Cloudflare MCP Server & CLI

An open source focused Cloudflare MCP and shared CLI with 29 tools, private profiles and explicit mutation approval.

Navid Moazzezby Navid Moazzez·Updated 3. 10. 2026·97 min read·
Rate this tool
key_takeaways.mdTL;DR

Key takeaways

One shared implementation provides local MCP, a CLI and a versioned desktop bundle.
All eleven mutations require exact confirmation before provider execution.
Read-only hides mutations and refuses direct confirmed calls.
The reviewed DNS digest detects changes to the exact local zone, profile and JSON body.
Private profiles, current schemas and bounded pages keep account requests explicit.
Cloudflare already has broader official tools, and the guide compares their current strengths honestly.

This free Cloudflare MCP server and CLI gives your AI real access to current DNS, cache, zone settings, Rulesets, Worker metadata and read-only analytics. Inspect the selected zone and complete native input, preview locally, then submit only the exact change you approve.

It's one install with 2 ways in. Claude, Codex, Cursor or any other MCP app calls its 29 tools for you, and the same tools work as a CLI that agents like Claude Code, Codex and OpenCode run, or that you type yourself.

Here's what the Cloudflare MCP server and CLI is, how to set it up in each app, and every tool it has.

What is the Cloudflare MCP server & CLI?

The Cloudflare MCP server & CLI is a free, open source program that lets AI agents read zone/DNS information and perform specifically approved management requests for you, in 2 ways. The MCP server is what an AI app like Claude, Codex or Cursor connects to, through MCP (Model Context Protocol), the open standard AI apps use to call outside tools.

You ask in plain language. Your AI picks the right tool, and the server makes the call directly to the fixed Cloudflare API origin.

The CLI is the same program as commands. cloudflare-cli list-zones runs the same code your AI runs when you ask to inspect the zones accessible to your private token, whether an agent like Claude Code runs it or you do.

What can you ask it?

Once it's set up, you ask the way you'd ask an assistant. These are real prompts it handles:

Try asking
Read DNS for this exact zone without changing records.
Show the complete current schema for a DNS record.
Preview this small DNS batch locally.
Apply only the same reviewed zone, profile and JSON body.
Read the selected zone setting before approving a change.
Inspect current Rulesets and their entrypoint.
Query the eligible analytics dataset for this time window.

Cloudflare already offers Code Mode and service MCPs, the general cf CLI and Wrangler. This owned package adds consistent local mandatory confirmation, isolated private profiles, no automatic request replay and an exact-request DNS batch review. Official coverage is much broader; current pinned comparisons acknowledge profiles, dry-run, delete confirmation and sandboxed credential handling.

How to install the Cloudflare MCP server

Use the existing install box for local MCP, the shared CLI or the versioned desktop bundle. Codex is the primary documented agent; complete client and OS setup follows below.

Before you start0/3

Set up Cloudflare access

Private API tokens and resource access

  1. Choose the intended Cloudflare user/account and zone. Create a least-privilege API token through My Profile > API Tokens, or Manage account > Account API tokens for an account-owned token.
  2. Choose only the permissions needed below and restrict account/zone resources. Check optional expiry and IP filters. Save the secret privately outside every repository; never use the Global API Key with this Bearer-only package.
  3. Configure CLOUDFLARE_TOKEN_FILE as an absolute token-only file, or privately set CLOUDFLARE_API_TOKEN. Optional CLOUDFLARE_ACCOUNT_ID and CLOUDFLARE_ZONE_ID supply input defaults. A default does not restrict token permissions.
  4. Run cloudflare-cli doctor for local configuration checks. Deliberately run doctor --network to verify token status: user tokens use GET /user/tokens/verify; account-owned tokens need CLOUDFLARE_TOKEN_KIND=account and a private account ID, using GET /accounts/{account_id}/tokens/verify. Only an active result is accepted; token IDs/status bodies are not printed.
  5. Read the exact zone and DNS records, inspect the complete current input schema, preview the intended change locally and approve only the chosen request. A local preview does not verify provider permissions, conflicts or current remote state.

Requests use Authorization: Bearer on the fixed https://api.cloudflare.com/client/v4 origin. Token-kind selection changes the diagnostic route, not ordinary authorization or resource access. The wrapper does not implement OAuth login, refresh, saved official cf sessions, automatic .env loading or global CLI config ingestion. login prints instructions; it neither opens consent nor saves credentials.

User tokens inherit permitted user access. Account-owned tokens act as service principals; creation requires the provider's token-provisioning capability or Super Administrator role and grants cannot exceed the creator's permissions. Some products still have compatibility restrictions; verify the exact operation in the account-token compatibility documentation.

Discover zones / zone identity
Permission to review with the provider
Zone: Read
Resource scope
Intended zone(s)
Read DNS records
Permission to review with the provider
DNS: Read
Resource scope
Intended zone(s)
Create/edit/delete/batch DNS
Permission to review with the provider
DNS: Edit
Resource scope
Intended zone(s)
Purge cache
Permission to review with the provider
Cache Purge permission
Resource scope
Intended zone(s)
Read/change zone settings
Permission to review with the provider
Zone Settings: Read / Edit
Resource scope
Intended zone(s) and supported setting
Read/change a Ruleset
Permission to review with the provider
The permission for its Ruleset phase, such as zone WAF or Transform Rules read/edit
Resource scope
Intended zone(s); phase/plan restrictions apply
Worker script metadata
Permission to review with the provider
Workers Scripts: Read
Resource scope
Intended account(s)
Query analytics
Permission to review with the provider
Analytics: Read and current dataset access
Resource scope
Intended account/zone(s)
Read Page Rules
Permission to review with the provider
Page Rules: Read
Resource scope
Intended zone(s)
List provider accounts
Permission to review with the provider
Account Settings: Read or provider-documented account listing grant
Resource scope
Accessible intended accounts

Review API token permissions and the selected endpoint's accepted grant list; this table is task guidance, not a complete static authorization manifest. Do not grant token-management, account administration or every zone solely for installation.

Use a private 0700 directory and regular 0600 token-only file on macOS/Linux. Windows users must restrict the file ACL to their own user; POSIX checks do not establish Windows ACL protection. Token files cannot be symlinks or exceed 64 KiB. File credentials override environment credentials and are cached until restart. GUI applications may have a different environment from your terminal.

Plans and limits

This AGPL wrapper is free; Cloudflare services and plan restrictions remain separate. DNS, proxy, cache purge, setting values, Ruleset phases and analytics availability are controlled by Cloudflare. Read metadata for the selected setting or dataset rather than assuming every write is allowed on every plan.

Current general API limits list 1200 requests per five minutes for a user/account token and 200 per second per IP, with cumulative user limits and endpoint-specific exceptions. Other sessions and processes consume the same upstream quota. Local pacing defaults to 200 ms per profile/process; it does not reserve quota. No reads or mutations retry automatically after 429, timeout, network failure or HTTP 200 provider errors. Wait according to current provider response/reset policy and inspect state before a deliberate repeat.

GraphQL analytics limits separately describe a default 300-query/five-minute user quota, up to ten zones or one account per scoped query, and dataset-specific retention/record limits. The general limits table uses a different GraphQL maximum figure; use the current analytics rules and returned policy for the actual query. Account-based limiting can be enabled through provider controls; the wrapper does not opt you into it. Inspect the provider's settings node for your dataset and resource. Adaptive analytics may be sampled; an aggregate is not necessarily an exact event ledger.

Reviewed DNS batches have a local cap of 1–50 total actions, deliberately below many provider plan limits. The underlying native batch command uses the reviewed source schema and provider limits. Request JSON is capped at 1 MiB; responses at 5 MiB; GraphQL query text at 64 KiB and 10000 parsed tokens; default timeout is 30 seconds. These caps do not raise Cloudflare quotas or plan allowances.

Rotation and revocation

Revoke or rotate the selected user/account token in its Cloudflare settings, update private configuration and restart every client using it. npm uninstall does not revoke the token, restore DNS, remove Rulesets or undo a cache purge. Keep account exports, DNS TXT values, signed URLs and diagnostic responses out of public issues.

Check that it works

Start with local configuration, then deliberately verify the configured user/account token route and active status without returning token details.

cloudflare-cli --version
cloudflare-cli doctor
cloudflare-cli doctor --network
cloudflare-cli list-accounts --agent
cloudflare-cli list-zones --per-page 10 --agent
cloudflare-cli doctor
cloudflare-cli doctor --network
cloudflare-cli list-accounts --agent
cloudflare-cli list-zones --per-page 10 --agent
cloudflare-cli get-zone --zone-id YOUR_ZONE_ID --agent

Local doctor reports configuration, not credentials validated. --network checks an active token through its configured token-kind route; it does not prove access to every endpoint. First provider read should be the exact zone needed for the task. Do not create DNS records or purge cache merely to verify installation.

Full discovery has 29 tools; CLOUDFLARE_READ_ONLY=1 hides eleven mutations and direct calls still refuse. Local helpers expose no tokens or provider IDs. A missing credential exits 10; a valid install is not proof of provider account access.

Use the Cloudflare CLI

The CLI is the same 29 tools as commands. AI agents that run commands, like Claude Code, Codex and OpenCode, use it on their own, and you can type the same commands in a terminal or a script.

