curl --request POST \
--url https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token \
--header 'Content-Type: application/json' \
--data '
{
"name": "<string>",
"projectId": "<string>",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment": "<string>",
"secretPath": "<string>",
"rotationInterval": 2,
"parameters": {
"name": "<string>",
"policies": [
{
"permissionGroupIds": [
"<string>"
],
"zoneIds": [
"<string>"
]
}
],
"allowedIps": [
"<string>"
],
"disallowedIps": [
"<string>"
]
},
"secretsMapping": {
"tokenId": "<string>",
"apiToken": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": true
}
'import requests
url = "https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token"
payload = {
"name": "<string>",
"projectId": "<string>",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment": "<string>",
"secretPath": "<string>",
"rotationInterval": 2,
"parameters": {
"name": "<string>",
"policies": [
{
"permissionGroupIds": ["<string>"],
"zoneIds": ["<string>"]
}
],
"allowedIps": ["<string>"],
"disallowedIps": ["<string>"]
},
"secretsMapping": {
"tokenId": "<string>",
"apiToken": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": True
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
projectId: '<string>',
connectionId: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
environment: '<string>',
secretPath: '<string>',
rotationInterval: 2,
parameters: {
name: '<string>',
policies: [{permissionGroupIds: ['<string>'], zoneIds: ['<string>']}],
allowedIps: ['<string>'],
disallowedIps: ['<string>']
},
secretsMapping: {tokenId: '<string>', apiToken: '<string>'},
description: '<string>',
isAutoRotationEnabled: true
})
};
fetch('https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'projectId' => '<string>',
'connectionId' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'environment' => '<string>',
'secretPath' => '<string>',
'rotationInterval' => 2,
'parameters' => [
'name' => '<string>',
'policies' => [
[
'permissionGroupIds' => [
'<string>'
],
'zoneIds' => [
'<string>'
]
]
],
'allowedIps' => [
'<string>'
],
'disallowedIps' => [
'<string>'
]
],
'secretsMapping' => [
'tokenId' => '<string>',
'apiToken' => '<string>'
],
'description' => '<string>',
'isAutoRotationEnabled' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"policies\": [\n {\n \"permissionGroupIds\": [\n \"<string>\"\n ],\n \"zoneIds\": [\n \"<string>\"\n ]\n }\n ],\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"tokenId\": \"<string>\",\n \"apiToken\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"policies\": [\n {\n \"permissionGroupIds\": [\n \"<string>\"\n ],\n \"zoneIds\": [\n \"<string>\"\n ]\n }\n ],\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"tokenId\": \"<string>\",\n \"apiToken\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"policies\": [\n {\n \"permissionGroupIds\": [\n \"<string>\"\n ],\n \"zoneIds\": [\n \"<string>\"\n ]\n }\n ],\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"tokenId\": \"<string>\",\n \"apiToken\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}"
response = http.request(request)
puts response.read_body{
"secretRotation": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"rotationInterval": 123,
"rotationStatus": "<string>",
"lastRotationAttemptedAt": "2023-11-07T05:31:56Z",
"lastRotatedAt": "2023-11-07T05:31:56Z",
"connection": {
"app": "cloudflare",
"name": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"environment": {
"slug": "<string>",
"name": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"projectId": "<string>",
"folder": {
"id": "<string>",
"path": "<string>"
},
"rotateAtUtc": {
"hours": 11.5,
"minutes": 29.5
},
"type": "cloudflare-api-token",
"parameters": {
"name": "<string>",
"policies": [
{
"permissionGroupIds": [
"<string>"
],
"zoneIds": [
"<string>"
]
}
],
"allowedIps": [
"<string>"
],
"disallowedIps": [
"<string>"
]
},
"secretsMapping": {
"tokenId": "<string>",
"apiToken": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": true,
"activeIndex": 0,
"lastRotationJobId": "<string>",
"nextRotationAt": "2023-11-07T05:31:56Z",
"isLastRotationManual": true,
"lastRotationMessage": "<string>"
}
}{
"reqId": "<string>",
"statusCode": 400,
"message": "<string>",
"error": "<string>",
"details": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 401,
"message": "<string>",
"error": "<string>"
}{
"reqId": "<string>",
"statusCode": 403,
"message": "<string>",
"error": "<string>",
"details": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 404,
"message": "<string>",
"error": "<string>"
}{
"reqId": "<string>",
"statusCode": 422,
"error": "<string>",
"message": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 500,
"message": "<string>",
"error": "<string>"
}Create
Create a Cloudflare API Token Rotation for the specified project.
