APIs.io Engineering Platform Zone-Level Access Applications API

The Zone-Level Access Applications API from APIs.io Engineering Platform — 4 operation(s) for zone-level access applications.

Operations 7

GET /zones/{zone_id}/access/apps APIs.io Engineering Platform List Access Applications #
POST /zones/{zone_id}/access/apps APIs.io Engineering Platform Add an Access application #
DELETE /zones/{zone_id}/access/apps/{app_id} APIs.io Engineering Platform Delete an Access application #
GET /zones/{zone_id}/access/apps/{app_id} APIs.io Engineering Platform Get an Access application #
PUT /zones/{zone_id}/access/apps/{app_id} APIs.io Engineering Platform Update an Access application #
POST /zones/{zone_id}/access/apps/{app_id}/revoke_tokens APIs.io Engineering Platform Revoke application tokens #
GET /zones/{zone_id}/access/apps/{app_id}/user_policy_checks APIs.io Engineering Platform Test Access policies #

Documentation

Specifications

Other Resources

🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-1ab188a6-cc1f-490d-9413-9c6da20918d0?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-0e94f581-cbc1-48e0-b594-1f6b3d07a328?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-4517d93a-e7f7-4dc2-b572-06762bbe14de?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-88f9ddbb-3115-47dc-b6e5-7fc6f1d2a190?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-3a12caae-4945-4df4-8ab9-bb6219ba7a9f?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-863b18f0-c2f2-4e32-a5fa-0d1e6ccf77a9?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-189876d1-f207-49a2-a4bc-5c67ae78cd19?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-c1e74fd9-3f84-4d95-943d-d645d6cb82f7?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-b002164d-6e8a-4b6d-b409-4929476e7818?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-508660fd-30b8-4c9c-aede-8edbac8a514d?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-da35e0ba-f1a9-42fe-a77a-56ff0a47e341?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-1d4df7d0-9c92-4fa8-946f-2110c2b3b48d?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-2af6f54f-d259-46c0-8f86-78856f5885cd?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-cc203f31-e7f6-42ec-ad34-c5c4cde58904?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-f19285da-48dd-4691-bbdf-f7d6bec157a3?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-aa69cacc-4bbf-4724-a1d4-78cdad57fee8?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-a5858f86-04d3-4e15-ae11-b42c7516688b?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-c2052341-766c-43c7-b1dc-ed4985e4606b?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-aa777c90-8271-4809-8eac-3ec39a9a899c?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-4d5957dc-df05-4216-a5fc-d46b3ba811d8?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-28d97617-fdba-46a5-ac3e-40f3d2e0fa57?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-7429b451-d812-4abc-b497-b763372cf5c5?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-b0eafdd0-adaa-48a2-a855-6a31beb86d83?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-209f34ef-13c1-400c-bca8-fcddb304aff5?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-fb2bbbb8-d4cc-48b1-a660-c8e158bfbbea?action=share&creator=35240

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/engineering-platform-zone-level-access-applications-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

engineering-platform-zone-level-access-applications-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: 'To get started using Cloudflare''s products and services via the API, refer to [how to interact with Cloudflare](https://developers.cloudflare.com/fundamentals/basic-tasks/interact-with-cloudflare/), which covers using tools like [Terraform](https://developers.cloudflare.com/terraform/#cloudflare-terraform) and the [official SDKs](https://developers.cloudflare.com/fundamentals/api/reference/sdks/) to maintain your Cloudflare resources.


    Using the Cloudflare API requires authentication so that Cloudflare knows who is making requests and what permissions you have. Create an API token to grant access to the API to perform actions.


    To create an API token, from the Cloudflare dashboard, go to My Profile > API Tokens and select Create Token. For more information on how to create and troubleshoot API tokens, refer to

    our [API fundamentals](https://developers.cloudflare.com/fundamentals/api/).