Every tool name becomes a command with dashes, so get_dns_record runs as cloudflare-cli get-dns-record.

cloudflare-cli tools
cloudflare-cli create-dns-record --help
cloudflare-cli schema create-dns-record
cloudflare-cli list-zones --per-page 10 --agent
cloudflare-cli get-zone --zone-id YOUR_ZONE_ID --agent

The bare cloudflare-cli lists every command, and cloudflare-cli <command> --help shows what a command takes. All eleven mutations require --confirm. --agent/--yes do not approve changes. Use a complete native payload or payload_file; local previews do not validate provider permissions or state.

These flags work on every command:

FlagWhat it does
--jsonStructured JSON
--compactOne-line JSON
--agentCompact JSON without prompts/color; no mutation approval
--select a,b.cTrim local result after receipt
--confirmApprove the exact requested mutation
--account NAMESelect one private profile
--payload / --payload-fileOne complete native body, never both

A script can branch on the exit code:

Exit codeWhat it means
0Success
2Invalid input or refused mutation
3Not found
4Authentication/permission failure
5Provider/transport failure
7Rate limit
10No private credential configured

MCP server or CLI: which one?

Both surfaces call the same tools. Codex can connect to the local MCP server or run the CLI directly. Neither requires Claude Code.

MCP provides structured tool discovery; the CLI supports scripts, compact JSON, field selection and command/schema discovery. Official hosted MCP connection and local CLI authentication have different setup requirements.

Codex-specific token measurements are pending. Record the actual client/model versions, discovery configuration, input/output usage, caching, latency and equivalent successful outcomes. Standing definitions and full task cost are separate measurements; CLI commands, selected help, results and reasoning still consume tokens.

No efficiency percentage or Claude-derived figure is presented as a Codex result. Other-client benchmarks can be added separately.

DNS, Rulesets, cache and analytics workflows

A deliberate DNS change

Read list_zones, get_zone and list_dns_records to establish the exact zone and record. Inspect get_operation_schema for create_dns_record or update_dns_record. A PATCH edits provided fields; a PUT replacement can alter omitted-field behavior. Choose ttl/proxied/type/content deliberately rather than assuming every record should be proxied. DNS conflicts, plan constraints and semantic validity are finally decided by Cloudflare.

cloudflare-cli preview-operation --operation create_dns_record --arguments '{"zone_id":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa","payload":{"name":"review.example.com","type":"A","content":"192.0.2.1","ttl":1,"proxied":false}}' --agent
cloudflare-cli create-dns-record --zone-id YOUR_ZONE_ID --payload-file /absolute/private/approved-dns.json --account work --confirm --agent

The first command is a local illustration using documentation-only IDs/IPs. It makes no provider request. The second is a real mutation only when private credentials, a real resource and the explicitly approved body are supplied. After any approved change, read the returned record and check the intended resolver/service.

Review a small DNS batch

Save only the chosen native deletes/patches/puts/posts body in a private JSON file. preview_dns_batch validates the same native schema and 1–50 total-action cap, then returns a SHA-256 digest of method, exact zone path, profile label and canonically sorted JSON object keys. Array order is preserved. Read and approve the full body, target and profile before apply_dns_batch.

cloudflare-cli preview-dns-batch --zone-id YOUR_ZONE_ID --payload-file /absolute/private/approved-dns-batch.json --account work --agent
cloudflare-cli apply-dns-batch --zone-id YOUR_ZONE_ID --payload-file /absolute/private/approved-dns-batch.json --account work --preview-sha256 REVIEWED_64_CHARACTER_HASH --confirm --agent

Any change to that reviewed request requires a new preview. This does not detect concurrent remote edits, credential rotation under the same label or changes in token grants. The digest is not an authorization secret, human approval signature or remote-state transaction lock. The direct native batch_dns_records command also exists, requires --confirm and does not require a digest; choose the review/apply workflow when you need exact local review.

Cloudflare batch semantics execute deletes, patches, puts, then posts in a database transaction; distributed DNS propagation remains non-atomic. If provider validation fails, no batch changes apply. A network failure after submission can leave the outcome unknown; read the affected records before repeating. The wrapper never promises all resolvers change at once or supplies a rollback.

Settings and Rulesets

get_zone_setting with setting_id=ssl replaces the older SSL helper. Inspect the setting's editable/value metadata before update_zone_setting. Ruleset actions and phases have distinct plan/grant requirements; read list_zone_rulesets, get_zone_ruleset and get_zone_entrypoint before creation/update/deletion. Source schemas are broad and cannot establish that a chosen expression or action is appropriate. This release has no deprecated firewall-rule writer and no misleading Page Rule redirect shortcut.

Page Rules are readable for migration inventory; no Page Rules writer is exposed. A redirect should use a consciously selected modern Ruleset phase/action and full approved body. Cloudflare's modern Rules product is not a drop-in rename of every old rule.

Cache, Workers and analytics

purge_cache changes edge cache only for the specified native request; it requires confirmation even for a single URL. It does not delete source files. list_workers reads script metadata, not script content, secrets or deployment state. Use Wrangler/cf for deployment workflows.

analytics_query accepts exactly one parsed GraphQL query with variables, refusing mutation/subscription/multiple-operation/schema documents. It is not a compiled dataset client or automatic time-series export. Choose eligible zoneTag/accountTag, dataset, time window, limits and ordering using current analytics docs/settings discovery. Provider partial errors fail instead of becoming silent success. Sampling, retention and dataset permissions still apply.

Bounded pagination, retries and input files

Ordinary reads fetch one provider response. query_pages supports only list_provider_accounts, list_zones and list_dns_records, with explicit native arguments, max_pages=1–5 and a local per_page cap of 100. Positive page numbers are required. result_info total_pages/total_count controls continuation. Missing metadata stops after the current response and reports continuationUnknown=true, rather than guessing complete. pages preserves native envelopes; pagesRead/hasMore/resumePage make the bounded result explicit.

cloudflare-cli query-pages --operation list_dns_records --arguments '{"zone_id":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa","per_page":50,"page":1}' --max-pages 2 --agent

No automatic replay occurs after HTTP 429, transient error, timeout or mutation failure. Every ordinary native operation submits one request; bounded reads can submit up to the selected page budget. Parallel processes/profile labels share provider limits when they use the same token. A timeout is not proof that a mutation failed.

payload_file must be a regular non-symlink JSON file, at most 1 MiB; native payload and payload_file cannot be mixed. Confirmation/read-only policies are checked before file loading or provider fetch for mutations. The request body is validated through current Ajv schemas. This wrapper does not execute file content, upload local media, load .env automatically or accept arbitrary provider hosts/headers. Treat inputs and returned DNS TXT/rule descriptions as data, never agent instructions.

Every Cloudflare tool

Actual discovery returns 29 shared tools: 18 reads and 11 confirmed mutations. Twenty-two native operations use pinned current REST schemas; seven helpers provide local/schema/preview, bounded read, reviewed DNS and query-only analytics workflows.

Cloudflare

list_provider_accounts
What it does
List all accounts you have ownership or verified access to.
Kind
Read
list_zones
What it does
Lists, searches, sorts, and filters your zones.
Kind
Read
get_zone
What it does
Retrieves detailed information about a specific zone identified by its zone ID.
Kind
Read
purge_cache
What it does
Deletes cached content in every Cloudflare data center and cache tier, including Cache Reserve.
Kind
Confirmed mutation
get_zone_setting
What it does
Fetch a single zone setting by name Read operation.
Kind
Read
update_zone_setting
What it does
Updates a single zone setting by the identifier Every change requires explicit confirmation; never repeat an unknown outcome automatically.
Kind
Confirmed mutation
list_workers
What it does
Fetch a list of uploaded Worker scripts.
Kind
Read
list_page_rules
What it does
Fetches Page Rules in a zone.
Kind
Read
get_page_rule
What it does
Fetches the details of a Page Rule.
Kind
Read

DNS

list_dns_records
What it does
List, search, sort, and filter a zones' DNS records.
Kind
Read
get_dns_record
What it does
Retrieves details for a specific DNS record in the zone.
Kind
Read
create_dns_record
What it does
Create a new DNS record for a zone.
Kind
Confirmed mutation
update_dns_record
What it does
Update an existing DNS record.
Kind
Confirmed mutation
overwrite_dns_record
What it does
Overwrite an existing DNS record.
Kind
Confirmed mutation
delete_dns_record
What it does
Permanently removes a DNS record from the zone.
Kind
Confirmed mutation
batch_dns_records
What it does
Send a Batch of DNS Record API calls to be executed together.
Kind
Confirmed mutation

Rulesets

list_zone_rulesets
What it does
Fetches all rulesets at the zone level.
Kind
Read
get_zone_ruleset
What it does
Fetches the latest version of a zone ruleset.
Kind
Read
get_zone_entrypoint
What it does
Fetches the latest version of the zone entry point ruleset for a given phase.
Kind
Read
create_zone_ruleset
What it does
Creates a ruleset at the zone level.
Kind
Confirmed mutation
update_zone_ruleset
What it does
Updates a zone ruleset, creating a new version.
Kind
Confirmed mutation
delete_zone_ruleset
What it does
Deletes all versions of an existing zone ruleset.
Kind
Confirmed mutation

Local

list_accounts
What it does
Local profile labels/default/auth method only.
Kind
Read
get_operation_schema
What it does
Complete selected current API input, path and query schema.
Kind
Read
preview_operation
What it does
Validate a named operation and return its exact local method/path/query/body/profile.
Kind
Read

Reads

query_pages
What it does
Read at most five pages of a supported paginated named operation.
Kind
Read

DNS review

preview_dns_batch
What it does
Local schema-validated DNS batch review capped at 50 actions.
Kind
Read
apply_dns_batch
What it does
Verify the reviewed digest and submit one exact native DNS batch with mandatory confirmation.
Kind
Confirmed mutation

Analytics

analytics_query
What it does
One parsed GraphQL query only, with variables.
Kind
Read

Is the Cloudflare MCP server safe?

