      - $ref: '#/components/schemas/access_okta_group_rule'
      - $ref: '#/components/schemas/access_saml_group_rule'
      - $ref: '#/components/schemas/access_service_token_rule'
      - $ref: '#/components/schemas/access_any_valid_service_token_rule'
      - $ref: '#/components/schemas/access_external_evaluation_rule'
      - $ref: '#/components/schemas/access_country_rule'
      - $ref: '#/components/schemas/access_authentication_method_rule'
      - $ref: '#/components/schemas/access_device_posture_rule'
      type: object
    access_schemas-empty_response:
      allOf:
      - properties:
          result:
            type:
            - object
            - 'null'
          success:
            enum:
            - true
            - false
            example: true
            type: boolean
    access_result_info:
      properties:
        count:
          description: Total number of results for the requested service
          example: 1
          type: number
        page:
          description: Current page within paginated list of results
          example: 1
          type: number
        per_page:
          description: Number of results per page of results
          example: 20
          type: number
        total_count:
          description: Total results available without any search parameters
          example: 2000
          type: number
      type: object
    access_app_req_embedded_policies:
      properties:
        policies:
          description: The policies that will apply to the application, in ascending order of precedence. Items can reference existing policies or create new policies exclusive to the application.
          items:
            oneOf:
            - $ref: '#/components/schemas/access_app_policy_link'
            - allOf:
              - description: A policy UID to link to this application.
              - $ref: '#/components/schemas/access_schemas-uuid'
            - allOf:
              - type: object
              - description: An application-scoped policy JSON. If the policy does not yet exist, it will be created.
                properties:
                  id:
                    $ref: '#/components/schemas/access_schemas-uuid'
              - $ref: '#/components/schemas/access_app_policy_request'
          type: array
      type: object
    access_schemas-aud:
      description: Audience tag.
      example: 737646a56ab1df6ec9bddc7e5ca84eaf3b0768850f3ffb5d74f1534911fe3893
      maxLength: 64
      readOnly: true
      type: string
    access_app_resp_embedded_policies:
      description: The policies that will apply to the application.
      properties:
        policies:
          items:
            $ref: '#/components/schemas/access_app_policy_response'
          type: array
      type: object
    access_enable_binding_cookie:
      default: false
      description: Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.
      type: boolean
    access_footer_links:
      description: The links in the App Launcher footer.
      example:
      - name: Cloudflare's Privacy Policy
        url: https://www.cloudflare.com/privacypolicy/
      items:
        properties:
          name:
            description: The hypertext in the footer link.
            example: Cloudflare's Privacy Policy
            type: string
          url:
            description: the hyperlink in the footer link.
            example: https://www.cloudflare.com/privacypolicy/
            type: string
        required:
        - name
        - url
        type: object
      type: array
    access_components-schemas-session_duration:
      default: 24h
      description: 'The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h.'
      example: 24h
      type: string
    access_authentication_method_rule:
      description: Enforce different MFA options
      properties:
        auth_method:
          properties:
            auth_method:
              description: The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2.
              example: mfa
              type: string
          required:
          - auth_method
          type: object
      required:
      - auth_method
      title: Authentication method
      type: object
    access_landing_page_design:
      description: The design of the App Launcher landing page shown to users when they log in.
      properties:
        button_color:
          $ref: '#/components/schemas/access_button_color'
        button_text_color:
          $ref: '#/components/schemas/access_button_text_color'
        image_url:
          $ref: '#/components/schemas/access_image_url'
        message:
          $ref: '#/components/schemas/access_message'
        title:
          $ref: '#/components/schemas/access_title'
      type: object
    access_scim_config_authentication_oauth_bearer_token:
      description: Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.
      properties:
        scheme:
          description: The authentication scheme to use when making SCIM requests to this application.
          enum:
          - oauthbearertoken
          type: string
        token:
          description: Token used to authenticate with the remote SCIM service.
          type: string
      required:
      - scheme
      - token
      title: OAuth Bearer Token
      type: object
    access_custom_non_identity_deny_url:
      description: The custom URL a user is redirected to when they are denied access to the application when failing non-identity rules.
      type: string
    access_domain_rule:
      description: Match an entire email domain.
      properties:
        email_domain:
          properties:
            domain:
              description: The email domain to match.