    Totally new to Cloudflare? [Start here](https://developers.cloudflare.com/fundamentals/get-started/).'
  license:
    name: BSD-3-Clause
    url: https://opensource.org/licenses/BSD-3-Clause
  title: APIs.io Engineering Platform Cloudflare Zone-Level Access Applications API
  version: 4.0.0
tags:
- name: Zone-Level Access Applications
paths:
  /zones/{zone_id}/access/apps:
    get:
      description: List all Access Applications in a zone.
      operationId: zone-level-access-applications-list-access-applications
      parameters:
      - in: path
        name: zone_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: List Access Applications response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_apps_components-schemas-response_collection-2'
          description: List Access Applications response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform List Access Applications
      tags:
      - Zone-Level Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Revoke'
      - 'Access: Apps and Policies Write'
      - 'Access: Apps and Policies Read'
    post:
      description: Adds a new application to Access.
      operationId: zone-level-access-applications-add-a-bookmark-application
      parameters:
      - in: path
        name: zone_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/access_apps'
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Add an Access application response failure
        '201':
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/access_apps_components-schemas-single_response-2'
                - properties:
                    result:
                      $ref: '#/components/schemas/access_apps'
          description: Add an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Add an Access application
      tags:
      - Zone-Level Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
  /zones/{zone_id}/access/apps/{app_id}:
    delete:
      description: Deletes an application from Access.
      operationId: zone-level-access-applications-delete-an-access-application
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: zone_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Delete an Access application response failure
        '202':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_id_response'
          description: Delete an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Delete an Access application
      tags:
      - Zone-Level Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
    get:
      description: Fetches information about an Access application.
      operationId: zone-level-access-applications-get-an-access-application
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: zone_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Get an Access application response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_apps_components-schemas-single_response-2'
          description: Get an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Get an Access application
      tags:
      - Zone-Level Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
      - 'Access: Apps and Policies Read'
    put:
      description: Updates an Access application.
      operationId: zone-level-access-applications-update-a-bookmark-application
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: zone_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/access_apps'
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Update an Access application response failure
        '200':
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/access_apps_components-schemas-single_response-2'
                - properties:
                    result:
                      $ref: '#/components/schemas/access_apps'
          description: Update an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Update an Access application
      tags:
      - Zone-Level Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
  /zones/{zone_id}/access/apps/{app_id}/revoke_tokens:
    post:
      description: Revokes all tokens issued for an application.
      operationId: zone-level-access-applications-revoke-service-tokens
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: zone_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Revoke application tokens response failure
        '202':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_schemas-empty_response'
          description: Revoke application tokens response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Revoke application tokens
      tags:
      - Zone-Level Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Revoke'
      - 'Access: Apps and Policies Write'
  /zones/{zone_id}/access/apps/{app_id}/user_policy_checks:
    get:
      description: Tests if a specific user has permission to access an application.
      operationId: zone-level-access-applications-test-access-policies
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: zone_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Test Access policies response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_schemas-policy_check_response'
          description: Test Access policies response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Test Access policies
      tags:
      - Zone-Level Access Applications
components:
  schemas:
    access_schemas-warp_props:
      allOf:
      - $ref: '#/components/schemas/access_schemas-feature_app_props'
      - properties:
          domain:
            example: authdomain.cloudflareaccess.com/warp
            readOnly: true
