コンテンツにスキップ

APIトークンの権限

権限はリソースに基づいて3つのカテゴリに分けられています:

  • ゾーン権限
  • アカウント権限
  • ユーザー権限

各カテゴリには、それぞれのリソースに関連する権限グループが含まれています。DNS権限はゾーンカテゴリに属し、請求権限はアカウントカテゴリに属します。以下は利用可能なトークン権限のリストです。

権限IDと各権限のスコープを含む更新されたトークン権限のリストを取得するには、権限グループのリストエンドポイントを使用してください。

ユーザー権限

ユーザー権限の適用スコープはcom.cloudflare.api.userです。

NameDescription
API Tokens ReadGrants read access to user’s API tokens.
API Tokens 編集Grants write access to user’s API tokens.
Memberships ReadGrants read access to a user’s account memberships.
Memberships 編集Grants write access to a user’s account memberships.
User Details ReadGrants read access to user details.
User Details 編集Grants write access to user details.

アカウント権限

アカウント権限の適用スコープはcom.cloudflare.api.accountです。

NameDescription
Access: Apps and Policies ReadGrants read access to Cloudflare Access account resources.
Access: Apps and Policies RevokeGrants ability to revoke all tokens to Cloudflare Access account resources.
Access: Apps and Policies 編集Grants write access to Cloudflare Access account resources.
Access: Audit Logs ReadGrants read access to Cloudflare Access audit logs.
Access: Custom Pages ReadGrants read access to Cloudflare Access Custom Pages.
Access: Custom Pages 編集Grants write access to Cloudflare Access Custom Pages.
Access: Device Posture ReadGrants read access to Cloudflare Access Device Posture.
Access: Device Posture 編集Grants write access to Cloudflare Access Device Posture.
Access: Mutual TLS Certificates ReadGrants read access to Cloudflare Access mTLS certificates.
Access: Mutual TLS Certificates 編集Grants write access to Cloudflare Access mTLS certificates.
Access: Organizations, Identity Providers, and Groups ReadGrants read access to Cloudflare Access account resources.
Access: Organizations, Identity Providers, and Groups RevokeGrants ability to revoke user sessions to Cloudflare Access account resources.
Access: Organizations, Identity Providers, and Groups 編集Grants write access to Cloudflare Access account resources.
Access: Service Tokens ReadGrants read access to Cloudflare Access Service Tokens.
Access: Service Tokens 編集Grants write access to Cloudflare Access Service Tokens.
Access: SSH Auditing ReadGrants read access to SSH Auditing.
Access: SSH Auditing 編集Grants write access to SSH Auditing.
Account Analytics ReadGrants read access to account analytics.
Account Custom Pages ReadGrants read access to account-level Custom Pages.
Account Custom Pages 編集Grants write access to account-level Custom Pages.
Account Filter Lists ReadGrants read access to Account Filter Lists.
Account Filter Lists 編集Grants write access to Account Filter Lists.
Account Firewall Access Rules ReadGrants read access to account firewall access rules.
Account Firewall Access Rules 編集Grants write access to account firewall access rules.
Account Rulesets ReadGrants read access to Account Rulesets.
Account Rulesets 編集Grants write access to Account Rulesets.
Account Settings ReadGrants read access to Account resources, account membership, and account level features.
Account Settings 編集Grants write access to Account resources, account membership, and account level features.
Account: SSL and Certificates ReadGrants read access to SSL and Certificates.
Account: SSL and Certificates 編集Grants write access to SSL and Certificates.
Account WAF ReadGrants read access to Account WAF.
Account WAF 編集Grants write access to Account WAF.
Address Maps 編集Grants write access to Address Maps
Address Maps ReadGrants read access to Address Maps
