curl --request POST \
--url https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key \
--header 'Content-Type: application/json' \
--data '
{
"name": "<string>",
"projectId": "<string>",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment": "<string>",
"secretPath": "<string>",
"rotationInterval": 2,
"parameters": {
"name": "<string>",
"buckets": [
{
"name": "<string>",
"jurisdiction": "default"
}
],
"accessLevel": "object-read",
"allowedIps": [
"<string>"
],
"disallowedIps": [
"<string>"
]
},
"secretsMapping": {
"accessKeyId": "<string>",
"secretAccessKey": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": true
}
'import requests
url = "https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key"
payload = {
"name": "<string>",
"projectId": "<string>",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment": "<string>",
"secretPath": "<string>",
"rotationInterval": 2,
"parameters": {
"name": "<string>",
"buckets": [
{
"name": "<string>",
"jurisdiction": "default"
}
],
"accessLevel": "object-read",
"allowedIps": ["<string>"],
"disallowedIps": ["<string>"]
},
"secretsMapping": {
"accessKeyId": "<string>",
"secretAccessKey": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": True
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
projectId: '<string>',
connectionId: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
environment: '<string>',
secretPath: '<string>',
rotationInterval: 2,
parameters: {
name: '<string>',
buckets: [{name: '<string>', jurisdiction: 'default'}],
accessLevel: 'object-read',
allowedIps: ['<string>'],
disallowedIps: ['<string>']
},
secretsMapping: {accessKeyId: '<string>', secretAccessKey: '<string>'},
description: '<string>',
isAutoRotationEnabled: true
})
};
fetch('https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'projectId' => '<string>',
'connectionId' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'environment' => '<string>',
'secretPath' => '<string>',
'rotationInterval' => 2,
'parameters' => [
'name' => '<string>',
'buckets' => [
[
'name' => '<string>',
'jurisdiction' => 'default'
]
],
'accessLevel' => 'object-read',
'allowedIps' => [
'<string>'
],
'disallowedIps' => [
'<string>'
]
],
'secretsMapping' => [
'accessKeyId' => '<string>',
'secretAccessKey' => '<string>'
],
'description' => '<string>',
'isAutoRotationEnabled' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"buckets\": [\n {\n \"name\": \"<string>\",\n \"jurisdiction\": \"default\"\n }\n ],\n \"accessLevel\": \"object-read\",\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"accessKeyId\": \"<string>\",\n \"secretAccessKey\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"buckets\": [\n {\n \"name\": \"<string>\",\n \"jurisdiction\": \"default\"\n }\n ],\n \"accessLevel\": \"object-read\",\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"accessKeyId\": \"<string>\",\n \"secretAccessKey\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"buckets\": [\n {\n \"name\": \"<string>\",\n \"jurisdiction\": \"default\"\n }\n ],\n \"accessLevel\": \"object-read\",\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"accessKeyId\": \"<string>\",\n \"secretAccessKey\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}"
response = http.request(request)
puts response.read_body{
"secretRotation": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"rotationInterval": 123,
"rotationStatus": "<string>",
"lastRotationAttemptedAt": "2023-11-07T05:31:56Z",
"lastRotatedAt": "2023-11-07T05:31:56Z",
"connection": {
"app": "cloudflare",
"name": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"environment": {
"slug": "<string>",
"name": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"projectId": "<string>",
"folder": {
"id": "<string>",
"path": "<string>"
},
"rotateAtUtc": {
"hours": 11.5,
"minutes": 29.5
},
"type": "cloudflare-r2-access-key",
"parameters": {
"name": "<string>",
"buckets": [
{
"name": "<string>",
"jurisdiction": "default"
}
],
"accessLevel": "object-read",
"allowedIps": [
"<string>"
],
"disallowedIps": [
"<string>"
]
},
"secretsMapping": {
"accessKeyId": "<string>",
"secretAccessKey": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": true,
"activeIndex": 0,
"lastRotationJobId": "<string>",
"nextRotationAt": "2023-11-07T05:31:56Z",
"isLastRotationManual": true,
"lastRotationMessage": "<string>"
}
}{
"reqId": "<string>",
"statusCode": 400,
"message": "<string>",
"error": "<string>",
"details": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 401,
"message": "<string>",
"error": "<string>"
}{
"reqId": "<string>",
"statusCode": 403,
"message": "<string>",
"error": "<string>",
"details": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 404,
"message": "<string>",
"error": "<string>"
}{
"reqId": "<string>",
"statusCode": 422,
"error": "<string>",
"message": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 500,
"message": "<string>",
"error": "<string>"
}Create
Create a Cloudflare R2 Access Key Rotation for the specified project.