              example: example.com
              type: string
          required:
          - domain
          type: object
      required:
      - email_domain
      title: Email domain
      type: object
    access_self_hosted_props:
      properties:
        allow_authenticate_via_warp:
          $ref: '#/components/schemas/access_schemas-allow_authenticate_via_warp'
        allowed_idps:
          $ref: '#/components/schemas/access_allowed_idps'
        app_launcher_visible:
          $ref: '#/components/schemas/access_app_launcher_visible'
        auto_redirect_to_identity:
          $ref: '#/components/schemas/access_schemas-auto_redirect_to_identity'
        cors_headers:
          $ref: '#/components/schemas/access_cors_headers'
        custom_deny_message:
          $ref: '#/components/schemas/access_custom_deny_message'
        custom_deny_url:
          $ref: '#/components/schemas/access_custom_deny_url'
        custom_non_identity_deny_url:
          $ref: '#/components/schemas/access_custom_non_identity_deny_url'
        custom_pages:
          $ref: '#/components/schemas/access_schemas-custom_pages'
        domain:
          $ref: '#/components/schemas/access_domain'
        enable_binding_cookie:
          $ref: '#/components/schemas/access_enable_binding_cookie'
        http_only_cookie_attribute:
          $ref: '#/components/schemas/access_http_only_cookie_attribute'
        logo_url:
          $ref: '#/components/schemas/access_logo_url'
        name:
          $ref: '#/components/schemas/access_apps_components-schemas-name'
        options_preflight_bypass:
          $ref: '#/components/schemas/access_options_preflight_bypass'
        path_cookie_attribute:
          $ref: '#/components/schemas/access_path_cookie_attribute'
        same_site_cookie_attribute:
          $ref: '#/components/schemas/access_same_site_cookie_attribute'
        self_hosted_domains:
          $ref: '#/components/schemas/access_self_hosted_domains'
        service_auth_401_redirect:
          $ref: '#/components/schemas/access_service_auth_401_redirect'
        session_duration:
          $ref: '#/components/schemas/access_schemas-session_duration'
        skip_interstitial:
          $ref: '#/components/schemas/access_skip_interstitial'
        tags:
          $ref: '#/components/schemas/access_tags'
        type:
          description: The application type.
          example: self_hosted
          type: string
      required:
      - type
      - domain
      title: Self Hosted Application
      type: object
    access_any_valid_service_token_rule:
      description: Matches any valid Access Service Token
      properties:
        any_valid_service_token:
          description: An empty object which matches on all service tokens.
          example: {}
          type: object
      required:
      - any_valid_service_token
      title: Any Valid Service Token
      type: object
    access_api-response-single:
      allOf:
      - $ref: '#/components/schemas/access_api-response-common'
      type: object
    access_skip_app_launcher_login_page:
      default: false
      description: Determines when to skip the App Launcher landing page.
      example: true
      type: boolean
    access_id_response:
      allOf:
      - $ref: '#/components/schemas/access_api-response-single'
      - properties:
          result:
            properties:
              id:
                $ref: '#/components/schemas/access_uuid'
            type: object
    access_app_launcher_visible:
      default: true
      description: Displays the application in the App Launcher.
      example: true
      type: boolean
    access_schemas-session_duration:
      default: 24h
      description: 'The amount of time that tokens issued for this application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h.'
      example: 24h
      type: string
    access_uuid:
      description: UUID
      example: f174e90a-fafe-4643-bbbc-4a0ed4fc8415
      maxLength: 36
      type: string
    access_app_request:
      anyOf:
      - allOf:
        - $ref: '#/components/schemas/access_self_hosted_props'
        - $ref: '#/components/schemas/access_app_req_embedded_policies'
        - $ref: '#/components/schemas/access_app_req_embedded_scim_config'
        title: Self Hosted Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_saas_props'
        - $ref: '#/components/schemas/access_app_req_embedded_policies'
        - $ref: '#/components/schemas/access_app_req_embedded_scim_config'
        title: SaaS Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_ssh_props'
        - $ref: '#/components/schemas/access_app_req_embedded_policies'
        - $ref: '#/components/schemas/access_app_req_embedded_scim_config'
        title: Browser SSH Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_vnc_props'
        - $ref: '#/components/schemas/access_app_req_embedded_policies'
        - $ref: '#/components/schemas/access_app_req_embedded_scim_config'
        title: Browser VNC Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_app_launcher_props'
        - $ref: '#/components/schemas/access_app_req_embedded_policies'
        - $ref: '#/components/schemas/access_app_req_embedded_scim_config'
        title: App Launcher Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_warp_props'
        - $ref: '#/components/schemas/access_app_req_embedded_policies'
        - $ref: '#/components/schemas/access_app_req_embedded_scim_config'
        title: Device Enrollment Permissions Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_biso_props'
        - $ref: '#/components/schemas/access_app_req_embedded_policies'
        - $ref: '#/components/schemas/access_app_req_embedded_scim_config'
        title: Browser Isolation Permissions Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_bookmark_props'
        - $ref: '#/components/schemas/access_app_req_embedded_scim_config'
        title: Bookmark application
        type: object
    access_identifier:
      description: Identifier
      example: 023e105f4ecef8ad9ca31a8372d0c353
      maxLength: 32
      type: string
    access_saas_props:
      properties:
        allowed_idps:
          $ref: '#/components/schemas/access_allowed_idps'
        app_launcher_visible:
          $ref: '#/components/schemas/access_app_launcher_visible'
        auto_redirect_to_identity:
          $ref: '#/components/schemas/access_schemas-auto_redirect_to_identity'
        custom_pages:
          $ref: '#/components/schemas/access_schemas-custom_pages'
        logo_url:
          $ref: '#/components/schemas/access_logo_url'
        name:
          $ref: '#/components/schemas/access_apps_components-schemas-name'
        saas_app:
          oneOf:
          - $ref: '#/components/schemas/access_saml_saas_app'
          - $ref: '#/components/schemas/access_oidc_saas_app'
          type: object
        tags:
          $ref: '#/components/schemas/access_tags'
        type:
          description: The application type.