Allow Request Tracer ReadGrants read access to Request Tracer.
API Gateway ReadGrants read access to API Gateway (including API Shield) for all domains in an account.
API Gateway 編集Grants write access to API Gateway (including API Shield) for all domains in an account.
Billing ReadGrants read access to billing profile, subscriptions, and access to fetch invoices and entitlements.
Billing 編集Grants write access to billing profile, subscriptions, and access to fetch invoices and entitlements.
Bulk URL Redirects ReadGrants read access to Bulk URL Redirects.
Bulk URL Redirects 編集Grants write access to Bulk URL Redirects.
China Network Steering ReadGrants read access to China Network Steering.
China Network Steering 編集Grants write access to China Network Steering.
Cloudchamber ReadGrants read access to Cloudchamber deployments.
Cloudchamber 編集Grants write access to Cloudchamber deployments.
Cloudflare Calls ReadGrants read access to Cloudflare Calls.
Cloudflare Calls 編集Grants write access to Cloudflare Calls.
Cloudflare DEX ReadGrants read access to Digital Experience Monitoring.
Cloudflare DEX 編集Grants write access to Digital Experience Monitoring.
Cloudflare Images ReadGrants read access to Cloudflare Images.
Cloudflare Images 編集Grants write access to Cloudflare Images.
Cloudflare One Connector: cloudflared ReadGrants read access to cloudflared Connectors
Cloudflare One Connector: cloudflared 編集Grants write access to cloudflared Connectors
Cloudflare One Connector: WARP ReadGrants read access to Warp Connectors
Cloudflare One Connector: WARP 編集Grants write access to Warp Connectors
Cloudflare One Connectors ReadGrants read access to Cloudflare One Connectors
Cloudflare One Connectors 編集Grants write access to Cloudflare One Connectors
Cloudflare One Networks ReadGrants read access to Cloudflare One Networks
Cloudflare One Networks 編集Grants write access to Cloudflare One Networks
Cloudflare Pages ReadGrants access to view Cloudflare Pages projects.
Cloudflare Pages 編集Grants access to create, edit and delete Cloudflare Pages projects.
Cloudflare Tunnel ReadGrants access to view Cloudflare Tunnels.
Cloudflare Tunnel 編集Grants access to create and delete Cloudflare Tunnels.
Cloudforce One ReadGrants read access to Cloudforce One.
Cloudforce One 編集Grants write access to Cloudforce One.
Cloud Email Security ReadGrants read access to Cloud Email Security.
Email Security 編集Grants write access to Email Security.
Constellation ReadGrants read access to Constellation.
Constellation 編集Grants write access to Constellation.
D1 ReadGrants read access to D1.
D1 編集Grants write access to D1.
DDoS Botnet Feed ReadGrants read access to Botnet Feed reports.
DDoS Botnet Feed 編集Grants write access to Botnet Feed configuration.
DDoS Protection ReadGrants read access to DDoS protection.
DDoS Protection 編集Grants write access to DDoS protection.
DNS Firewall ReadGrants read access to DNS Firewall.
DNS Firewall 編集Grants write access to DNS Firewall.
Email Routing Addresses ReadGrants read access to Email Routing Addresses.
Email Routing Addresses 編集Grants write access to Email Routing Addresses.
Hyperdrive ReadGrants read access to Hyperdrive.
Hyperdrive 編集Grants write access to Hyperdrive.
Intel ReadGrants read access to Intel.
Intel 編集Grants write access to Intel.
Integration 編集Grants write access to integrations.
IOT ReadGrants read access to IOT.
IOT 編集Grants write access to IOT.
IP Prefixes: ReadGrants access to read IP prefix settings.
IP Prefixes: 編集Grants access to read/write IP prefix settings.
