## List Access identity providers `client.ZeroTrust.IdentityProviders.List(ctx, params) (*V4PagePaginationArray[IdentityProviderListResponse], error)` **get** `/{accounts_or_zones}/{account_or_zone_id}/access/identity_providers` Lists all configured identity providers. ### Parameters - `params IdentityProviderListParams` - `AccountID param.Field[string]` Path param: The Account ID to use for this endpoint. Mutually exclusive with the Zone ID. - `ZoneID param.Field[string]` Path param: The Zone ID to use for this endpoint. Mutually exclusive with the Account ID. - `Page param.Field[int64]` Query param: Page number of results. - `PerPage param.Field[int64]` Query param: Number of results per page. - `SCIMEnabled param.Field[string]` Query param: Indicates to Access to only retrieve identity providers that have the System for Cross-Domain Identity Management (SCIM) enabled. ### Returns - `type IdentityProviderListResponse interface{…}` - `type AzureAD struct{…}` - `Config AzureADConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `ConditionalAccessEnabled bool` Should Cloudflare try to load authentication contexts from your account - `DirectoryID string` Your Azure directory uuid - `EmailClaimName string` The claim name for email in the id_token response. - `Prompt AzureADConfigPrompt` Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn't presented with any interactive prompt. If the request can't be completed silently by using single-sign on, the Microsoft identity platform returns an interaction_required error. prompt=select_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether. - `const AzureADConfigPromptLogin AzureADConfigPrompt = "login"` - `const AzureADConfigPromptSelectAccount AzureADConfigPrompt = "select_account"` - `const AzureADConfigPromptNone AzureADConfigPrompt = "none"` - `SupportGroups bool` Should Cloudflare try to load groups from your account - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `const IdentityProviderTypeOnetimepin IdentityProviderType = "onetimepin"` - `const IdentityProviderTypeAzureAD IdentityProviderType = "azureAD"` - `const IdentityProviderTypeSAML IdentityProviderType = "saml"` - `const IdentityProviderTypeCentrify IdentityProviderType = "centrify"` - `const IdentityProviderTypeFacebook IdentityProviderType = "facebook"` - `const IdentityProviderTypeGitHub IdentityProviderType = "github"` - `const IdentityProviderTypeGoogleApps IdentityProviderType = "google-apps"` - `const IdentityProviderTypeGoogle IdentityProviderType = "google"` - `const IdentityProviderTypeLinkedin IdentityProviderType = "linkedin"` - `const IdentityProviderTypeOIDC IdentityProviderType = "oidc"` - `const IdentityProviderTypeOkta IdentityProviderType = "okta"` - `const IdentityProviderTypeOnelogin IdentityProviderType = "onelogin"` - `const IdentityProviderTypePingone IdentityProviderType = "pingone"` - `const IdentityProviderTypeYandex IdentityProviderType = "yandex"` - `const IdentityProviderTypeCloudflare IdentityProviderType = "cloudflare"` - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet AzureADSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate AzureADSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `Enabled bool` A flag to enable or disable SCIM for the identity provider. - `IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehavior` Indicates how a SCIM event updates a user identity used for policy evaluation. Use "automatic" to automatically update a user's identity and augment it with fields from the SCIM user resource. Use "reauth" to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With "reauth" identities will not contain fields from the SCIM user resource. With "no_action" identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate. - `const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"` - `const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"` - `const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no_action"` - `SCIMBaseURL string` The base URL of Cloudflare's SCIM V2.0 API endpoint. - `SeatDeprovision bool` A flag to remove a user's seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user_deprovision is also enabled. - `Secret string` A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity_providers/:idpID/refresh_scim_secret. - `UserDeprovision bool` A flag to enable revoking a user's session in Access and Gateway when they have been deprovisioned in the Identity Provider. - `type IdentityProviderListResponseAccessCentrify struct{…}` - `Config IdentityProviderListResponseAccessCentrifyConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `CentrifyAccount string` Your centrify account url - `CentrifyAppID string` Your centrify app id - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessCentrifySAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessCentrifySAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessFacebook struct{…}` - `Config GenericOAuthConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessFacebookSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessFacebookSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessGitHub struct{…}` - `Config GenericOAuthConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessGitHubSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessGitHubSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessGoogle struct{…}` - `Config IdentityProviderListResponseAccessGoogleConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessGoogleSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessGoogleSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessGoogleApps struct{…}` - `Config IdentityProviderListResponseAccessGoogleAppsConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `AppsDomain string` Your companies TLD - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessGoogleAppsSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessGoogleAppsSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessLinkedin struct{…}` - `Config GenericOAuthConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessLinkedinSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessLinkedinSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessOIDC struct{…}` - `Config IdentityProviderListResponseAccessOIDCConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `AuthURL string` The authorization_endpoint URL of your IdP - `CERTsURL string` The jwks_uri endpoint of your IdP to allow the IdP keys