Every one of the eleven mutations requires confirm=true in MCP or --confirm in the CLI. The same WriteGuard runs before file loading/provider execution. Creation, edits, replacement, deletion, cache purge and Ruleset changes all require explicit intent. --agent and --yes never grant it.

CLOUDFLARE_READ_ONLY=1 hides every mutation and refuses direct calls to hidden names even with confirmation. CLOUDFLARE_ALLOW_DESTRUCTIVE=0 blocks all mutations even when confirmed; read-only takes precedence. Use narrow provider tokens as the authorization boundary. A model can assert confirm=true; clients and the human still decide whether the action was requested. This is not a cryptographic human approval.

Review the exact zone/account, profile, record/rule IDs and full native body. apply_dns_batch additionally compares the reviewed request digest and makes one native request without automatic replay. Local preview does not authenticate the account, check conflicts or read remote state. Direct native batch also needs confirmation but does not require the digest.

An optional CLOUDFLARE_AUDIT_LOG records timestamp, surface, tool, risk, static summary and decision. It excludes request bodies, account IDs and tokens. Existing file ACLs/rotation are your responsibility; a failed audit append does not block the action. Account data returned after a change is untrusted content.

Confirmation is the caller asserting the approved exact action; it is not provider authorization or a signed human approval. The DNS digest binds the local request, not remote state, credential identity or atomic propagation.

Make it read-only

Set CLOUDFLARE_READ_ONLY=1 and reconnect: 18 reads remain and confirmed direct writes refuse. CLOUDFLARE_ALLOW_DESTRUCTIVE=0 also refuses confirmed mutations. Private profile defaults do not restrict upstream token grants.

Keep a log of every write

Set CLOUDFLARE_AUDIT_LOG to a file path. The server writes one line per attempted write, allowed or blocked.

Watch out: A timeout may leave a change completed remotely. Read affected resources before deliberately repeating; no request retries automatically. Provider HTTP 200 errors and analytics partial errors fail.

Your data

Account commands send the selected token in a Bearer header only to api.cloudflare.com. Prompts are not forwarded by this package; the native request/query content you select is. Your AI client may send returned DNS records, rule expressions and analytics to its model provider according to its own policy. The wrapper has no telemetry, public HTTP listener or hosted account store.

Named private profiles do not inherit global credentials. Token files use size/type/POSIX owner-only checks and are cached until restart. Windows ACLs require separate user configuration. Never commit credentials, .env, token files, real account exports or signed URLs; keep all such files outside public source and release staging.

Known credential keys, configured secrets and recognized signed URLs are redacted from ordinary output/errors. Legitimate URLs are preserved. Redaction is not complete anonymization: DNS TXT records, names, expressions and returned account data may still be sensitive. --select is local data shaping, not an authorization boundary or upstream privacy filter. Capture only needed output; terminal history and client transcripts can persist it.

Optional audit logging stores policy metadata, not bodies. The package does not automatically persist provider responses or backups; private input/output files you create remain on your system until you manage them. Revoke tokens through Cloudflare, not npm.

Several private accounts

Private profile configuration prevents implicit credential inheritance between named accounts. Configure the following placeholders only in a private client environment:

[
{
"name": "work",
"token_file": "/absolute/private/work-cloudflare.txt",
"account_id": "YOUR_WORK_ACCOUNT_ID",
"zone_id": "YOUR_WORK_ZONE_ID",
"token_kind": "user"
},
{
"name": "client",
"token_file": "/absolute/private/client-cloudflare.txt",
"account_id": "YOUR_CLIENT_ACCOUNT_ID",
"zone_id": "YOUR_CLIENT_ZONE_ID",
"token_kind": "account"
}
]

Put the array in CLOUDFLARE_ACCOUNTS and set CLOUDFLARE_DEFAULT_ACCOUNT=work. Names must be unique and nonempty. --account selects the exact label; list_accounts returns only label/default/auth method, never token values, file paths or provider IDs. A profile lacking credentials does not fall back to a global token. Global account/zone defaults likewise do not leak into explicitly named entries.

account_id/zone_id are routing defaults; explicit operation inputs take precedence and can name another resource allowed by the token. Token-kind defaults to user and only changes the diagnostic verification route. Use provider token resource scopes for real access boundaries. Local profile separation is not a multi-user access-control service.

Cloudflare MCP server settings

Configure these in private shell/user-client settings; no automatic .env loading or global official CLI credentials are used.

CLOUDFLARE_API_TOKEN
Default
Credentials
What it does
Private Bearer API token; no Global API Key support
CLOUDFLARE_TOKEN_FILE
Default
Credentials
What it does
Absolute regular owner-only token-only file; max 64 KiB; takes precedence
CLOUDFLARE_ACCOUNTS
Default
Credentials
What it does
Private JSON array of explicit named profiles; no global credential/default inheritance
CLOUDFLARE_DEFAULT_ACCOUNT
Default
Credentials
What it does
Exact profile name; first profile default when omitted
CLOUDFLARE_ACCOUNT_ID
Default
Credentials
What it does
Optional default account ID when using the single global profile
CLOUDFLARE_ZONE_ID
Default
Credentials
What it does
Optional default zone ID when using the single global profile
CLOUDFLARE_TOKEN_KIND
Default
Credentials
What it does
user (default) or account; doctor verification route only
CLOUDFLARE_READ_ONLY
Default
Safety
What it does
1/true hides/refuses every mutation
CLOUDFLARE_ALLOW_DESTRUCTIVE
Default
Safety
What it does
0/false refuses confirmed mutations; otherwise enabled
CLOUDFLARE_AUDIT_LOG
Default
Safety
What it does
Optional private append-only metadata path
CLOUDFLARE_REQUEST_TIMEOUT_MS
Default
Tuning
What it does
Default 30000; integer 100–300000; no automatic retry
CLOUDFLARE_MIN_REQUEST_INTERVAL_MS
Default
Tuning
What it does
Default 200; integer 0–10000; per profile/process

Troubleshooting

Run the doctor first. It names the step that failed and the fix.

What you seeWhat to do
Exit 10Check selected private token/file and GUI environment.
401/403Check intended resource, token grants, expiry/IP filters and membership.
Doctor status failsSet user/account token kind; account verification needs the account ID; only active status succeeds.
Mutation refusedConfirm only the human-requested action and inspect policy.
Native body invalidUse complete type-specific current payload schema.
Batch digest changedRe-preview the exact body, zone and profile.
Continuation unknownMissing result_info stops; do not claim complete.
HTTP 200 failureInspect provider success/errors or analytics partial errors.
429 / timeoutWait for upstream policy and inspect remote state before deliberate retry.
Missing analyticsDataset grant, plan, settings/time window, retention and sampling.
Expected deployment/OAuthUse official cf, Wrangler or hosted MCP for those workflows.
Desktop rejectedCheck actual host/runtime, extension policy and private settings.

If the server doesn't show up in your app at all, run the command your app runs, in a terminal, and read the error.

Every argument and nested native input

Twenty-two current native operations and seven helpers. Each schema below comes from actual stdio discovery. Native payload bodies preserve required keys, enums, unions, nested references and source constraints. Missing zone_id/account_id may use the selected private profile default; other required arguments remain required. Confirmation is enforced outside ordinary schema-required lists.

list_provider_accounts
CLI command
cloudflare-cli list-provider-accounts
Policy
Read / local helper
list_zones
CLI command
cloudflare-cli list-zones
Policy
Read / local helper
get_zone
CLI command
cloudflare-cli get-zone
Policy
Read / local helper
list_dns_records
CLI command
cloudflare-cli list-dns-records
Policy
Read / local helper
get_dns_record
CLI command
cloudflare-cli get-dns-record
Policy
Read / local helper
create_dns_record
CLI command
cloudflare-cli create-dns-record
Policy
Explicit confirmation required
update_dns_record
CLI command
cloudflare-cli update-dns-record
Policy
Explicit confirmation required
overwrite_dns_record
CLI command
cloudflare-cli overwrite-dns-record
Policy
Explicit confirmation required
delete_dns_record
CLI command
cloudflare-cli delete-dns-record
Policy
Explicit confirmation required
batch_dns_records
CLI command
cloudflare-cli batch-dns-records
Policy
Explicit confirmation required
purge_cache
CLI command
cloudflare-cli purge-cache
Policy
Explicit confirmation required
get_zone_setting
CLI command
cloudflare-cli get-zone-setting
Policy
Read / local helper
update_zone_setting
CLI command
cloudflare-cli update-zone-setting
Policy
Explicit confirmation required
list_workers
CLI command
cloudflare-cli list-workers
Policy
Read / local helper
list_zone_rulesets
CLI command
cloudflare-cli list-zone-rulesets
Policy
Read / local helper
get_zone_ruleset
CLI command
cloudflare-cli get-zone-ruleset
Policy
Read / local helper
get_zone_entrypoint
CLI command
cloudflare-cli get-zone-entrypoint
Policy
Read / local helper
create_zone_ruleset
CLI command
cloudflare-cli create-zone-ruleset
Policy
Explicit confirmation required
update_zone_ruleset
CLI command
cloudflare-cli update-zone-ruleset
Policy
Explicit confirmation required
delete_zone_ruleset
CLI command
cloudflare-cli delete-zone-ruleset
Policy
Explicit confirmation required
list_page_rules
CLI command
cloudflare-cli list-page-rules
Policy
Read / local helper
get_page_rule
CLI command
cloudflare-cli get-page-rule
Policy
Read / local helper
list_accounts
CLI command
cloudflare-cli list-accounts
Policy
Read / local helper
get_operation_schema
CLI command
cloudflare-cli get-operation-schema
Policy
Read / local helper
preview_operation
CLI command
cloudflare-cli preview-operation
Policy
Read / local helper
query_pages
CLI command
cloudflare-cli query-pages
Policy
Read / local helper
preview_dns_batch
CLI command
cloudflare-cli preview-dns-batch
Policy
Read / local helper
apply_dns_batch
CLI command
cloudflare-cli apply-dns-batch
Policy
Explicit confirmation required
analytics_query
CLI command
cloudflare-cli analytics-query
Policy
Read / local helper

