Skip to content

Schema Profiles

Last updated View as MarkdownAgent setup

A Schema Profile models expected request fields and their constraints. You can learn one from traffic or supply an uploaded schema.

After a profile becomes available, Cloudflare runs an always-on detection. Detection does not mitigate requests by itself.

Learn from traffic

An operation is Cloudflare's term for an endpoint. Its identity combines an HTTP method, hostname pattern, and path pattern.

Web Assets continuously discovers operations under Web Assets > Operations. You can also add an operation manually.

Both methods only add operations to the inventory. To start profiling, select Learn profile from the operation overflow menu.

Meet traffic requirements

Learning runs weekly using qualifying traffic from the previous seven days. Only requests that received a 2xx response contribute.

The field-learning threshold requires 1,000 qualifying requests. The boundary-learning threshold requires 10,000 qualifying requests.

The field-learning threshold allows Cloudflare to learn request fields. The boundary-learning threshold allows Cloudflare to learn constraints such as numeric ranges and string lengths.

The first profile appears after the next weekly learning run. This can take up to seven days after meeting the relevant threshold.

Review learned content

From the operation overflow menu, select View details. The learned schema appears under Security overview.

Profiles can learn these request components where supported:

  • Path variables
  • Query parameters
  • Headers and cookies
  • JSON request bodies
  • Form-encoded request bodies

Profiles can validate integers, strings, universally unique identifiers (UUIDs), and arrays. Supported constraints include numeric ranges, string lengths, character classes, and enumerations containing up to three values.

Successful traffic can include bots, scanners, or malicious requests. Review the learned profile before enforcing its detection.

Each weekly run can update a profile as qualifying traffic changes. For a fixed schema, export the learned schema as OpenAPI and upload it for validation.

Consider limitations

Learned Schema Profiles have these limitations:

  • Multipart forms, GraphQL, and XML are unsupported.
  • Repeated parameters have each value validated, without uniqueness enforcement.
  • Required parameter presence is not enforced.
  • New parameters alone do not produce violations.
  • Constraints apply to learned fields, not a complete allowlist.

Use an uploaded schema

An uploaded OpenAPI schema supplies expected structure instead of observed traffic. It produces detections through cf.schema_validation.uploaded.violated.

API Shield provides the detailed Schema validation reference. It covers supported versions, import procedures, OpenAPI fields, body limits, and troubleshooting.

For automation, refer to the API and Terraform instructions.

Was this helpful?