curl --request POST \
--url https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token \
--header 'Content-Type: application/json' \
--data '
{
"name": "<string>",
"projectId": "<string>",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment": "<string>",
"secretPath": "<string>",
"rotationInterval": 2,
"parameters": {
"name": "<string>",
"policies": [
{
"permissionGroupIds": [
"<string>"
],
"zoneIds": [
"<string>"
]
}
],
"allowedIps": [
"<string>"
],
"disallowedIps": [
"<string>"
]
},
"secretsMapping": {
"tokenId": "<string>",
"apiToken": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": true
}
'import requests
url = "https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token"
payload = {
"name": "<string>",
"projectId": "<string>",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment": "<string>",
"secretPath": "<string>",
"rotationInterval": 2,
"parameters": {
"name": "<string>",
"policies": [
{
"permissionGroupIds": ["<string>"],
"zoneIds": ["<string>"]
}
],
"allowedIps": ["<string>"],
"disallowedIps": ["<string>"]
},
"secretsMapping": {
"tokenId": "<string>",
"apiToken": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": True
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
projectId: '<string>',
connectionId: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
environment: '<string>',
secretPath: '<string>',
rotationInterval: 2,
parameters: {
name: '<string>',
policies: [{permissionGroupIds: ['<string>'], zoneIds: ['<string>']}],
allowedIps: ['<string>'],
disallowedIps: ['<string>']
},
secretsMapping: {tokenId: '<string>', apiToken: '<string>'},
description: '<string>',
isAutoRotationEnabled: true
})
};
fetch('https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'projectId' => '<string>',
'connectionId' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'environment' => '<string>',
'secretPath' => '<string>',
'rotationInterval' => 2,
'parameters' => [
'name' => '<string>',
'policies' => [
[
'permissionGroupIds' => [
'<string>'
],
'zoneIds' => [
'<string>'
]
]
],
'allowedIps' => [
'<string>'
],
'disallowedIps' => [
'<string>'
]
],
'secretsMapping' => [
'tokenId' => '<string>',
'apiToken' => '<string>'
],
'description' => '<string>',
'isAutoRotationEnabled' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"policies\": [\n {\n \"permissionGroupIds\": [\n \"<string>\"\n ],\n \"zoneIds\": [\n \"<string>\"\n ]\n }\n ],\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"tokenId\": \"<string>\",\n \"apiToken\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"policies\": [\n {\n \"permissionGroupIds\": [\n \"<string>\"\n ],\n \"zoneIds\": [\n \"<string>\"\n ]\n }\n ],\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"tokenId\": \"<string>\",\n \"apiToken\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"policies\": [\n {\n \"permissionGroupIds\": [\n \"<string>\"\n ],\n \"zoneIds\": [\n \"<string>\"\n ]\n }\n ],\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"tokenId\": \"<string>\",\n \"apiToken\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}"
response = http.request(request)
puts response.read_body{
"secretRotation": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"rotationInterval": 123,
"rotationStatus": "<string>",
"lastRotationAttemptedAt": "2023-11-07T05:31:56Z",
"lastRotatedAt": "2023-11-07T05:31:56Z",
"connection": {
"app": "cloudflare",
"name": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"environment": {
"slug": "<string>",
"name": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"projectId": "<string>",
"folder": {
"id": "<string>",
"path": "<string>"
},
"rotateAtUtc": {
"hours": 11.5,
"minutes": 29.5
},
"type": "cloudflare-api-token",
"parameters": {
"name": "<string>",
"policies": [
{
"permissionGroupIds": [
"<string>"
],
"zoneIds": [
"<string>"
]
}
],
"allowedIps": [
"<string>"
],
"disallowedIps": [
"<string>"
]
},
"secretsMapping": {
"tokenId": "<string>",
"apiToken": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": true,
"activeIndex": 0,
"lastRotationJobId": "<string>",
"nextRotationAt": "2023-11-07T05:31:56Z",
"isLastRotationManual": true,
"lastRotationMessage": "<string>"
}
}{
"reqId": "<string>",
"statusCode": 400,
"message": "<string>",
"error": "<string>",
"details": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 401,
"message": "<string>",
"error": "<string>"
}{
"reqId": "<string>",
"statusCode": 403,
"message": "<string>",
"error": "<string>",
"details": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 404,
"message": "<string>",
"error": "<string>"
}{
"reqId": "<string>",
"statusCode": 422,
"error": "<string>",
"message": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 500,