list_provider_accounts

cloudflare-cli list-provider-accounts

List all accounts you have ownership or verified access to. Read operation.

name
Required
No; body and guard rules apply
Type
string
Details
Name of the account.
page
Required
No; body and guard rules apply
Type
number
Details
Page number of paginated results. minimum: 1. default: 1.
per_page
Required
No; body and guard rules apply
Type
number
Details
Maximum number of results per page. minimum: 5. maximum: 50. default: 20.
direction
Required
No; body and guard rules apply
Type
string
Details
Direction to order results. Values: asc, desc.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /accounts; accounts-list-accounts. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

list_zones

cloudflare-cli list-zones

Lists, searches, sorts, and filters your zones. Listing zones across more than 500 accounts is currently not allowed. Read operation.

name
Required
No; body and guard rules apply
Type
string
Details
A domain name. Optional filter operators can be provided to extend refine the search: * equal (default) * not_equal * starts_with * ends_with * contains * starts_with_case_sensitive * ends_with_case_sensitive * contains_case_sensitive maxLength: 253.
status
Required
No; body and guard rules apply
Type
string
Details
Specify a zone status to filter by. Values: initializing, pending, active, moved.
type
Required
No; body and guard rules apply
Type
array
Details
Zone types to filter by. Multiple types can be specified as a comma-separated list (e.g., ?type=full,partial,secondary). When this parameter is not provided, zones with type "internal" are excluded from the results. Items: string.
account_id
Required
No; body and guard rules apply
Type
string
Details
Filter by an account ID.
account_name
Required
No; body and guard rules apply
Type
string
Details
An account Name. Optional filter operators can be provided to extend refine the search: * equal (default) * not_equal * starts_with * ends_with * contains * starts_with_case_sensitive * ends_with_case_sensitive * contains_case_sensitive maxLength: 253.
page
Required
No; body and guard rules apply
Type
number
Details
Page number of paginated results. minimum: 1. default: 1.
per_page
Required
No; body and guard rules apply
Type
number
Details
Number of zones per page. minimum: 5. maximum: 50. default: 20.
order
Required
No; body and guard rules apply
Type
string
Details
Field to order zones by. Values: name, status, account.id, account.name, plan.id.
direction
Required
No; body and guard rules apply
Type
string
Details
Direction to order zones. Values: asc, desc.
match
Required
No; body and guard rules apply
Type
string
Details
Whether to match all search requirements or at least one (any). Values: any, all. default: all.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /zones; zones-get. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

get_zone

cloudflare-cli get-zone

Retrieves detailed information about a specific zone identified by its zone ID.

Returns zone configuration, status, nameservers, and associated metadata. Read operation.

zone_id
Required
No; body and guard rules apply
Type
zones_identifier
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /zones/{zone_id}; zones-0-get. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

list_dns_records

cloudflare-cli list-dns-records

List, search, sort, and filter a zones' DNS records. Read operation.

zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
name
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record name. This is a convenience alias for name.exact.
name_exact
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record name. Name filters are case-insensitive.
name_contains
Required
No; body and guard rules apply
Type
string
Details
Substring of the DNS record name. Name filters are case-insensitive.
name_startswith
Required
No; body and guard rules apply
Type
string
Details
Prefix of the DNS record name. Name filters are case-insensitive.
name_endswith
Required
No; body and guard rules apply
Type
string
Details
Suffix of the DNS record name. Name filters are case-insensitive.
type
Required
No; body and guard rules apply
Type
dns-records_type
Details
See current schema
content
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record content. This is a convenience alias for content.exact.
content_exact
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record content. Content filters are case-insensitive.
content_contains
Required
No; body and guard rules apply
Type
string
Details
Substring of the DNS record content. Content filters are case-insensitive.
content_startswith
Required
No; body and guard rules apply
Type
string
Details
Prefix of the DNS record content. Content filters are case-insensitive.
content_endswith
Required
No; body and guard rules apply
Type
string
Details
Suffix of the DNS record content. Content filters are case-insensitive.
proxied
Required
No; body and guard rules apply
Type
dns-records_proxied
Details
See current schema
match
Required
No; body and guard rules apply
Type
dns-records_match
Details
See current schema
comment
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record comment. This is a convenience alias for comment.exact.
comment_present
Required
No; body and guard rules apply
Type
string
Details
If this parameter is present, only records with a comment are returned.
comment_absent
Required
No; body and guard rules apply
Type
string
Details
If this parameter is present, only records without a comment are returned.
comment_exact
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record comment. Comment filters are case-insensitive.
comment_contains
Required
No; body and guard rules apply
Type
string
Details
Substring of the DNS record comment. Comment filters are case-insensitive.
comment_startswith
Required
No; body and guard rules apply
Type
string
Details
Prefix of the DNS record comment. Comment filters are case-insensitive.
comment_endswith
Required
No; body and guard rules apply
Type
string
Details
Suffix of the DNS record comment. Comment filters are case-insensitive.
tag
Required
No; body and guard rules apply
Type
string
Details
Condition on the DNS record tag. Parameter values can be of the form : to search for an exact name:value pair, or just ` to search for records with a specific tag name regardless of its value. This is a convenience shorthand for the more powerful tag. parameters. Examples: - tag=important is equivalent to tag.present=important - tag=team:DNS is equivalent to tag.exact=team:DNS`
tag_present
Required
No; body and guard rules apply
Type
string
Details
Name of a tag which must be present on the DNS record. Tag filters are case-insensitive.
tag_absent
Required
No; body and guard rules apply
Type
string
Details
Name of a tag which must not be present on the DNS record. Tag filters are case-insensitive.
tag_exact
Required
No; body and guard rules apply
Type
string
Details
A tag and value, of the form :. The API will only return DNS records that have a tag named ` whose value is `. Tag filters are case-insensitive.
tag_contains
Required
No; body and guard rules apply
Type
string
Details
A tag and value, of the form :. The API will only return DNS records that have a tag named ` whose value contains `. Tag filters are case-insensitive.
tag_startswith
Required
No; body and guard rules apply
Type
string
Details
A tag and value, of the form :. The API will only return DNS records that have a tag named ` whose value starts with `. Tag filters are case-insensitive.
tag_endswith
Required
No; body and guard rules apply
Type
string
Details
A tag and value, of the form :. The API will only return DNS records that have a tag named ` whose value ends with `. Tag filters are case-insensitive.
search
Required
No; body and guard rules apply
Type
dns-records_search
Details
See current schema
tag_match
Required
No; body and guard rules apply
Type
dns-records_tag_match
Details
See current schema
page
Required
No; body and guard rules apply
Type
dns-records_page
Details
See current schema
per_page
Required
No; body and guard rules apply
Type
dns-records_per_page
Details
See current schema
order
Required
No; body and guard rules apply
Type
dns-records_order
Details
See current schema
direction
Required
No; body and guard rules apply
Type
dns-records_direction
Details
See current schema
include_shadow_metadata
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include shadow metadata in the meta field of each record in the response. See Shadowed records. default: False.
shadowed_by_name
Required
No; body and guard rules apply
Type
string
Details
Filters the response to records at or below the specified NS delegation name. NS, DS, and NSEC records at the delegation name are excluded because they are not shadowed by that delegation. Those record types are included only when they exist below the delegation. The value must be a non-apex subdomain of the zone. Requires include_shadow_metadata=true. See Shadowed records.
shadowing_name
Required
No; body and guard rules apply
Type
string
Details
Returns NS records that shadow the given name, searching at the name itself and each of its ancestor names within the zone, excluding the zone apex. The value must be a subdomain of the zone; the zone apex is not accepted. See Shadowed records.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /zones/{zone_id}/dns_records; dns-records-for-a-zone-list-dns-records. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

get_dns_record

cloudflare-cli get-dns-record

Retrieves details for a specific DNS record in the zone. Read operation.

dns_record_id
Required
Yes
Type
dns-records_identifier
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
include_shadow_metadata
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include shadow metadata in the meta field of each record in the response. See Shadowed records. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /zones/{zone_id}/dns_records/{dns_record_id}; dns-records-for-a-zone-dns-record-details. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

create_dns_record

cloudflare-cli create-dns-record

Create a new DNS record for a zone.