          name:
            default: Warp Login App
            example: Warp Login App
            readOnly: true
          type:
            description: The application type.
            example: warp
            type: string
    access_id_response:
      allOf:
      - $ref: '#/components/schemas/access_api-response-single'
      - properties:
          result:
            properties:
              id:
                $ref: '#/components/schemas/access_uuid'
            type: object
    access_schemas-allowed_headers:
      description: Allowed HTTP request headers.
      items: {}
      type: array
    access_schemas-session_duration:
      default: 24h
      description: 'The amount of time that tokens issued for this application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h.'
      example: 24h
      type: string
    access_app_launcher_visible:
      default: true
      description: Displays the application in the App Launcher.
      example: true
      type: boolean
    access_timestamp:
      example: '2014-01-01T05:20:00.12345Z'
      format: date-time
      type: string
    access_apps_components-schemas-single_response-2:
      allOf:
      - $ref: '#/components/schemas/access_api-response-single'
      - properties:
          result:
            $ref: '#/components/schemas/access_apps'
    access_allowed_idps:
      description: The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.
      items:
        description: The identity providers selected for application.
        example: 699d98642c564d2e855e9661899b7252
        type: string
      type: array
    access_uuid:
      description: UUID
      example: f174e90a-fafe-4643-bbbc-4a0ed4fc8415
      maxLength: 36
      type: string
    access_apps_components-schemas-response_collection-2:
      allOf:
      - $ref: '#/components/schemas/access_api-response-collection'
      - properties:
          result:
            items:
              $ref: '#/components/schemas/access_apps'
            type: array
    access_api-response-collection:
      allOf:
      - $ref: '#/components/schemas/access_api-response-common'
      - properties:
          result_info:
            $ref: '#/components/schemas/access_result_info'
      type: object
    access_allow_all_methods:
      description: Allows all HTTP request methods.
      type: boolean
    access_identifier:
      description: Identifier
      example: 023e105f4ecef8ad9ca31a8372d0c353
      maxLength: 32
      type: string
    access_http_only_cookie_attribute:
      default: true
      description: Enables the HttpOnly cookie attribute, which increases security against XSS attacks.
      example: true
      type: boolean
    access_schemas-app_launcher_props:
      allOf:
      - $ref: '#/components/schemas/access_schemas-feature_app_props'
      - properties:
          domain:
            example: authdomain.cloudflareaccess.com
            readOnly: true
          name:
            default: App Launcher
            example: App Launcher
            readOnly: true
          type:
            description: The application type.
            example: app_launcher
            type: string
    access_schemas-vnc_props:
      allOf:
      - $ref: '#/components/schemas/access_schemas-self_hosted_props'
      - properties:
          type:
            description: The application type.
            example: vnc
            type: string
    access_schemas-oidc_saas_app:
      properties:
        access_token_lifetime:
          description: The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h.
          example: 5m
          type: string
        allow_pkce_without_client_secret:
          description: If client secret should be required on the token endpoint when authorization_code_with_pkce grant is used.
          example: true
          type: boolean
        app_launcher_url:
          description: The URL where this applications tile redirects users
          example: https://example.com/login
          type: string
        auth_type:
          description: Identifier of the authentication protocol used for the saas app. Required for OIDC.
          enum:
          - saml
          - oidc
          example: oidc
          type: string
        client_id:
          description: The application client id
          example: oidc client id
          type: string
        client_secret:
          description: The application client secret, only returned on POST request.
          example: oidc client secret
          type: string
        created_at:
          $ref: '#/components/schemas/access_timestamp'
        custom_claims:
          properties:
            name:
              description: The name of the claim.
              example: family_name
              type: string
            required:
              description: If the claim is required when building an OIDC token.
              example: true
              type: boolean
            scope:
              description: The scope of the claim.
              enum:
              - groups
              - profile
              - email
              - openid
              example: profile
              type: string
            source:
              properties:
                name:
                  description: The name of the IdP claim.
                  example: last_name
                  type: string
                name_by_idp:
                  additionalProperties:
                    type: string
                  description: A mapping from IdP ID to claim name.
