Skip to content
Cloudflare Docs logomark
Cloudflare
Docs
Cloudflare Zero Trust
Navigation menu icon
Open external link
Cloudflare Docs logomark
Cloudflare
Docs
Cloudflare Zero Trust
Dropdown icon
Cloudflare Zero Trust menu
Blog: Introducing Cloudflare One
Zero Trust and SASE plans and pricing
Cloudflare homepage
Overview
Get started
Tutorials
Expand: Learning paths
Learning paths
Get started with DNS filtering
External link icon
Open external link
Replace your VPN
External link icon
Open external link
Expand: Identity
Identity
One-time PIN login
Expand: SSO integration
SSO integration
Generic SAML 2.0
SAML | Centrify
Azure AD®
SAML | OneLogin
SAML | Jumpcloud
SAML | Active Directory®
PingFederate®
PingOne®
PingOne® (SAML)
SAML | Citrix ADC
SAML | Signed AuthN requests
SAML | Keycloak
Generic OIDC
OneLogin OIDC
Centrify
Facebook
GitHub
Google
Google Workspace
LinkedIn
Okta
Okta (SAML)
Yandex
Expand: Device posture
Device posture
Expand: WARP client checks
WARP client checks
Application check
Carbon Black
Device serial numbers
Device UUID
Disk encryption
Domain joined
File check
Firewall
OS version
Require Gateway
Require WARP
SentinelOne
Expand: Service providers
Service providers
CrowdStrike
Kolide
Microsoft Endpoint Manager
SentinelOne
Uptycs
Workspace ONE
Expand: Access integrations
Access integrations
Azure AD
Mutual TLS
Tanium
Expand: User management
User management
Access groups
Session management
Seat management
Short-lived certificates
Service tokens
Expand: Authorization cookie
Authorization cookie
Validate JWTs
Application token
CORS
Expand: Connections
Connections
Expand: Cloudflare Tunnel
Cloudflare Tunnel
Expand: Get started
Get started
Expand: Set up a tunnel
Set up a tunnel
Expand: Via the dashboard
Via the dashboard
Configuration
Expand: Via the command line
Via the command line
Expand: Configuration
Configuration
Configuration file
Ingress rules
Cloudflared parameters
Run a tunnel
Expand: Run as a service
Run as a service
Linux
macOS
Windows
Useful commands
Tunnel availability and failover
Tunnel permissions
Tunnel with firewall
Useful terms
Expand: Downloads
Downloads
Update cloudflared
System requirements
License
Copyrights
Expand: Tunnel use cases
Tunnel use cases
SSH
RDP
SMB
Expand: Private networks
Private networks
Connect private networks
Create private networks
Private hostnames and IPs
Tunnel Virtual Networks
Expand: Public hostnames
Public hostnames
DNS record
Load balancers
Expand: Monitor tunnels
Monitor tunnels
Logs
Notifications
Expand: Tunnel administration
Tunnel administration
Ansible
AWS
Azure
GCP
Kubernetes
Terraform
Expand: Do more with Tunnel
Do more with Tunnel
Secure the server
Migrate legacy tunnels
Quick Tunnels
Grafana Dashboard for Tunnels
Expand: Connect devices
Connect devices
Expand: WARP
WARP
First-time setup
Expand: Download WARP
Download WARP
Migrate 1.1.1.1 app
Expand: User-side certificates
User-side certificates
Install certificate using WARP
Install certificate manually
Deploy custom certificate
Expand: Deploy WARP
Deploy WARP
Expand: Managed deployment
Managed deployment
Expand: Partners
Partners
Hexnode
Intune
Jamf
JumpCloud
Kandji
Parameters
Manual deployment
Device enrollment permissions
WARP with firewall
WARP with legacy VPN
Expand: Configure WARP
Configure WARP
Device profiles
Expand: WARP modes
WARP modes
Enable Device Information Only
WARP settings
Managed networks
Expand: Route traffic
Route traffic
Local Domain Fallback
Split Tunnels
WARP architecture
WARP sessions
Expand: Troubleshoot WARP
Troubleshoot WARP
Common issues
Client errors
Debug logs
Known limitations