Notes: - A/AAAA records cannot exist on the same name as CNAME records. - NS records cannot exist on the same name as any other record type. - Domain names are always represented in Punycode, even if Unicode characters were used when creating the record. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
include_shadow_metadata
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include shadow metadata in the meta field of each record in the response. See Shadowed records. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

Native operation: POST /zones/{zone_id}/dns_records; dns-records-for-a-zone-create-dns-record. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

update_dns_record

cloudflare-cli update-dns-record

Update an existing DNS record.

Notes: - A/AAAA records cannot exist on the same name as CNAME records. - NS records cannot exist on the same name as any other record type. - Domain names are always represented in Punycode, even if Unicode characters were used when creating the record. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

dns_record_id
Required
Yes
Type
dns-records_identifier
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
include_shadow_metadata
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include shadow metadata in the meta field of each record in the response. See Shadowed records. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

Native operation: PATCH /zones/{zone_id}/dns_records/{dns_record_id}; dns-records-for-a-zone-patch-dns-record. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

overwrite_dns_record

cloudflare-cli overwrite-dns-record

Overwrite an existing DNS record.

Notes: - A/AAAA records cannot exist on the same name as CNAME records. - NS records cannot exist on the same name as any other record type. - Domain names are always represented in Punycode, even if Unicode characters were used when creating the record. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

dns_record_id
Required
Yes
Type
dns-records_identifier
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
include_shadow_metadata
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include shadow metadata in the meta field of each record in the response. See Shadowed records. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

Native operation: PUT /zones/{zone_id}/dns_records/{dns_record_id}; dns-records-for-a-zone-update-dns-record. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

delete_dns_record

cloudflare-cli delete-dns-record

Permanently removes a DNS record from the zone. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

dns_record_id
Required
Yes
Type
dns-records_identifier
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.

Native operation: DELETE /zones/{zone_id}/dns_records/{dns_record_id}; dns-records-for-a-zone-delete-dns-record. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

batch_dns_records

cloudflare-cli batch-dns-records

Send a Batch of DNS Record API calls to be executed together.

Notes: - Although Cloudflare will execute the batched operations in a single database transaction, Cloudflare's distributed KV store must treat each record change as a single key-value pair. This means that the propagation of changes is not atomic. See [the documentation](https://developers.cloudflare.com/dns/manage-dns-records/how-to/batch-record-changes/ "Batch DNS records") for more information. - The operations you specify within the /batch request body are always executed in the following order:

- Deletes - Patches - Puts - Posts Every change requires explicit confirmation; never repeat an unknown outcome automatically.

zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
include_shadow_metadata
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include shadow metadata in the meta field of each record in the response. See Shadowed records. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

Native operation: POST /zones/{zone_id}/dns_records/batch; dns-records-for-a-zone-batch-dns-records. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

purge_cache

cloudflare-cli purge-cache

Deletes cached content in every Cloudflare data center and cache tier, including Cache Reserve. The next request for purged content is a cache MISS: Cloudflare fetches the full response from your origin and caches it again. Cloudflare does not serve purged content from cache again, even if your origin is unavailable.

To keep content cached and have Cloudflare revalidate it with your origin instead, use POST /zones/{zone_id}/invalidate_cache.

Choose what to purge

Send one of these fields in the request body:

  • files: specific URLs. If your cache key includes request headers, send each URL with the header values it was cached with.
  • tags: all content whose Cache-Tag response header contains one of the tags.
  • hosts: all content cached for the hostnames.
  • prefixes: all content whose URL starts with one of the prefixes.
  • purge_everything: all cached content in the zone.

Check the result

A 200 response with success: true means Cloudflare accepted the request. It does not confirm that any content was cached or removed. To check, request a purged URL and confirm that the CF-Cache-Status response header is MISS.

Availability and limits

Rate limits and the number of items you can send in one request depend on your plan. See Purge cache: availability and limits. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

zone_id
Required
No; body and guard rules apply
Type
cache-purge_identifier
Details
The zone ID. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
Union
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

Native operation: POST /zones/{zone_id}/purge_cache; zone-purge. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

get_zone_setting

cloudflare-cli get-zone-setting

Fetch a single zone setting by name Read operation.

zone_id
Required
No; body and guard rules apply
Type
zones_identifier
Details
See current schema minLength: 1.
setting_id
Required
Yes
Type
zones_setting_name
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /zones/{zone_id}/settings/{setting_id}; zone-settings-get-single-setting. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

update_zone_setting

cloudflare-cli update-zone-setting

Updates a single zone setting by the identifier Every change requires explicit confirmation; never repeat an unknown outcome automatically.

zone_id
Required
No; body and guard rules apply
Type
zones_identifier
Details
See current schema minLength: 1.
setting_id
Required
Yes
Type
zones_setting_name
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
Union
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

Native operation: PATCH /zones/{zone_id}/settings/{setting_id}; zone-settings-edit-single-setting. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

list_workers

cloudflare-cli list-workers

Fetch a list of uploaded Worker scripts. Read operation.

account_id
Required
No; body and guard rules apply
Type
workers_identifier
Details
See current schema minLength: 1.
tags
Required
No; body and guard rules apply
Type
string
Details
Filter scripts by tags. Format: comma-separated list of tag:allowed pairs where allowed is 'yes' or 'no'.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /accounts/{account_id}/workers/scripts; worker-script-list-workers. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

list_zone_rulesets

cloudflare-cli list-zone-rulesets

Fetches all rulesets at the zone level. Read operation.

zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
cursor
Required
No; body and guard rules apply
Type
rulesets_Cursor
Details
See current schema
per_page
Required
No; body and guard rules apply
Type
rulesets_PerPage
Details
See current schema
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /zones/{zone_id}/rulesets; listZoneRulesets. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

get_zone_ruleset

cloudflare-cli get-zone-ruleset

Fetches the latest version of a zone ruleset. Read operation.

ruleset_id
Required
Yes
Type
rulesets_RulesetId
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /zones/{zone_id}/rulesets/{ruleset_id}; getZoneRuleset. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

get_zone_entrypoint

cloudflare-cli get-zone-entrypoint

Fetches the latest version of the zone entry point ruleset for a given phase. Read operation.

ruleset_phase
Required
Yes
Type
rulesets_RulesetPhase
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /zones/{zone_id}/rulesets/phases/{ruleset_phase}/entrypoint; getZoneEntrypointRuleset. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

create_zone_ruleset

cloudflare-cli create-zone-ruleset

Creates a ruleset at the zone level. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
dry_run
Required
No; body and guard rules apply
Type
boolean
Details
Validates the request without persisting changes when set to true. Responses that normally return 200 return result: null; endpoints that normally return 204 continue to return 204. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
JSON
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

Native operation: POST /zones/{zone_id}/rulesets; createZoneRuleset. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

update_zone_ruleset

cloudflare-cli update-zone-ruleset

Updates a zone ruleset, creating a new version. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

ruleset_id
Required
Yes
Type
rulesets_RulesetId
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
dry_run
Required
No; body and guard rules apply
Type
boolean
Details
Validates the request without persisting changes when set to true. Responses that normally return 200 return result: null; endpoints that normally return 204 continue to return 204. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
JSON
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

Native operation: PUT /zones/{zone_id}/rulesets/{ruleset_id}; updateZoneRuleset. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

delete_zone_ruleset

cloudflare-cli delete-zone-ruleset

Deletes all versions of an existing zone ruleset. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

ruleset_id
Required
Yes
Type
rulesets_RulesetId
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
dry_run
Required
No; body and guard rules apply
Type
boolean
Details
Validates the request without persisting changes when set to true. Responses that normally return 200 return result: null; endpoints that normally return 204 continue to return 204. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.

Native operation: DELETE /zones/{zone_id}/rulesets/{ruleset_id}; deleteZoneRuleset. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

list_page_rules

cloudflare-cli list-page-rules

Fetches Page Rules in a zone. Read operation.

zone_id
Required
No; body and guard rules apply
Type
zones_identifier-2
Details
See current schema minLength: 1.
order
Required
No; body and guard rules apply
Type
string
Details
The field used to sort returned Page Rules. Values: status, priority. default: priority.
direction
Required
No; body and guard rules apply
Type
string
Details
The direction used to sort returned Page Rules. Values: asc, desc. default: desc.
match
Required
No; body and guard rules apply
Type
string
Details
When set to all, all the search requirements must match. When set to any, only one of the search requirements has to match. Values: any, all. default: all.
status
Required
No; body and guard rules apply
Type
string
Details
The status of the Page Rule. Values: active, disabled. default: disabled.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /zones/{zone_id}/pagerules; page-rules-list-page-rules. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

get_page_rule

cloudflare-cli get-page-rule

Fetches the details of a Page Rule. Read operation.

pagerule_id
Required
Yes
Type
zones_identifier-2
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
zones_identifier-2
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

Native operation: GET /zones/{zone_id}/pagerules/{pagerule_id}; page-rules-get-a-page-rule. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.

list_accounts

cloudflare-cli list-accounts

Local profile labels/default/auth method only. No provider IDs, credential values or paths. No network.