curl --request POST \
--url https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key \
--header 'Content-Type: application/json' \
--data '
{
"name": "<string>",
"projectId": "<string>",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment": "<string>",
"secretPath": "<string>",
"rotationInterval": 2,
"parameters": {
"name": "<string>",
"buckets": [
{
"name": "<string>",
"jurisdiction": "default"
}
],
"accessLevel": "object-read",
"allowedIps": [
"<string>"
],
"disallowedIps": [
"<string>"
]
},
"secretsMapping": {
"accessKeyId": "<string>",
"secretAccessKey": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": true
}
'import requests
url = "https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key"
payload = {
"name": "<string>",
"projectId": "<string>",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment": "<string>",
"secretPath": "<string>",
"rotationInterval": 2,
"parameters": {
"name": "<string>",
"buckets": [
{
"name": "<string>",
"jurisdiction": "default"
}
],
"accessLevel": "object-read",
"allowedIps": ["<string>"],
"disallowedIps": ["<string>"]
},
"secretsMapping": {
"accessKeyId": "<string>",
"secretAccessKey": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": True
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
projectId: '<string>',
connectionId: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
environment: '<string>',
secretPath: '<string>',
rotationInterval: 2,
parameters: {
name: '<string>',
buckets: [{name: '<string>', jurisdiction: 'default'}],
accessLevel: 'object-read',
allowedIps: ['<string>'],
disallowedIps: ['<string>']
},
secretsMapping: {accessKeyId: '<string>', secretAccessKey: '<string>'},
description: '<string>',
isAutoRotationEnabled: true
})
};
fetch('https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'projectId' => '<string>',
'connectionId' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'environment' => '<string>',
'secretPath' => '<string>',
'rotationInterval' => 2,
'parameters' => [
'name' => '<string>',
'buckets' => [
[
'name' => '<string>',
'jurisdiction' => 'default'
]
],
'accessLevel' => 'object-read',
'allowedIps' => [
'<string>'
],
'disallowedIps' => [
'<string>'
]
],
'secretsMapping' => [
'accessKeyId' => '<string>',
'secretAccessKey' => '<string>'
],
'description' => '<string>',
'isAutoRotationEnabled' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"buckets\": [\n {\n \"name\": \"<string>\",\n \"jurisdiction\": \"default\"\n }\n ],\n \"accessLevel\": \"object-read\",\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"accessKeyId\": \"<string>\",\n \"secretAccessKey\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"buckets\": [\n {\n \"name\": \"<string>\",\n \"jurisdiction\": \"default\"\n }\n ],\n \"accessLevel\": \"object-read\",\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"accessKeyId\": \"<string>\",\n \"secretAccessKey\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"projectId\": \"<string>\",\n \"connectionId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"environment\": \"<string>\",\n \"secretPath\": \"<string>\",\n \"rotationInterval\": 2,\n \"parameters\": {\n \"name\": \"<string>\",\n \"buckets\": [\n {\n \"name\": \"<string>\",\n \"jurisdiction\": \"default\"\n }\n ],\n \"accessLevel\": \"object-read\",\n \"allowedIps\": [\n \"<string>\"\n ],\n \"disallowedIps\": [\n \"<string>\"\n ]\n },\n \"secretsMapping\": {\n \"accessKeyId\": \"<string>\",\n \"secretAccessKey\": \"<string>\"\n },\n \"description\": \"<string>\",\n \"isAutoRotationEnabled\": true\n}"
response = http.request(request)
puts response.read_body{
"secretRotation": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"rotationInterval": 123,
"rotationStatus": "<string>",
"lastRotationAttemptedAt": "2023-11-07T05:31:56Z",
"lastRotatedAt": "2023-11-07T05:31:56Z",
"connection": {
"app": "cloudflare",
"name": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"environment": {
"slug": "<string>",
"name": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"projectId": "<string>",
"folder": {
"id": "<string>",
"path": "<string>"
},
"rotateAtUtc": {
"hours": 11.5,
"minutes": 29.5
},
"type": "cloudflare-r2-access-key",
"parameters": {
"name": "<string>",
"buckets": [
{
"name": "<string>",
"jurisdiction": "default"
}
],
"accessLevel": "object-read",
"allowedIps": [
"<string>"
],
"disallowedIps": [
"<string>"
]
},
"secretsMapping": {
"accessKeyId": "<string>",
"secretAccessKey": "<string>"
},
"description": "<string>",
"isAutoRotationEnabled": true,
"activeIndex": 0,
"lastRotationJobId": "<string>",
"nextRotationAt": "2023-11-07T05:31:56Z",
"isLastRotationManual": true,
"lastRotationMessage": "<string>"
}
}{
"reqId": "<string>",
"statusCode": 400,
"message": "<string>",
"error": "<string>",
"details": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 401,
"message": "<string>",
"error": "<string>"