                  example:
                    exampleIdPID1: ClaimName1
                    exampleIdPID2: ClaimName2
                  type: object
              type: object
          type: object
        grant_types:
          description: The OIDC flows supported by this application
          example:
          - authorization_code
          items:
            enum:
            - authorization_code
            - authorization_code_with_pkce
            - refresh_tokens
            - hybrid
            - implicit
            type: string
          type: array
        group_filter_regex:
          description: A regex to filter Cloudflare groups returned in ID token and userinfo endpoint.
          example: ^GROUP_FILTER-*$
          type: string
        hybrid_and_implicit_options:
          properties:
            return_access_token_from_authorization_endpoint:
              description: If an Access Token should be returned from the OIDC Authorization endpoint
              type: boolean
            return_id_token_from_authorization_endpoint:
              description: If an ID Token should be returned from the OIDC Authorization endpoint
              type: boolean
          type: object
        public_key:
          description: The Access public certificate that will be used to verify your identity.
          example: example unique name
          type: string
        redirect_uris:
          description: The permitted URL's for Cloudflare to return Authorization codes and Access/ID tokens
          example:
          - https://example.com
          items:
            type: string
          type: array
        refresh_token_options:
          properties:
            lifetime:
              description: How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m.
              example: 30d
              type: string
          type: object
        scopes:
          description: Define the user information shared with access, "offline_access" scope will be automatically enabled if refresh tokens are enabled
          example:
          - openid
          - groups
          - email
          - profile
          items:
            enum:
            - openid
            - groups
            - email
            - profile
            type: string
          type: array
        updated_at:
          $ref: '#/components/schemas/access_timestamp'
      title: OIDC SaaS App
      type: object
    access_schemas-biso_props:
      allOf:
      - $ref: '#/components/schemas/access_schemas-feature_app_props'
      - properties:
          domain:
            example: authdomain.cloudflareaccess.com/browser
            readOnly: true
          name:
            default: Clientless Web Isolation
            example: Clientless Web Isolation
            readOnly: true
          type:
            description: The application type.
            example: biso
            type: string
    access_options_preflight_bypass:
      description: Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors_headers is set.
      example: true
      type: boolean
    access_api-response-single:
      allOf:
      - $ref: '#/components/schemas/access_api-response-common'
      type: object
    access_schemas-cors_headers:
      properties:
        allow_all_headers:
          $ref: '#/components/schemas/access_allow_all_headers'
        allow_all_methods:
          $ref: '#/components/schemas/access_allow_all_methods'
        allow_all_origins:
          $ref: '#/components/schemas/access_allow_all_origins'
        allow_credentials:
          $ref: '#/components/schemas/access_allow_credentials'
        allowed_headers:
          $ref: '#/components/schemas/access_schemas-allowed_headers'
        allowed_methods:
          $ref: '#/components/schemas/access_allowed_methods'
        allowed_origins:
          $ref: '#/components/schemas/access_schemas-allowed_origins'
        max_age:
          $ref: '#/components/schemas/access_max_age'
      type: object
    access_schemas-feature_app_props:
      properties:
        allowed_idps:
          $ref: '#/components/schemas/access_allowed_idps'
        auto_redirect_to_identity:
          $ref: '#/components/schemas/access_schemas-auto_redirect_to_identity'
        domain:
          $ref: '#/components/schemas/access_components-schemas-domain'
        name:
          $ref: '#/components/schemas/access_apps_components-schemas-name'
        session_duration:
          $ref: '#/components/schemas/access_schemas-session_duration'
        type:
          $ref: '#/components/schemas/access_type'
      required:
      - type
      type: object
    access_schemas-auto_redirect_to_identity:
      default: false
      description: When set to `true`, users skip the identity provider selection step during login. You must specify only one identity provider in allowed_idps.
      type: boolean
    access_allow_all_headers:
      description: Allows all HTTP request headers.
      example: true
      type: boolean
    access_same_site_cookie_attribute:
      description: Sets the SameSite cookie setting, which provides increased security against CSRF attacks.
      example: strict
      type: string
    access_api-response-common-failure:
      properties:
        errors:
          allOf:
          - $ref: '#/components/schemas/access_messages'
          example:
          - code: 7003
            message: No route for the URI
          minLength: 1
        messages:
          allOf:
          - $ref: '#/components/schemas/access_messages'