None
Required
No
Type
None
Details
No arguments

get_operation_schema

cloudflare-cli get-operation-schema

Complete selected current API input, path and query schema. Local metadata only.

operation
Required
Yes
Type
string
Details
See the full input schema. Values: list_provider_accounts, list_zones, get_zone, list_dns_records, get_dns_record, create_dns_record, update_dns_record, overwrite_dns_record, delete_dns_record, batch_dns_records, purge_cache, get_zone_setting, update_zone_setting, list_workers, list_zone_rulesets, get_zone_ruleset, get_zone_entrypoint, create_zone_ruleset, update_zone_ruleset, delete_zone_ruleset, list_page_rules, get_page_rule.

preview_operation

cloudflare-cli preview-operation

Validate a named operation and return its exact local method/path/query/body/profile. No request, auth validation or provider policy checks.

operation
Required
Yes
Type
string
Details
See the full input schema. Values: list_provider_accounts, list_zones, get_zone, list_dns_records, get_dns_record, create_dns_record, update_dns_record, overwrite_dns_record, delete_dns_record, batch_dns_records, purge_cache, get_zone_setting, update_zone_setting, list_workers, list_zone_rulesets, get_zone_ruleset, get_zone_entrypoint, create_zone_ruleset, update_zone_ruleset, delete_zone_ruleset, list_page_rules, get_page_rule.
arguments
Required
Yes
Type
object
Details
See the full input schema.

query_pages

cloudflare-cli query-pages

Read at most five pages of a supported paginated named operation. Provider page metadata determines continuation; missing metadata stops with an explicit unknown continuation.

operation
Required
Yes
Type
string
Details
See the full input schema. Values: list_provider_accounts, list_zones, list_dns_records.
arguments
Required
Yes
Type
object
Details
See the full input schema.
max_pages
Required
No; body and guard rules apply
Type
integer
Details
See the full input schema. minimum: 1. maximum: 5. default: 1.

preview_dns_batch

cloudflare-cli preview-dns-batch

Local schema-validated DNS batch review capped at 50 actions. Digest binds exact JSON body, zone path and profile label; no account or DNS state read. Not a provider authorization grant.

zone_id
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. minLength: 1. maxLength: 32.
account
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.
payload
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
payload_file
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. minLength: 1.

apply_dns_batch

cloudflare-cli apply-dns-batch

Verify the reviewed digest and submit one exact native DNS batch with mandatory confirmation. Does not assert remote-state consistency or atomic DNS propagation; no retry.

zone_id
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. minLength: 1. maxLength: 32.
account
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.
payload
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
payload_file
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. minLength: 1.
preview_sha256
Required
Yes
Type
string
Details
See the full input schema. pattern: ^[0-9a-f]{64}$.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
See the full input schema.

analytics_query

cloudflare-cli analytics-query

One parsed GraphQL query only, with variables. No mutations, subscriptions or multiple operations. Permissions, dataset retention, sampling and query limits remain provider controlled.

query
Required
Yes
Type
string
Details
See the full input schema. minLength: 1. maxLength: 65536.
variables
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
account
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

Nested native input definitions

Identical object shapes are listed once below. References point to the named definitions; union branches retain their individual requirements. Some provider JSON-schema conditions do not fit a flat table; use schema COMMAND or get_operation_schema for complete validation. Unknown native root body keys are refused locally; provider constraints still apply.

##### list_provider_accounts

name
Required
No; body and guard rules apply
Type
string
Details
Name of the account.
page
Required
No; body and guard rules apply
Type
number
Details
Page number of paginated results. minimum: 1. default: 1.
per_page
Required
No; body and guard rules apply
Type
number
Details
Maximum number of results per page. minimum: 5. maximum: 50. default: 20.
direction
Required
No; body and guard rules apply
Type
string
Details
Direction to order results. Values: asc, desc.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### list_zones

name
Required
No; body and guard rules apply
Type
string
Details
A domain name. Optional filter operators can be provided to extend refine the search: * equal (default) * not_equal * starts_with * ends_with * contains * starts_with_case_sensitive * ends_with_case_sensitive * contains_case_sensitive maxLength: 253.
status
Required
No; body and guard rules apply
Type
string
Details
Specify a zone status to filter by. Values: initializing, pending, active, moved.
type
Required
No; body and guard rules apply
Type
array
Details
Zone types to filter by. Multiple types can be specified as a comma-separated list (e.g., ?type=full,partial,secondary). When this parameter is not provided, zones with type "internal" are excluded from the results. Items: string.
account_id
Required
No; body and guard rules apply
Type
string
Details
Filter by an account ID.
account_name
Required
No; body and guard rules apply
Type
string
Details
An account Name. Optional filter operators can be provided to extend refine the search: * equal (default) * not_equal * starts_with * ends_with * contains * starts_with_case_sensitive * ends_with_case_sensitive * contains_case_sensitive maxLength: 253.
page
Required
No; body and guard rules apply
Type
number
Details
Page number of paginated results. minimum: 1. default: 1.
per_page
Required
No; body and guard rules apply
Type
number
Details
Number of zones per page. minimum: 5. maximum: 50. default: 20.
order
Required
No; body and guard rules apply
Type
string
Details
Field to order zones by. Values: name, status, account.id, account.name, plan.id.
direction
Required
No; body and guard rules apply
Type
string
Details
Direction to order zones. Values: asc, desc.
match
Required
No; body and guard rules apply
Type
string
Details
Whether to match all search requirements or at least one (any). Values: any, all. default: all.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### get_zone

zone_id
Required
No; body and guard rules apply
Type
zones_identifier
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### list_dns_records

zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
name
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record name. This is a convenience alias for name.exact.
name_exact
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record name. Name filters are case-insensitive.
name_contains
Required
No; body and guard rules apply
Type
string
Details
Substring of the DNS record name. Name filters are case-insensitive.
name_startswith
Required
No; body and guard rules apply
Type
string
Details
Prefix of the DNS record name. Name filters are case-insensitive.
name_endswith
Required
No; body and guard rules apply
Type
string
Details
Suffix of the DNS record name. Name filters are case-insensitive.
type
Required
No; body and guard rules apply
Type
dns-records_type
Details
See current schema
content
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record content. This is a convenience alias for content.exact.
content_exact
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record content. Content filters are case-insensitive.
content_contains
Required
No; body and guard rules apply
Type
string
Details
Substring of the DNS record content. Content filters are case-insensitive.
content_startswith
Required
No; body and guard rules apply
Type
string
Details
Prefix of the DNS record content. Content filters are case-insensitive.
content_endswith
Required
No; body and guard rules apply
Type
string
Details
Suffix of the DNS record content. Content filters are case-insensitive.
proxied
Required
No; body and guard rules apply
Type
dns-records_proxied
Details
See current schema
match
Required
No; body and guard rules apply
Type
dns-records_match
Details
See current schema
comment
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record comment. This is a convenience alias for comment.exact.
comment_present
Required
No; body and guard rules apply
Type
string
Details
If this parameter is present, only records with a comment are returned.
comment_absent
Required
No; body and guard rules apply
Type
string
Details
If this parameter is present, only records without a comment are returned.
comment_exact
Required
No; body and guard rules apply
Type
string
Details
Exact value of the DNS record comment. Comment filters are case-insensitive.
comment_contains
Required
No; body and guard rules apply
Type
string
Details
Substring of the DNS record comment. Comment filters are case-insensitive.
comment_startswith
Required
No; body and guard rules apply
Type
string
Details
Prefix of the DNS record comment. Comment filters are case-insensitive.
comment_endswith
Required
No; body and guard rules apply
Type
string
Details
Suffix of the DNS record comment. Comment filters are case-insensitive.
tag
Required
No; body and guard rules apply
Type
string
Details
Condition on the DNS record tag. Parameter values can be of the form : to search for an exact name:value pair, or just ` to search for records with a specific tag name regardless of its value. This is a convenience shorthand for the more powerful tag. parameters. Examples: - tag=important is equivalent to tag.present=important - tag=team:DNS is equivalent to tag.exact=team:DNS`
tag_present
Required
No; body and guard rules apply
Type
string
Details
Name of a tag which must be present on the DNS record. Tag filters are case-insensitive.
tag_absent
Required
No; body and guard rules apply
Type
string
Details
Name of a tag which must not be present on the DNS record. Tag filters are case-insensitive.
tag_exact
Required
No; body and guard rules apply
Type
string
Details
A tag and value, of the form :. The API will only return DNS records that have a tag named ` whose value is `. Tag filters are case-insensitive.
tag_contains
Required
No; body and guard rules apply
Type
string
Details
A tag and value, of the form :. The API will only return DNS records that have a tag named ` whose value contains `. Tag filters are case-insensitive.
tag_startswith
Required
No; body and guard rules apply
Type
string
Details
A tag and value, of the form :. The API will only return DNS records that have a tag named ` whose value starts with `. Tag filters are case-insensitive.
tag_endswith
Required
No; body and guard rules apply
Type
string
Details
A tag and value, of the form :. The API will only return DNS records that have a tag named ` whose value ends with `. Tag filters are case-insensitive.
search
Required
No; body and guard rules apply
Type
dns-records_search
Details
See current schema
tag_match
Required
No; body and guard rules apply
Type
dns-records_tag_match
Details
See current schema
page
Required
No; body and guard rules apply
Type
dns-records_page
Details
See current schema
per_page
Required
No; body and guard rules apply
Type
dns-records_per_page
Details
See current schema
order
Required
No; body and guard rules apply
Type
dns-records_order
Details
See current schema
direction
Required
No; body and guard rules apply
Type
dns-records_direction
Details
See current schema
include_shadow_metadata
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include shadow metadata in the meta field of each record in the response. See Shadowed records. default: False.
shadowed_by_name
Required
No; body and guard rules apply
Type
string
Details
Filters the response to records at or below the specified NS delegation name. NS, DS, and NSEC records at the delegation name are excluded because they are not shadowed by that delegation. Those record types are included only when they exist below the delegation. The value must be a non-apex subdomain of the zone. Requires include_shadow_metadata=true. See Shadowed records.
shadowing_name
Required
No; body and guard rules apply
Type
string
Details
Returns NS records that shadow the given name, searching at the name itself and each of its ancestor names within the zone, excluding the zone apex. The value must be a subdomain of the zone; the zone apex is not accepted. See Shadowed records.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### get_dns_record

dns_record_id
Required
Yes
Type
dns-records_identifier
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
include_shadow_metadata
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include shadow metadata in the meta field of each record in the response. See Shadowed records. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### create_dns_record

zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
include_shadow_metadata
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include shadow metadata in the meta field of each record in the response. See Shadowed records. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

