## Update an Access identity provider `client.ZeroTrust.IdentityProviders.Update(ctx, identityProviderID, params) (*IdentityProvider, error)` **put** `/{accounts_or_zones}/{account_or_zone_id}/access/identity_providers/{identity_provider_id}` Updates a configured identity provider. ### Parameters - `identityProviderID string` UUID. - `params IdentityProviderUpdateParams` - `AzureAD param.Field[AzureAD]` Body param - `AccountID param.Field[string]` Path param: The Account ID to use for this endpoint. Mutually exclusive with the Zone ID. - `ZoneID param.Field[string]` Path param: The Zone ID to use for this endpoint. Mutually exclusive with the Account ID. ### Returns - `type IdentityProvider interface{…}` - `type AzureAD struct{…}` - `Config AzureADConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `ConditionalAccessEnabled bool` Should Cloudflare try to load authentication contexts from your account - `DirectoryID string` Your Azure directory uuid - `EmailClaimName string` The claim name for email in the id_token response. - `Prompt AzureADConfigPrompt` Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn't presented with any interactive prompt. If the request can't be completed silently by using single-sign on, the Microsoft identity platform returns an interaction_required error. prompt=select_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether. - `const AzureADConfigPromptLogin AzureADConfigPrompt = "login"` - `const AzureADConfigPromptSelectAccount AzureADConfigPrompt = "select_account"` - `const AzureADConfigPromptNone AzureADConfigPrompt = "none"` - `SupportGroups bool` Should Cloudflare try to load groups from your account - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `const IdentityProviderTypeOnetimepin IdentityProviderType = "onetimepin"` - `const IdentityProviderTypeAzureAD IdentityProviderType = "azureAD"` - `const IdentityProviderTypeSAML IdentityProviderType = "saml"` - `const IdentityProviderTypeCentrify IdentityProviderType = "centrify"` - `const IdentityProviderTypeFacebook IdentityProviderType = "facebook"` - `const IdentityProviderTypeGitHub IdentityProviderType = "github"` - `const IdentityProviderTypeGoogleApps IdentityProviderType = "google-apps"` - `const IdentityProviderTypeGoogle IdentityProviderType = "google"` - `const IdentityProviderTypeLinkedin IdentityProviderType = "linkedin"` - `const IdentityProviderTypeOIDC IdentityProviderType = "oidc"` - `const IdentityProviderTypeOkta IdentityProviderType = "okta"` - `const IdentityProviderTypeOnelogin IdentityProviderType = "onelogin"` - `const IdentityProviderTypePingone IdentityProviderType = "pingone"` - `const IdentityProviderTypeYandex IdentityProviderType = "yandex"` - `const IdentityProviderTypeCloudflare IdentityProviderType = "cloudflare"` - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet AzureADSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate AzureADSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `Enabled bool` A flag to enable or disable SCIM for the identity provider. - `IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehavior` Indicates how a SCIM event updates a user identity used for policy evaluation. Use "automatic" to automatically update a user's identity and augment it with fields from the SCIM user resource. Use "reauth" to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With "reauth" identities will not contain fields from the SCIM user resource. With "no_action" identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate. - `const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"` - `const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"` - `const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no_action"` - `SCIMBaseURL string` The base URL of Cloudflare's SCIM V2.0 API endpoint. - `SeatDeprovision bool` A flag to remove a user's seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user_deprovision is also enabled. - `Secret string` A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity_providers/:idpID/refresh_scim_secret. - `UserDeprovision bool` A flag to enable revoking a user's session in Access and Gateway when they have been deprovisioned in the Identity Provider. - `type IdentityProviderAccessCentrify struct{…}` - `Config IdentityProviderAccessCentrifyConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `CentrifyAccount string` Your centrify account url - `CentrifyAppID string` Your centrify app id - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessCentrifySAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessCentrifySAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessFacebook struct{…}` - `Config GenericOAuthConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessFacebookSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessFacebookSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessGitHub struct{…}` - `Config GenericOAuthConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessGitHubSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessGitHubSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessGoogle struct{…}` - `Config IdentityProviderAccessGoogleConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessGoogleSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessGoogleSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessGoogleApps struct{…}` - `Config IdentityProviderAccessGoogleAppsConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `AppsDomain string` Your companies TLD - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessGoogleAppsSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessGoogleAppsSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessLinkedin struct{…}` - `Config GenericOAuthConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessLinkedinSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessLinkedinSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessOIDC struct{…}` - `Config IdentityProviderAccessOIDCConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `AuthURL string` The authorization_endpoint URL of your IdP - `CERTsURL string` The jwks_uri endpoint of your IdP to allow the IdP keys to sign the tokens - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `PKCEEnabled bool` Enable Proof Key for Code Exchange (PKCE) - `Scopes []string` OAuth scopes - `TokenURL string` The token_endpoint URL of your IdP - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessOIDCSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessOIDCSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessOkta struct{…}` - `Config IdentityProviderAccessOktaConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `AuthorizationServerID string` Your okta authorization server id - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `OktaAccount string` Your okta account url - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessOktaSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessOktaSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessOnelogin struct{…}` - `Config IdentityProviderAccessOneloginConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `OneloginAccount string` Your OneLogin account url - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessOneloginSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessOneloginSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessPingone struct{…}` - `Config IdentityProviderAccessPingoneConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Claims []string` Custom claims - `ClientID string` Your OAuth Client ID - `ClientSecret string` Your OAuth Client Secret - `EmailClaimName string` The claim name for email in the id_token response. - `PingEnvID string` Your PingOne environment identifier - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessPingoneSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessPingoneSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessSAML struct{…}` - `Config IdentityProviderAccessSAMLConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Attributes []string` A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules. - `EmailAttributeName string` The attribute name for email in the SAML response. - `EnableEncryption bool` Enable SAML assertion encryption. When enabled, the Identity Provider will encrypt SAML assertions using the certificate from the assigned certificate set. To enable encryption: 1. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate` 1. Set this field to `true` and include `saml_certificate_set_id` in the PUT request 1. Configure the public certificate in your external Identity Provider Note: Requires `saml_certificate_set_id` to be set when `true`. - `HeaderAttributes []IdentityProviderAccessSAMLConfigHeaderAttribute` Add a list of attribute names that will be returned in the response header from the Access callback. - `AttributeName string` attribute name from the IDP - `HeaderName string` header that will be added on the request to the origin - `IdPPublicCERTs []string` X509 certificate to verify the signature in the SAML authentication response - `IssuerURL string` IdP Entity ID or Issuer URL - `SignRequest bool` Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints. - `SSOTargetURL string` URL to send the SAML authentication requests to - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessSAMLSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessSAMLSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessYandex struct{…}` - `Config GenericOAuthConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessYandexSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessYandexSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessOnetimepin struct{…}` - `Config IdentityProviderAccessOnetimepinConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `RedirectURL string` - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessOnetimepinSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessOnetimepinSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. - `type IdentityProviderAccessCloudflare struct{…}` - `Config IdentityProviderAccessCloudflareConfig` The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `RedirectURL string` - `RestrictToAccountMembers bool` When enabled, only users who are members of your Cloudflare account can authenticate through this identity provider. When disabled, any user with a Cloudflare account can authenticate, subject to your Access policies. - `Name string` The name of the identity provider, shown to users on the login page. - `Type IdentityProviderType` The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/identity/idp-integration/). - `ID string` UUID. - `ReadOnly bool` Indicates that the identity provider is immutable and cannot be updated or deleted via the API. - `SAMLCertificateSet IdentityProviderAccessCloudflareSAMLCertificateSet` The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned. - `CreatedAt Time` Timestamp when the certificate set was created - `UID string` Unique identifier for the certificate set - `UpdatedAt Time` Timestamp when the certificate set was last updated (e.g., during rotation) - `CurrentCertificate IdentityProviderAccessCloudflareSAMLCertificateSetCurrentCertificate` The currently active certificate used for encrypting SAML assertions - `IsCurrent bool` Indicates whether this is the currently active certificate - `NotAfter Time` Certificate expiration date. Certificates are automatically rotated 30 days before expiration. - `PublicCertificate string` PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption. - `UID string` Unique identifier for the certificate - `PreviousCertificate unknown` The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`. - `SAMLCertificateSetID string` The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`. - `SCIMConfig IdentityProviderSCIMConfig` The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. ### Example ```go package main import ( "context" "fmt" "github.com/cloudflare/cloudflare-go" "github.com/cloudflare/cloudflare-go/option" "github.com/cloudflare/cloudflare-go/zero_trust" ) func main() { client := cloudflare.NewClient( option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"), ) identityProvider, err := client.ZeroTrust.IdentityProviders.Update( context.TODO(), "f174e90a-fafe-4643-bbbc-4a0ed4fc8415", zero_trust.IdentityProviderUpdateParams{ IdentityProvider: zero_trust.AzureADParam{ Config: cloudflare.F(zero_trust.AzureADConfigParam{ }), Name: cloudflare.F("Widget Corps IDP"), Type: cloudflare.F(zero_trust.IdentityProviderTypeOnetimepin), }, }, ) if err != nil { panic(err.Error()) } fmt.Printf("%+v\n", identityProvider) } ``` #### Response ```json { "errors": [ { "code": 1000, "message": "message", "documentation_url": "documentation_url", "source": { "pointer": "pointer" } } ], "messages": [ { "code": 1000, "message": "message", "documentation_url": "documentation_url", "source": { "pointer": "pointer" } } ], "success": true, "result": { "config": { "claims": [ "email_verified", "preferred_username", "custom_claim_name" ], "client_id": "", "client_secret": "", "conditional_access_enabled": true, "directory_id": "", "email_claim_name": "custom_claim_name", "prompt": "login", "support_groups": true }, "name": "Widget Corps IDP", "type": "onetimepin", "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415", "read_only": true, "saml_certificate_set": { "created_at": "2026-05-07T19:16:19.821162Z", "uid": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8", "updated_at": "2026-05-07T19:16:19.821162Z", "current_certificate": { "is_current": true, "not_after": "2027-05-07T19:11:00Z", "public_certificate": "-----BEGIN CERTIFICATE-----\nMIIEpzCCA4+gAwIBAgIUTh2VSDDJ0oB/gabio6j1L9QwWoUwDQYJKoZIhvcNAQEL\n...\n-----END CERTIFICATE-----\n", "uid": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415" }, "previous_certificate": {} }, "saml_certificate_set_id": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8", "scim_config": { "enabled": true, "identity_update_behavior": "automatic", "scim_base_url": "scim_base_url", "seat_deprovision": true, "secret": "secret", "user_deprovision": true } } } ```