          example: saas
          type: string
      title: SaaS Application
      type: object
    access_policy_check_response:
      allOf:
      - $ref: '#/components/schemas/access_api-response-single'
      - properties:
          result:
            properties:
              app_state:
                properties:
                  app_uid:
                    $ref: '#/components/schemas/access_uuid'
                  aud:
                    example: 737646a56ab1df6ec9bddc7e5ca84eaf3b0768850f3ffb5d74f1534911fe389
                    type: string
                  hostname:
                    example: test.com
                    type: string
                  name:
                    example: Test App
                    type: string
                  policies:
                    example:
                    - decision: allow
                      exclude: []
                      include:
                      - _type: email
                        email: testuser@gmail.com
                      precedence: 0
                      require: []
                      status: Success
                    items:
                      type: object
                    type: array
                  status:
                    example: Success
                    type: string
                type: object
              user_identity:
                properties:
                  account_id:
                    example: 41ecfbb341f033e52b46742756aabb8b
                    type: string
                  device_sessions:
                    example: {}
                    type: object
                  email:
                    example: testuser@gmail.com
                    type: string
                  geo:
                    properties:
                      country:
                        example: US
                        type: string
                    type: object
                  iat:
                    type: integer
                  id:
                    example: '1164449231815010287495'
                    type: string
                  is_gateway:
                    example: false
                    type: boolean
                  is_warp:
                    example: false
                    type: boolean
                  name:
                    example: Test User
                    type: string
                  user_uuid:
                    $ref: '#/components/schemas/access_uuid'
                  version:
                    type: integer
                type: object
            type: object
    access_schemas-require:
      description: Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.
      items:
        $ref: '#/components/schemas/access_rule'
      type: array
    access_allow_all_headers:
      description: Allows all HTTP request headers.
      example: true
      type: boolean
    access_purpose_justification_prompt:
      description: A custom message that will appear on the purpose justification screen.
      example: Please enter a justification for entering this protected domain.
      type: string
    access_everyone_rule:
      description: Matches everyone.
      properties:
        everyone:
          description: An empty object which matches on all users.
          example: {}
          type: object
      required:
      - everyone
      title: Everyone
      type: object
    access_access_group_rule:
      description: Matches an Access group.
      properties:
        group:
          properties:
            id:
              description: The ID of a previously created Access group.
              example: aa0a4aab-672b-4bdb-bc33-a59f1130a11f
              type: string
          required:
          - id
          type: object
      required:
      - group
      title: Access groups
      type: object
    access_allowed_headers:
      description: Allowed HTTP request headers.
      items:
        type: string
      type: array
    access_service_auth_401_redirect:
      description: Returns a 401 status code when the request is blocked by a Service Auth policy.
      example: true
      type: boolean
    access_button_text_color:
      description: The color of the text in the log in button on the landing page.
      example: '#ff0000'
      type: string
    access_allow_all_origins:
      description: Allows all origins.
      type: boolean
    access_cors_headers:
      properties:
        allow_all_headers:
          $ref: '#/components/schemas/access_allow_all_headers'
        allow_all_methods:
          

# --- truncated at 32 KB (71 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/engineering-platform/refs/heads/main/openapi/engineering-platform-access-applications-api-openapi.yml