}{
"reqId": "<string>",
"statusCode": 403,
"message": "<string>",
"error": "<string>",
"details": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 404,
"message": "<string>",
"error": "<string>"
}{
"reqId": "<string>",
"statusCode": 422,
"error": "<string>",
"message": "<unknown>"
}{
"reqId": "<string>",
"statusCode": 500,
"message": "<string>",
"error": "<string>"
}Request body
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | A unique name for the rotation (max 100 characters). |
projectId | string (UUID) | Yes | The project ID. |
connectionId | string (UUID) | Yes | ID of the Cloudflare app connection. |
environment | string | Yes | Environment slug (e.g. dev, prod). |
secretPath | string | Yes | Path where the generated access key secrets will be stored. |
isAutoRotationEnabled | boolean | No | Whether to rotate automatically on the schedule. Defaults to true. |
rotationInterval | number | Yes | Days between rotations (minimum 1). |
rotateAtUtc | object | No | Time of day (UTC) to run rotation: { "hours", "minutes" }. Defaults to { "hours": 0, "minutes": 0 }. |
parameters.name | string | Yes | The name for the generated Cloudflare API token that backs the access key (max 100 characters). A timestamp is appended to each generated token. |
parameters.buckets | array | Yes | The R2 buckets the generated access key is scoped to. At least one bucket is required, and each entry must be unique. |
parameters.buckets[].name | string | Yes | The bucket’s name, exactly as it appears in Cloudflare. |
parameters.buckets[].jurisdiction | string | No | The bucket’s storage jurisdiction: "default", "eu", or "fedramp". Defaults to "default". |
parameters.accessLevel | string | Yes | What the generated key can do on the selected buckets: "object-read" (get and list) or "object-read-write" (also put and delete). |
parameters.allowedIps | string[] | No | The IP addresses or CIDR blocks the generated access key is restricted to. |
parameters.disallowedIps | string[] | No | The IP addresses or CIDR blocks the generated access key is denied from. |
secretsMapping.accessKeyId | string | Yes | Secret key name to store the generated access key ID (e.g. CLOUDFLARE_R2_ACCESS_KEY_ID). |
secretsMapping.secretAccessKey | string | Yes | Secret key name to store the generated secret access key (e.g. CLOUDFLARE_R2_SECRET_ACCESS_KEY). |
description | string | No | Optional description. |
Sample request
curl --request POST \
--url https://us.infisical.com/api/v2/secret-rotations/cloudflare-r2-access-key \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer <ACCESS_TOKEN>' \
--data '{
"name": "my-r2-access-key-rotation",
"projectId": "<project-id>",
"description": "Cloudflare R2 access key rotation",
"connectionId": "<cloudflare-connection-id>",
"environment": "dev",
"secretPath": "/",
"isAutoRotationEnabled": true,
"rotationInterval": 30,
"rotateAtUtc": { "hours": 0, "minutes": 0 },
"parameters": {
"name": "infisical-r2-access-key",
"buckets": [
{ "name": "my-bucket", "jurisdiction": "default" },
{ "name": "my-eu-bucket", "jurisdiction": "eu" }
],
"accessLevel": "object-read",
"allowedIps": ["203.0.113.0/24"]
},
"secretsMapping": {
"accessKeyId": "CLOUDFLARE_R2_ACCESS_KEY_ID",
"secretAccessKey": "CLOUDFLARE_R2_SECRET_ACCESS_KEY"
}
}'
Sample response
{
"secretRotation": {
"id": "<rotation-id>",
"name": "my-r2-access-key-rotation",
"description": "Cloudflare R2 access key rotation",
"secretsMapping": {
"accessKeyId": "CLOUDFLARE_R2_ACCESS_KEY_ID",
"secretAccessKey": "CLOUDFLARE_R2_SECRET_ACCESS_KEY"
},
"isAutoRotationEnabled": true,
"activeIndex": 0,
"connectionId": "<cloudflare-connection-id>",
"rotationInterval": 30,
"rotateAtUtc": { "hours": 0, "minutes": 0 },
"type": "cloudflare-r2-access-key",
"parameters": {
"name": "infisical-r2-access-key",
"buckets": [
{ "name": "my-bucket", "jurisdiction": "default" },
{ "name": "my-eu-bucket", "jurisdiction": "eu" }
],
"accessLevel": "object-read",
"allowedIps": ["203.0.113.0/24"]
}
}
}
Body
The name of the Cloudflare R2 Access Key Rotation to create. Must be slug-friendly.
1 - 64The ID of the project to create the rotation in.
1The ID of the Cloudflare Connection to use for rotation.
The slug of the project environment to create the rotation in.
1 - 64The secret path of the project to create the rotation in.
1The interval, in days, to automatically rotate secrets.
x >= 1Show child attributes
Show child attributes
Show child attributes
Show child attributes
An optional description for the Cloudflare R2 Access Key Rotation.
256Whether secrets should be automatically rotated when the specified rotation interval has elapsed.
The hours and minutes rotation should occur at in UTC. Defaults to Midnight (00:00) UTC.
Show child attributes
Show child attributes
Response
Default Response
Show child attributes
Show child attributes
Was this page helpful?