          example: []
        result:
          enum:
          - null
          type:
          - object
          - 'null'
        success:
          description: Whether the API call was successful
          enum:
          - false
          example: false
          type: boolean
      required:
      - success
      - errors
      - messages
      - result
      type: object
    access_schemas-bookmark_props:
      properties:
        app_launcher_visible:
          default: true
        domain:
          description: The URL or domain of the bookmark.
          example: https://mybookmark.com
        logo_url:
          $ref: '#/components/schemas/access_logo_url'
        name:
          $ref: '#/components/schemas/access_apps_components-schemas-name'
        type:
          description: The application type.
          example: bookmark
          type: string
      required:
      - type
      - domain
      title: Bookmark Application
      type: object
    access_skip_interstitial:
      description: Enables automatic authentication through cloudflared.
      example: true
      type: boolean
    access_app_id:
      oneOf:
      - $ref: '#/components/schemas/access_identifier'
      - $ref: '#/components/schemas/access_uuid'
    access_messages:
      example: []
      items:
        properties:
          code:
            minimum: 1000
            type: integer
          message:
            type: string
        required:
        - code
        - message
        type: object
        uniqueItems: true
      type: array
    access_schemas-empty_response:
      allOf:
      - properties:
          result:
            type:
            - object
            - 'null'
          success:
            enum:
            - true
            - false
            example: true
            type: boolean
    access_schemas-saas_props:
      properties:
        allowed_idps:
          $ref: '#/components/schemas/access_allowed_idps'
        app_launcher_visible:
          $ref: '#/components/schemas/access_app_launcher_visible'
        auto_redirect_to_identity:
          $ref: '#/components/schemas/access_schemas-auto_redirect_to_identity'
        logo_url:
          $ref: '#/components/schemas/access_logo_url'
        name:
          $ref: '#/components/schemas/access_apps_components-schemas-name'
        saas_app:
          oneOf:
          - $ref: '#/components/schemas/access_schemas-saml_saas_app'
          - $ref: '#/components/schemas/access_schemas-oidc_saas_app'
          type: object
        type:
          description: The application type.
          example: saas
          type: string
      title: SaaS Application
      type: object
    access_result_info:
      properties:
        count:
          description: Total number of results for the requested service
          example: 1
          type: number
        page:
          description: Current page within paginated list of results
          example: 1
          type: number
        per_page:
          description: Number of results per page of results
          example: 20
          type: number
        total_count:
          description: Total results available without any search parameters
          example: 2000
          type: number
      type: object
    access_api-response-common:
      properties:
        errors:
          $ref: '#/components/schemas/access_messages'
        messages:
          $ref: '#/components/schemas/access_messages'
        success:
          description: Whether the API call was successful
          enum:
          - true
          example: true
          type: boolean
      required:
      - success
      - errors
      - messages
      type: object
    access_schemas-aud:
      description: Audience tag.
      example: 737646a56ab1df6ec9bddc7e5ca84eaf3b0768850f3ffb5d74f1534911fe3893
      maxLength: 64
      readOnly: true
      type: string
    access_service_auth_401_redirect:
      description: Returns a 401 status code when the request is blocked by a Service Auth policy.
      example: true
      type: boolean
    access_schemas-basic_app_response_props:
      properties:
        aud:
          $ref: '#/components/schemas/access_schemas-aud'
        created_at:
          $ref: '#/components/schemas/access_timestamp'
        id:
          $ref: '#/components/schemas/access_uuid'
        scim_config:
          $ref: '#/components/schemas/access_schemas-scim_config'
        updated_at:
          $ref: '#/components/schemas/access_timestamp'
      type: object
    access_allow_all_origins:
      description: Allows all origins.
      type: boolean
    access_components-schemas-domain:
      description: The domain and path that Access will secure.
      example: test.example.com/admin
      type: string
    access_max_age:
      description: The maximum number of seconds the results of a preflight request can be cached.
      example: -1
      maximum: 86400
      minimum: -1
      type: number
    access_schemas-allowed_origins:
      description: Allowed origins.
      example:
      - https://example.com
      items: {}
      type: array
    access_schemas-custom_deny_url:
      description: The custom URL a user is redirected to when they are denied access to the application.
      type: string
    access_enable_binding_cookie:
      default: false
      description: Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.
      type: boolean
    access_custom_deny_message:
