---
title: Enable Content Scanning for a zone.
---

[Skip to content](#%5Ftop) 

[API Reference](https://developers.cloudflare.com/api/typescript)

[Content Scanning](https://developers.cloudflare.com/api/typescript/resources/content%5Fscanning)

Copy Markdown

Open in **Claude**

Open in **ChatGPT**

Open in **Cursor**

---

**Copy Markdown**

**View as Markdown**

# Enable Content Scanning for a zone.

client.contentScanning.enable(ContentScanningEnableParams { zone\_id } params, RequestOptionsoptions?): [ContentScanningEnableResponse](https://developers.cloudflare.com/api/typescript/resources/content%5Fscanning#%28resource%29%20content%5Fscanning%20%3E%20%28model%29%20content%5Fscanning%5Fenable%5Fresponse%20%3E%20%28schema%29)

POST/zones/{zone\_id}/content-upload-scan/enable

Enable Content Scanning for a zone, so that Cloudflare inspects content objects uploaded to the zone and checks them for malware. Scan results populate the `cf.waf.content_scan.*` fields, which you can reference in custom rules and rate limiting rules.

##### Security

API Token

The preferred authorization scheme for interacting with the Cloudflare API. [Create a token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/).

**Example:**`Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY`

API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**`X-Auth-Email: user@example.com`

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**`X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194`

##### Accepted Permissions (at least one required)

`Zone WAF Write` `Account WAF Write`

##### ParametersExpand Collapse 

params: ContentScanningEnableParams { zone\_id } 

zone\_id: string

Defines an identifier.

maxLength32

##### ReturnsExpand Collapse 

ContentScanningEnableResponse \= unknown

### Enable Content Scanning for a zone.

TypeScript

HTTPHTTP

TypeScriptTypeScript

PythonPython

GoGo

TerraformTerraform

```
import Cloudflare from 'cloudflare';

const client = new Cloudflare({
  apiToken: process.env['CLOUDFLARE_API_TOKEN'], // This is the default and can be omitted
});

const response = await client.contentScanning.enable({
  zone_id: '023e105f4ecef8ad9ca31a8372d0c353',
});

console.log(response);
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {},
  "success": true
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {},
  "success": true
}
```