Remove WARP
Expand: Agentless options
Agentless options
Expand: DNS
DNS
Expand: Add locations
Add locations
DNS resolver IPs and hostnames
DNS over HTTPS
DNS over TLS
HTTP
Magic WAN
External link icon
Open external link
Expand: Applications
Applications
Expand: Add web applications
Add web applications
Expand: SaaS applications
SaaS applications
AWS
DocuSign
Google Workspace
Hubspot
Salesforce
Zendesk
Self-hosted applications
Cloudflare dashboard SSO application
Expand: Add non-HTTP applications
Add non-HTTP applications
Arbitrary TCP
Expand: Scan SaaS applications
Scan SaaS applications
Manage findings
Expand: Available integrations
Available integrations
Atlassian Confluence
Atlassian Jira
Box
Dropbox
GitHub
Expand: Google Workspace
Google Workspace
Google Drive
Gmail
Google Admin
Google Calendar
Expand: Microsoft 365
Microsoft 365
Admin Center
OneDrive
SharePoint
Outlook
Salesforce
ServiceNow
Slack
Scan for sensitive data
Customize an application
Add bookmarks
App Launcher
Expand: Policies
Policies
Expand: Secure Web Gateway
Secure Web Gateway
Expand: Get started
Get started
DNS filtering
Network filtering
HTTP filtering
Expand: DNS policies
DNS policies
Common policies
Test DNS filtering
Scheduled DNS policies
Expand: Network policies
Network policies
Common policies
Protocol detection
SSH proxy and command logs
Expand: HTTP policies
HTTP policies
Common policies
HTTP/3
TLS decryption
Tenant control
AV scanning
WebSocket traffic
Expand: Egress policies
Egress policies
Dedicated egress IPs
Global policies
Applications and app types
Domain categories
Identity-based policies
Block page
Order of enforcement
Lists
Proxy
Expand: Access
Access
Manage Access policies
Require Purpose Justification
External Evaluation rules
Isolate self-hosted application
Application paths
Enforce MFA
Temporary authentication
Expand: Browser Isolation
Browser Isolation
Expand: Setup
Setup
Clientless Web Isolation
Non-identity on-ramps
Isolation policies
Extensions
Accessibility
Browser Isolation with firewall
Known limitations
Expand: Data Loss Prevention
Data Loss Prevention
Expand: Scan HTTP traffic
Scan HTTP traffic
Common policies
Log the payload of matched rules
Expand: Configure a DLP profile
Configure a DLP profile
Predefined profiles
Integration profiles
Profile settings
Exact Data Match
Expand: Insights
Insights
Expand: Analytics
Analytics
Shadow IT Discovery
Gateway analytics
Expand: Digital Experience Monitoring
Digital Experience Monitoring
Fleet status
Expand: Tests
Tests
HTTP test
Traceroute test
Test results
Expand: Logs
Logs
User logs
Access audit logs
Expand: Gateway activity logs
Gateway activity logs
Manage PII
Tunnel audit logs
Posture logs
Expand: Logpush integration
Logpush integration
RData
Expand: API and Terraform
API and Terraform
Expand: Access API examples
Access API examples
Access group
Any valid service token
Authentication method
Azure® Group
Common name
Country Code
Email
Email domain
Everyone
G Suite® Group
GitHub™ Organization
IP range
mTLS certificate
Okta® Group
SAML Attribute
Service token
Expand: Gateway API examples
Gateway API examples
DNS policy
Network policy
HTTP policy
Scoped API tokens
Terraform
Glossary
Account limits
Roles and permissions
FAQ
Give Feedback
GitHub icon
Visit Cloudflare Zero Trust on GitHub
Search icon (depiction of a magnifying glass)
Light theme icon (depiction of a sun)
Dark theme icon (depiction of a moon)
Set theme to dark (⇧+D)
Products
Cloudflare Zero Trust
...
Access API examples
Country Code
Country Code
Allow a specific country.
{
"geo"
:
{
"country_code"
:
"US"
}
}