##### update_dns_record

dns_record_id
Required
Yes
Type
dns-records_identifier
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
include_shadow_metadata
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include shadow metadata in the meta field of each record in the response. See Shadowed records. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

##### delete_dns_record

dns_record_id
Required
Yes
Type
dns-records_identifier
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.

##### batch_dns_records

zone_id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See current schema minLength: 1.
include_shadow_metadata
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include shadow metadata in the meta field of each record in the response. See Shadowed records. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

##### batch_dns_records.payload

deletes
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. Items: dns-records_dns-record-batch-delete.
patches
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. Items: dns-records_dns-record-batch-patch.
posts
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. Items: dns-records_dns-record-batch-post.
puts
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. Items: dns-records_dns-record-batch-put.

##### purge_cache

zone_id
Required
No; body and guard rules apply
Type
cache-purge_identifier
Details
The zone ID. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
Union
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

##### get_zone_setting

zone_id
Required
No; body and guard rules apply
Type
zones_identifier
Details
See current schema minLength: 1.
setting_id
Required
Yes
Type
zones_setting_name
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### update_zone_setting

zone_id
Required
No; body and guard rules apply
Type
zones_identifier
Details
See current schema minLength: 1.
setting_id
Required
Yes
Type
zones_setting_name
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
Union
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

##### update_zone_setting.payload.oneOf[0]

enabled
Required
No; body and guard rules apply
Type
zones_ssl_recommender_enabled
Details
See the full input schema.

##### update_zone_setting.payload.oneOf[1]

value
Required
No; body and guard rules apply
Type
zones_setting_value
Details
See the full input schema.

##### list_workers

account_id
Required
No; body and guard rules apply
Type
workers_identifier
Details
See current schema minLength: 1.
tags
Required
No; body and guard rules apply
Type
string
Details
Filter scripts by tags. Format: comma-separated list of tag:allowed pairs where allowed is 'yes' or 'no'.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### list_zone_rulesets

zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
cursor
Required
No; body and guard rules apply
Type
rulesets_Cursor
Details
See current schema
per_page
Required
No; body and guard rules apply
Type
rulesets_PerPage
Details
See current schema
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### get_zone_ruleset

ruleset_id
Required
Yes
Type
rulesets_RulesetId
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### get_zone_entrypoint

ruleset_phase
Required
Yes
Type
rulesets_RulesetPhase
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### create_zone_ruleset

zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
dry_run
Required
No; body and guard rules apply
Type
boolean
Details
Validates the request without persisting changes when set to true. Responses that normally return 200 return result: null; endpoints that normally return 204 continue to return 204. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
JSON
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

##### create_zone_ruleset.payload.allOf[1]

kind
Required
No; body and guard rules apply
Type
rulesets_RulesetKind
Details
See the full input schema.
phase
Required
No; body and guard rules apply
Type
rulesets_RulesetPhase
Details
See the full input schema.
rules
Required
No; body and guard rules apply
Type
rulesets_RequestRules
Details
See the full input schema.

##### update_zone_ruleset

ruleset_id
Required
Yes
Type
rulesets_RulesetId
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
dry_run
Required
No; body and guard rules apply
Type
boolean
Details
Validates the request without persisting changes when set to true. Responses that normally return 200 return result: null; endpoints that normally return 204 continue to return 204. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.
payload
Required
No; body and guard rules apply
Type
JSON
Details
Complete current native JSON request body. Do not mix with payload_file.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength: 1.

##### delete_zone_ruleset

ruleset_id
Required
Yes
Type
rulesets_RulesetId
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
rulesets_ZoneId
Details
See current schema minLength: 1.
dry_run
Required
No; body and guard rules apply
Type
boolean
Details
Validates the request without persisting changes when set to true. Responses that normally return 200 return result: null; endpoints that normally return 204 continue to return 204. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for the exact selected mutation, target and reviewed request.

##### list_page_rules

zone_id
Required
No; body and guard rules apply
Type
zones_identifier-2
Details
See current schema minLength: 1.
order
Required
No; body and guard rules apply
Type
string
Details
The field used to sort returned Page Rules. Values: status, priority. default: priority.
direction
Required
No; body and guard rules apply
Type
string
Details
The direction used to sort returned Page Rules. Values: asc, desc. default: desc.
match
Required
No; body and guard rules apply
Type
string
Details
When set to all, all the search requirements must match. When set to any, only one of the search requirements has to match. Values: any, all. default: all.
status
Required
No; body and guard rules apply
Type
string
Details
The status of the Page Rule. Values: active, disabled. default: disabled.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### get_page_rule

pagerule_id
Required
Yes
Type
zones_identifier-2
Details
See current schema minLength: 1.
zone_id
Required
No; body and guard rules apply
Type
zones_identifier-2
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.

##### get_operation_schema

operation
Required
Yes
Type
string
Details
See the full input schema. Values: list_provider_accounts, list_zones, get_zone, list_dns_records, get_dns_record, create_dns_record, update_dns_record, overwrite_dns_record, delete_dns_record, batch_dns_records, purge_cache, get_zone_setting, update_zone_setting, list_workers, list_zone_rulesets, get_zone_ruleset, get_zone_entrypoint, create_zone_ruleset, update_zone_ruleset, delete_zone_ruleset, list_page_rules, get_page_rule.

##### preview_operation

operation
Required
Yes
Type
string
Details
See the full input schema. Values: list_provider_accounts, list_zones, get_zone, list_dns_records, get_dns_record, create_dns_record, update_dns_record, overwrite_dns_record, delete_dns_record, batch_dns_records, purge_cache, get_zone_setting, update_zone_setting, list_workers, list_zone_rulesets, get_zone_ruleset, get_zone_entrypoint, create_zone_ruleset, update_zone_ruleset, delete_zone_ruleset, list_page_rules, get_page_rule.
arguments
Required
Yes
Type
object
Details
See the full input schema.

##### query_pages

operation
Required
Yes
Type
string
Details
See the full input schema. Values: list_provider_accounts, list_zones, list_dns_records.
arguments
Required
Yes
Type
object
Details
See the full input schema.
max_pages
Required
No; body and guard rules apply
Type
integer
Details
See the full input schema. minimum: 1. maximum: 5. default: 1.

##### preview_dns_batch

zone_id
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. minLength: 1. maxLength: 32.
account
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.
payload
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
payload_file
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. minLength: 1.

##### preview_dns_batch.payload

deletes
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. Items: dns-records_dns-record-batch-delete.
patches
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. Items: dns-records_dns-record-batch-patch.
posts
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. Items: dns-records_dns-record-batch-post.
puts
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. Items: dns-records_dns-record-batch-put.

##### apply_dns_batch

zone_id
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. minLength: 1. maxLength: 32.
account
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.
payload
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
payload_file
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. minLength: 1.
preview_sha256
Required
Yes
Type
string
Details
See the full input schema. pattern: ^[0-9a-f]{64}$.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
See the full input schema.

##### analytics_query

query
Required
Yes
Type
string
Details
See the full input schema. minLength: 1. maxLength: 65536.
variables
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
account
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### dns-records_AAAARecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
A valid IPv6 address. format: ipv6.
private_routing
Required
No; body and guard rules apply
Type
boolean
Details
Enables private network routing to the origin. default: False.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: AAAA.

##### dns-records_ARecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
A valid IPv4 address. format: ipv4.
private_routing
Required
No; body and guard rules apply
Type
boolean
Details
Enables private network routing to the origin. default: False.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: A.

##### dns-records_CAARecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted CAA content. See 'data' to set CAA properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a CAA record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: CAA.

##### dns-records_CAARecord.allOf[1].data

flags
Required
No; body and guard rules apply
Type
number
Details
Flags for the CAA record. minimum: 0. maximum: 255.
tag
Required
No; body and guard rules apply
Type
string
Details
Name of the property controlled by this record (e.g.: issue, issuewild, iodef).
value
Required
No; body and guard rules apply
Type
string
Details
Value of the record. This field's semantics depend on the chosen tag.