      description: The custom error message shown to a user when they are denied access to the application.
      type: string
    access_schemas-self_hosted_props:
      properties:
        allowed_idps:
          $ref: '#/components/schemas/access_allowed_idps'
        app_launcher_visible:
          $ref: '#/components/schemas/access_app_launcher_visible'
        auto_redirect_to_identity:
          $ref: '#/components/schemas/access_schemas-auto_redirect_to_identity'
        cors_headers:
          $ref: '#/components/schemas/access_schemas-cors_headers'
        custom_deny_message:
          $ref: '#/components/schemas/access_custom_deny_message'
        custom_deny_url:
          $ref: '#/components/schemas/access_schemas-custom_deny_url'
        domain:
          $ref: '#/components/schemas/access_components-schemas-domain'
        enable_binding_cookie:
          $ref: '#/components/schemas/access_enable_binding_cookie'
        http_only_cookie_attribute:
          $ref: '#/components/schemas/access_http_only_cookie_attribute'
        logo_url:
          $ref: '#/components/schemas/access_logo_url'
        name:
          $ref: '#/components/schemas/access_apps_components-schemas-name'
        options_preflight_bypass:
          $ref: '#/components/schemas/access_options_preflight_bypass'
        same_site_cookie_attribute:
          $ref: '#/components/schemas/access_same_site_cookie_attribute'
        service_auth_401_redirect:
          $ref: '#/components/schemas/access_service_auth_401_redirect'
        session_duration:
          $ref: '#/components/schemas/access_schemas-session_duration'
        skip_interstitial:
          $ref: '#/components/schemas/access_skip_interstitial'
        type:
          description: The application type.
          example: self_hosted
          type: string
      required:
      - type
      - domain
      title: Self Hosted Application
      type: object
    access_type:
      description: The application type.
      enum:
      - self_hosted
      - saas
      - ssh
      - vnc
      - app_launcher
      - warp
      - biso
      - bookmark
      - dash_sso
      example: self_hosted
      type: string
    access_schemas-scim_config:
      description: Configuration for provisioning to this application via SCIM. This is currently in closed beta.
      properties:
        authentication:
          oneOf:
          - $ref: '#/components/schemas/access_scim_config_authentication_http_basic'
          - $ref: '#/components/schemas/access_scim_config_authentication_oauth_bearer_token'
          - $ref: '#/components/schemas/access_scim_config_authentication_oauth2'
        deactivate_on_delete:
          description: If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set `active` to false on the SCIM resource. This is useful because some targets do not support DELETE operations.
          type: boolean
        enabled:
          description: Whether SCIM provisioning is turned on for this application.
          type: boolean
        idp_uid:
          description: The UID of the IdP to use as the source for SCIM resources to provision to this application.
          type: string
        mappings:
          description: A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.
          items:
            $ref: '#/components/schemas/access_scim_config_mapping'
          type: array
        remote_uri:
          description: The base URI for the application's SCIM-compatible API.
          type: string
      required:
      - remote_uri
      - idp_uid
      type: object
    access_scim_config_mapping:
      description: Transformations and filters applied to resources before they are provisioned in the remote SCIM service.
      properties:
        enabled:
          description: Whether or not this mapping is enabled.
          type: boolean
        filter:
          description: A [SCIM filter expression](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2) that matches resources that should be provisioned to this application.
          example: title pr or userType eq "Intern"
          type: string
        operations:
          description: Whether or not this mapping applies to creates, updates, or deletes.
          properties:
            create:
              description: Whether or not this mapping applies to create (POST) operations.
              type: boolean
            delete:
              description: Whether or not this mapping applies to DELETE operations.
              type: boolean
            update:
              description: Whether or not this mapping applies to update (PATCH/PUT) operations.
              type: boolean
          type: object
        schema:
          description: Which SCIM resource type this mapping applies to.
          example: urn:ietf:params:scim:schemas:core:2.0:User
          type: string
        transform_jsonata:
          description: A [JSONata](https://jsonata.org/) expression that transforms the resource before provisioning it in the application.
          example: '$merge([$, {''userName'': $substringBefore($.userName, ''@'') & ''+test@'' & $substringAfter($.userName, ''@'')}])'
          type: string
      required:
      - schema
      type: object
    access_scim_config_authentication_oauth2:
      description: Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an a

# --- truncated at 32 KB (43 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/engineering-platform/refs/heads/main/openapi/engineering-platform-zone-level-access-applications-api-openapi.yml