"message": "<string>",
"error": "<string>"
}Request body
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | A unique name for the rotation (max 100 characters). |
projectId | string (UUID) | Yes | The project ID. |
connectionId | string (UUID) | Yes | ID of the Cloudflare app connection. |
environment | string | Yes | Environment slug (e.g. dev, prod). |
secretPath | string | Yes | Path where the generated API token secrets will be stored. |
isAutoRotationEnabled | boolean | No | Whether to rotate automatically on the schedule. Defaults to true. |
rotationInterval | number | Yes | Days between rotations (minimum 1). |
rotateAtUtc | object | No | Time of day (UTC) to run rotation: { "hours", "minutes" }. Defaults to { "hours": 0, "minutes": 0 }. |
parameters.name | string | Yes | The name for the generated Cloudflare API token (max 100 characters). A timestamp is appended to each generated token. |
parameters.policies | array | Yes | The access policies to attach to the generated Cloudflare API token. Each policy scopes a set of permission groups to either the entire account or a set of zones. At least one policy is required. |
parameters.policies[].effect | string | Yes | Whether the policy grants or denies the permission groups: "allow" or "deny". |
parameters.policies[].scope | string | Yes | The resources the policy applies to: "account" (the entire account), "all-zones" (every zone in the account), or "zones" (specific zones). |
parameters.policies[].zoneIds | string[] | Conditional | The IDs of the zones the policy applies to. Required when scope is "zones", and rejected for the other scopes. |
parameters.policies[].permissionGroupIds | string[] | Yes | The IDs of the Cloudflare permission groups to grant. At least one is required. |
parameters.allowedIps | string[] | No | The IP addresses or CIDR blocks the generated Cloudflare API token is restricted to. |
parameters.disallowedIps | string[] | No | The IP addresses or CIDR blocks the generated Cloudflare API token is denied from. |
secretsMapping.tokenId | string | Yes | Secret key name to store the generated API token’s ID (e.g. CLOUDFLARE_API_TOKEN_ID). |
secretsMapping.apiToken | string | Yes | Secret key name to store the generated API token’s value (e.g. CLOUDFLARE_API_TOKEN). |
description | string | No | Optional description. |
Sample request
curl --request POST \
--url https://us.infisical.com/api/v2/secret-rotations/cloudflare-api-token \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer <ACCESS_TOKEN>' \
--data '{
"name": "my-cloudflare-rotation",
"projectId": "<project-id>",
"description": "Cloudflare API token rotation",
"connectionId": "<cloudflare-connection-id>",
"environment": "dev",
"secretPath": "/",
"isAutoRotationEnabled": true,
"rotationInterval": 30,
"rotateAtUtc": { "hours": 0, "minutes": 0 },
"parameters": {
"name": "infisical-rotated-token",
"policies": [
{
"effect": "allow",
"scope": "zones",
"zoneIds": ["<zone-id>"],
"permissionGroupIds": ["<permission-group-id>"]
}
],
"allowedIps": ["203.0.113.0/24"]
},
"secretsMapping": {
"tokenId": "CLOUDFLARE_API_TOKEN_ID",
"apiToken": "CLOUDFLARE_API_TOKEN"
}
}'
Sample response
{
"secretRotation": {
"id": "<rotation-id>",
"name": "my-cloudflare-rotation",
"description": "Cloudflare API token rotation",
"secretsMapping": {
"tokenId": "CLOUDFLARE_API_TOKEN_ID",
"apiToken": "CLOUDFLARE_API_TOKEN"
},
"isAutoRotationEnabled": true,
"activeIndex": 0,
"connectionId": "<cloudflare-connection-id>",
"rotationInterval": 30,
"rotateAtUtc": { "hours": 0, "minutes": 0 },
"type": "cloudflare-api-token",
"parameters": {
"name": "infisical-rotated-token",
"policies": [
{
"effect": "allow",
"scope": "zones",
"zoneIds": ["<zone-id>"],
"permissionGroupIds": ["<permission-group-id>"]
}
],
"allowedIps": ["203.0.113.0/24"]
}
}
}
Body
The name of the Cloudflare API Token Rotation to create. Must be slug-friendly.
1 - 64The ID of the project to create the rotation in.
1The ID of the Cloudflare Connection to use for rotation.
The slug of the project environment to create the rotation in.
1 - 64The secret path of the project to create the rotation in.
1The interval, in days, to automatically rotate secrets.
x >= 1Show child attributes
Show child attributes
Show child attributes
Show child attributes
An optional description for the Cloudflare API Token Rotation.
256Whether secrets should be automatically rotated when the specified rotation interval has elapsed.
The hours and minutes rotation should occur at in UTC. Defaults to Midnight (00:00) UTC.
Show child attributes
Show child attributes
Response
Default Response
Show child attributes
Show child attributes
Was this page helpful?