IP Prefixes: BGP On Demand ReadGrants access to read IP prefix BGP configuration.
IP Prefixes: BGP On Demand 編集Grants access to read and change IP prefix BGP configuration.
L3/4 DDoS Managed Ruleset ReadGrants read access to L3/4 DDoS managed ruleset.
L3/4 DDoS Managed Ruleset 編集Grants write access to L3/4 DDoS managed ruleset.
Load Balancing: Monitors and Pools ReadGrants read access to account level load balancer resources.
Load Balancing: Monitors and Pools 編集Grants write access to account level load balancer resources.
Logs ReadGrants read access to logs using Logpull or Instant Logs.
Logs 編集Grants read and write access to Logpull, Logpush, and Instant Logs.
Magic Firewall ReadGrants read access to Magic Firewall.
Magic Firewall 編集Grants write access to Magic Firewall.
Magic Firewall Packet Captures - Read PCAPs APIGrants read access to Packet Captures.
Magic Firewall Packet Captures - 編集 PCAPs APIGrants write access to Packet Captures.
Magic Network Monitoring ReadGrants read access to Magic Network Monitoring.
Magic Network Monitoring 編集Grants write access to Magic Network Monitoring.
Magic Transit ReadGrants read access to manage a user’s Magic Transit prefixes.
Magic Transit 編集Grants write access to manage a user’s Magic Transit prefixes.
Notifications ReadGrants read access to Notifications.
Notifications 編集Grants write access to Notifications.
Page Shield ReadGrants read access to Page Shield.
Page Shield 編集Grants write access to Page Shield.
Pipelines ReadGrants read access to Cloudflare Pipelines.
Pipelines 編集Grants write access to Cloudflare Pipelines.
Pub/Sub ReadGrants read access to Pub/Sub.
Pub/Sub 編集Grants write access to Pub/Sub.
Queues ReadGrants read access to Queues.
Queues 編集Grants write access to Queues.
Rule Policies ReadGrants read access to Rule Policies.
Rule Policies 編集Grants write access to Rule Policies.
Stream ReadGrants read access to Cloudflare Stream.
Stream 編集Grants write access to Cloudflare Stream.
Transform Rules ReadGrants read access to Transform Rules.
Transform Rules 編集Grants write access to Transform Rules.
Turnstile ReadGrants read access to Turnstile.
Turnstile 編集Grants write access to Turnstile.
URL Scanner ReadGrants read access to URL Scanner.
URL Scanner 編集Grants write access to URL Scanner.
Vectorize ReadGrants read access to Vectorize.
Vectorize 編集Grants write access to Vectorize.
Workers AI ReadGrants read access to Workers AI.
Workers AI 編集Grants write access to Workers AI.
Workers CI ReadGrants read access to [Workers CI] (/workers/).
Workers CI 編集Grants write access to Workers CI.
Workers KV Storage ReadGrants read access to Cloudflare Workers KV Storage.
Workers KV Storage 編集Grants write access to Cloudflare Workers KV Storage.
Workers R2 Storage ReadGrants read access to Cloudflare R2 Storage.
Workers R2 Storage 編集Grants write access to Cloudflare R2 Storage.
Workers Scripts ReadGrants read access to Cloudflare Workers scripts.
Workers Scripts 編集Grants write access to Cloudflare Workers scripts.
Workers Tail ReadGrants wrangler tail read permissions.
Zero Trust ReadGrants read access to Cloudflare Zero Trust.
Zero Trust ReportGrants reporting access to Cloudflare Zero Trust.
Zero Trust 編集Grants write access to Cloudflare Zero Trust.
Zero Trust PII ReadGrants read access to Cloudflare Zero Trust PII.
Zero Trust PII 編集Grants write access to Cloudflare Zero Trust PII.
Zero Trust Seats 編集Grants write access to the number of Zero Trust Seats your organization can use (and be billed for).