to sign the tokens - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `PKCEEnabled bool` Enable Proof Key for Code Exchange (PKCE) - `Scopes []string` OAuth scopes - `TokenURL string` The token_endpoint URL of your IdP - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessOIDCSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessOIDCSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessOkta struct{…}` - `Config IdentityProviderListResponseAccessOktaConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `AuthorizationServerID string` Your okta authorization server id - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `OktaAccount string` Your okta account url - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessOktaSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessOktaSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessOnelogin struct{…}` - `Config IdentityProviderListResponseAccessOneloginConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `OneloginAccount string` Your OneLogin account url - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessOneloginSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessOneloginSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessPingone struct{…}` - `Config IdentityProviderListResponseAccessPingoneConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `PingEnvID string` Your PingOne environment identifier - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessPingoneSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessPingoneSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessSAML struct{…}` - `Config IdentityProviderListResponseAccessSAMLConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Attributes []string` A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules. - `EmailAttributeName string` The attribute name for email in the SAML response. - `EnableEncryption bool` Enable SAML assertion encryption. When enabled, the Identity Provider will encrypt SAML assertions using the certificate from the assigned certificate set. To enable encryption: 1. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate` 1. Set this field to `true` and include `saml_certificate_set_id` in the PUT request 1. Configure the public certificate in your external Identity Provider Note: Requires `saml_certificate_set_id` to be set when `true`. - `HeaderAttributes []IdentityProviderListResponseAccessSAMLConfigHeaderAttribute` Add a list of attribute names that will be returned in the response header from the Access callback. - `AttributeName string` attribute name from the IDP - `HeaderName string` header that will be added on the request to the origin - `IdPPublicCERTs []string` X509 certificate to verify the signature in the SAML authentication response - `IssuerURL string` IdP Entity ID or Issuer URL - `SignRequest bool` Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints. - `SSOTargetURL string` URL to send the SAML authentication requests to - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessSAMLSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessSAMLSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessYandex struct{…}` - `Config GenericOAuthConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessYandexSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessYandexSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessOnetimepin struct{…}` - `Config IdentityProviderListResponseAccessOnetimepinConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `RedirectURL string` - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessOnetimepinSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessOnetimepinSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderListResponseAccessCloudflare struct{…}` - `Config IdentityProviderListResponseAccessCloudflareConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `RedirectURL string` - `RestrictToAccountMembers bool` When enabled, only users who are members of your Cloudflare account can authenticate through this identity provider. When disabled, any user with a Cloudflare account can authenticate, subject to your Access policies. - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderListResponseAccessCloudflareSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderListResponseAccessCloudflareSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. ### Example ```go package main import ( "context" "fmt" "github.com/cloudflare/cloudflare-go" "github.com/cloudflare/cloudflare-go/option" "github.com/cloudflare/cloudflare-go/zero_trust" ) func main() { client := cloudflare.NewClient( option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"), ) page, err := client.ZeroTrust.IdentityProviders.List(context.TODO(), zero_trust.IdentityProviderListParams{ }) if err != nil { panic(err.Error()) } fmt.Printf("%+v\n", page) } ``` #### Response ```json { "errors": [ { "code": 1000, "message": "message", "documentation_url": "documentation_url", "source": { "pointer": "pointer" } } ], "messages": [ { "code": 1000, "message": "message", "documentation_url": "documentation_url", "source": { "pointer": "pointer" } } ], "success": true, "result": [ { "config": { "claims": [ "email_verified", "preferred_username", "custom_claim_name" ], "client_id": "", "client_secret": "", "conditional_access_enabled": true, "directory_id": "", "email_claim_name": "custom_claim_name", "prompt": "login", "support_groups": true }, "name": "Widget Corps IDP", "type": "onetimepin", "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415", "read_only": true, "saml_certificate_set": { "created_at": "2026-05-07T19:16:19.821162Z", "uid": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8", "updated_at": "2026-05-07T19:16:19.821162Z", "current_certificate": { "is_current": true, "not_after": "2027-05-07T19:11:00Z", "public_certificate": "-----BEGIN CERTIFICATE-----\nMIIEpzCCA4+gAwIBAgIUTh2VSDDJ0oB/gabio6j1L9QwWoUwDQYJKoZIhvcNAQEL\n...\n-----END CERTIFICATE-----\n", "uid": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415" }, "previous_certificate": {} }, "saml_certificate_set_id": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8", "scim_config": { "enabled": true, "identity_update_behavior": "automatic", "scim_base_url": "scim_base_url", "seat_deprovision": true, "secret": "secret", "user_deprovision": true } } ], "result_info": { "count": 1, "page": 1, "per_page": 20, "total_count": 2000, "total_pages": 100 } } ```