ゾーン権限

ゾーン権限の適用スコープはcom.cloudflare.api.account.zoneです。

NameDescription
Access: Apps and Policies ReadGrants read access to Cloudflare Access zone resources.
Access: Apps and Policies RevokeGrants ability to revoke all tokens to Cloudflare Access zone resources.
Access: Apps and Policies 編集Grants write access to Cloudflare Access zone resources.
Analytics ReadGrants read access to analytics.
API Gateway ReadGrants read access to API Gateway zone resources.
API Gateway 編集Grants write access to API Gateway zone resources.
Apps 編集Grants full access to Cloudflare Apps.
Bot Management ReadGrants read access to Bot Management.
Bot Management 編集Grants write access to Bot Management.
Bot Management Feedback ReadGrants read access to Bot Management feedback.
Bot Management Feedback 編集Grants write access to Bot Management feedback.
Cache PurgeGrants access to purge cache.
Cache Rules ReadGrants read access to Cache Rules.
Cache Rules 編集Grants write access to Cache Rules.
Cloud Connector ReadGrants read access to Cloud Connector rules.
Cloud Connector 編集Grants write access to Cloud Connector rules.
Config Rules ReadGrants read access to Configuration Rules.
Config Rules 編集Grants write access to Configuration Rules.
Custom Errors ReadGrants read access to Custom Errors Phase.
Custom Errors 編集Grants write access to Custom Errors Phase.
Custom Error Rules ReadGrants read access to Custom Error Rules.
Custom Error Rules 編集Grants write access to Custom Error Rules.
Custom Pages ReadGrants read access to Custom Pages.
Custom Pages 編集Grants write access to Custom Pages.
DMARC Management ReadGrants read access to DMARC Management.
DMARC Management 編集Grants write access to DMARC Management.
DNS ReadGrants read access to DNS.
DNS WriteGrants write access to DNS.
Dynamic URL Redirect ReadGrants read access to zone-level Single Redirects.
Dynamic URL Redirect 編集Grants write access to zone-level Single Redirects.
Email Routing Rules ReadGrants read access to Email Routing Rules.
Email Routing Rules 編集Grants write access to Email Routing Rules.
Firewall Services ReadGrants read access to Firewall resources.
Firewall Services 編集Grants write access to Firewall resources.
Health Checks ReadGrants read access to Health Checks.
Health Checks 編集Grants write access to Health Checks.
HTTP DDoS Managed Ruleset ReadGrants read access to HTTP DDoS managed ruleset.
HTTP DDoS Managed Ruleset 編集Grants write access to HTTP DDoS managed ruleset.
Load Balancers ReadGrants read access to load balancer resources.
Load Balancers 編集Grants write access to load balancer resources.
Logs ReadGrants read access to logs using Logpull.
Logs 編集Grants write access to Logpull and Logpush.
Managed Headers ReadGrants read access to Managed Headers.
Managed Headers 編集Grants write access to Managed Headers.
Origin Rules ReadGrants read access to Origin Rules.
Origin Rules 編集Grants write access to Origin Rules.
Page Rules ReadGrants read access to Page Rules.
Page Rules 編集Grants write access to Page Rules.
Page Shield ReadGrants read access to Page Shield.
Page Shield 編集Grants write access to Page Shield.
Response Compression ReadGrants read access to Response Compression.
Response Compression 編集Grants write access to Response Compression.
Sanitize ReadGrants read access to sanitization.
Sanitize 編集Grants write access to sanitization.
SSL and Certificates ReadGrants read access to SSL configuration and certificate management.
SSL and Certificates 編集Grants write access to SSL configuration and certificate management.
Transform Rules ReadGrants read access to Transform Rules.
Transform Rules 編集Grants write access to Transform Rules.
Waiting Room ReadGrants read access to Waiting Room.
Waiting Room 編集Grants write access to Waiting Room.
Web3 Hostnames ReadGrants read access to Web3 Hostnames.
Web3 Hostnames 編集Grants write access to Web3 Hostnames.
Workers Routes ReadGrants read access to Cloudflare Workers and Workers KV Storage.
Workers Routes 編集Grants write access to Cloudflare Workers and Workers KV Storage.
Zaraz ReadGrants read access to Zaraz zone level settings.
Zaraz 編集Grants write access to Zaraz zone level settings.
Zone ReadGrants read access to zone management.
Zone 編集Grants write access to zone management.
Zone Settings ReadGrants read access to zone settings.
Zone Settings 編集Grants write access to zone settings.
Zone Versioning ReadGrants read access to Zone Versioning at zone level.
Zone Versioning 編集Grants write access to Zone Versioning at zone level.
Zone WAF ReadGrants read access to Zone WAF.
Zone WAF 編集Grants write access to Zone WAF.