##### dns-records_CERTRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted CERT content. See 'data' to set CERT properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a CERT record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: CERT.

##### dns-records_CERTRecord.allOf[1].data

algorithm
Required
No; body and guard rules apply
Type
number
Details
Algorithm. minimum: 0. maximum: 255.
certificate
Required
No; body and guard rules apply
Type
string
Details
Certificate.
key_tag
Required
No; body and guard rules apply
Type
number
Details
Key Tag. minimum: 0. maximum: 65535.
type
Required
No; body and guard rules apply
Type
number
Details
Type. minimum: 0. maximum: 65535.

##### dns-records_CNAMERecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
A valid hostname. Must not match the record's name.
settings
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: CNAME.

##### dns-records_CNAMERecord.allOf[1].settings

flatten_cname
Required
No; body and guard rules apply
Type
boolean
Details
If enabled, causes the CNAME record to be resolved externally and the resulting address records (e.g., A and AAAA) to be returned instead of the CNAME record itself. This setting is unavailable for proxied records, since they are always flattened. default: False.

##### dns-records_DNSKEYRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted DNSKEY content. See 'data' to set DNSKEY properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a DNSKEY record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: DNSKEY.

##### dns-records_DNSKEYRecord.allOf[1].data

algorithm
Required
No; body and guard rules apply
Type
number
Details
Algorithm. minimum: 0. maximum: 255.
flags
Required
No; body and guard rules apply
Type
number
Details
Flags. minimum: 0. maximum: 65535.
protocol
Required
No; body and guard rules apply
Type
number
Details
Protocol. minimum: 0. maximum: 255.
public_key
Required
No; body and guard rules apply
Type
string
Details
Public Key.

##### dns-records_DSRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted DS content. See 'data' to set DS properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a DS record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: DS.

##### dns-records_DSRecord.allOf[1].data

algorithm
Required
No; body and guard rules apply
Type
number
Details
Algorithm. minimum: 0. maximum: 255.
digest
Required
No; body and guard rules apply
Type
string
Details
Digest.
digest_type
Required
No; body and guard rules apply
Type
number
Details
Digest Type. minimum: 0. maximum: 255.
key_tag
Required
No; body and guard rules apply
Type
number
Details
Key Tag. minimum: 0. maximum: 65535.

##### dns-records_HTTPSRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted HTTPS content. See 'data' to set HTTPS properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a HTTPS record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: HTTPS.

##### dns-records_HTTPSRecord.allOf[1].data

priority
Required
No; body and guard rules apply
Type
number
Details
Priority. minimum: 0. maximum: 65535.
target
Required
No; body and guard rules apply
Type
string
Details
Target.
value
Required
No; body and guard rules apply
Type
string
Details
Value.

##### dns-records_LOCRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted LOC content. See 'data' to set LOC properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a LOC record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: LOC.

##### dns-records_LOCRecord.allOf[1].data

altitude
Required
No; body and guard rules apply
Type
number
Details
Altitude of location in meters. minimum: -100000. maximum: 42849672.95.
lat_degrees
Required
No; body and guard rules apply
Type
number
Details
Degrees of latitude. minimum: 0. maximum: 90.
lat_direction
Required
No; body and guard rules apply
Type
string
Details
Latitude direction. Values: N, S.
lat_minutes
Required
No; body and guard rules apply
Type
number
Details
Minutes of latitude. minimum: 0. maximum: 59.
lat_seconds
Required
No; body and guard rules apply
Type
number
Details
Seconds of latitude. minimum: 0. maximum: 59.999.
long_degrees
Required
No; body and guard rules apply
Type
number
Details
Degrees of longitude. minimum: 0. maximum: 180.
long_direction
Required
No; body and guard rules apply
Type
string
Details
Longitude direction. Values: E, W.
long_minutes
Required
No; body and guard rules apply
Type
number
Details
Minutes of longitude. minimum: 0. maximum: 59.
long_seconds
Required
No; body and guard rules apply
Type
number
Details
Seconds of longitude. minimum: 0. maximum: 59.999.
precision_horz
Required
No; body and guard rules apply
Type
number
Details
Horizontal precision of location. minimum: 0. maximum: 90000000.
precision_vert
Required
No; body and guard rules apply
Type
number
Details
Vertical precision of location. minimum: 0. maximum: 90000000.
size
Required
No; body and guard rules apply
Type
number
Details
Size of location in meters. minimum: 0. maximum: 90000000.

##### dns-records_MXRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
A valid mail server hostname. format: hostname.
priority
Required
No; body and guard rules apply
Type
dns-records_priority
Details
See the full input schema.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: MX.

##### dns-records_NAPTRRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted NAPTR content. See 'data' to set NAPTR properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a NAPTR record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: NAPTR.

##### dns-records_NAPTRRecord.allOf[1].data

flags
Required
No; body and guard rules apply
Type
string
Details
Flags.
order
Required
No; body and guard rules apply
Type
number
Details
Order. minimum: 0. maximum: 65535.
preference
Required
No; body and guard rules apply
Type
number
Details
Preference. minimum: 0. maximum: 65535.
regex
Required
No; body and guard rules apply
Type
string
Details
Regex.
replacement
Required
No; body and guard rules apply
Type
string
Details
Replacement.
service
Required
No; body and guard rules apply
Type
string
Details
Service.

##### dns-records_NSRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
A valid name server host name.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: NS.

##### dns-records_OPENPGPKEYRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
A single Base64-encoded OpenPGP Transferable Public Key (RFC 4880 Section 11.1)
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: OPENPGPKEY.

##### dns-records_PTRRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Domain name pointing to the address.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: PTR.

##### dns-records_SMIMEARecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted SMIMEA content. See 'data' to set SMIMEA properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a SMIMEA record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: SMIMEA.

##### dns-records_SMIMEARecord.allOf[1].data

certificate
Required
No; body and guard rules apply
Type
string
Details
Certificate.
matching_type
Required
No; body and guard rules apply
Type
number
Details
Matching Type. minimum: 0. maximum: 255.
selector
Required
No; body and guard rules apply
Type
number
Details
Selector. minimum: 0. maximum: 255.
usage
Required
No; body and guard rules apply
Type
number
Details
Usage. minimum: 0. maximum: 255.

##### dns-records_SRVRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Priority, weight, port, and SRV target. See 'data' for setting the individual component values.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a SRV record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: SRV.

##### dns-records_SRVRecord.allOf[1].data

port
Required
No; body and guard rules apply
Type
number
Details
The port of the service. minimum: 0. maximum: 65535.
priority
Required
No; body and guard rules apply
Type
dns-records_priority
Details
See the full input schema.
target
Required
No; body and guard rules apply
Type
string
Details
A valid hostname. format: hostname.
weight
Required
No; body and guard rules apply
Type
number
Details
The record weight. minimum: 0. maximum: 65535.

##### dns-records_SSHFPRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted SSHFP content. See 'data' to set SSHFP properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a SSHFP record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: SSHFP.

##### dns-records_SSHFPRecord.allOf[1].data

algorithm
Required
No; body and guard rules apply
Type
number
Details
Algorithm. minimum: 0. maximum: 255.
fingerprint
Required
No; body and guard rules apply
Type
string
Details
Fingerprint.
type
Required
No; body and guard rules apply
Type
number
Details
Type. minimum: 0. maximum: 255.

##### dns-records_SVCBRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted SVCB content. See 'data' to set SVCB properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a SVCB record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: SVCB.

##### dns-records_SVCBRecord.allOf[1].data

priority
Required
No; body and guard rules apply
Type
number
Details
Priority. minimum: 0. maximum: 65535.
target
Required
No; body and guard rules apply
Type
string
Details
Target.
value
Required
No; body and guard rules apply
Type
string
Details
Value.

##### dns-records_TLSARecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted TLSA content. See 'data' to set TLSA properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a TLSA record.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: TLSA.

##### dns-records_TLSARecord.allOf[1].data

certificate
Required
No; body and guard rules apply
Type
string
Details
Certificate.
matching_type
Required
No; body and guard rules apply
Type
number
Details
Matching Type. minimum: 0. maximum: 255.
selector
Required
No; body and guard rules apply
Type
number
Details
Selector. minimum: 0. maximum: 255.
usage
Required
No; body and guard rules apply
Type
number
Details
Usage. minimum: 0. maximum: 255.

##### dns-records_TXTRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Text content for the record. The content must consist of quoted "character strings" (RFC 1035), each with a length of up to 255 bytes. Strings exceeding this allowed maximum length are automatically split. Learn more at .
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: TXT.

##### dns-records_URIRecord.allOf[1]

content
Required
No; body and guard rules apply
Type
string
Details
Formatted URI content. See 'data' to set URI properties.
data
Required
No; body and guard rules apply
Type
object
Details
Components of a URI record.
priority
Required
No; body and guard rules apply
Type
dns-records_priority
Details
See the full input schema.
type
Required
No; body and guard rules apply
Type
string
Details
Record type. Values: URI.

##### dns-records_URIRecord.allOf[1].data

target
Required
No; body and guard rules apply
Type
string
Details
The record content.
weight
Required
No; body and guard rules apply
Type
number
Details
The record weight. minimum: 0. maximum: 65535.

##### dns-records_dns-record-shared-fields

comment
Required
No; body and guard rules apply
Type
dns-records_comment
Details
See the full input schema.
name
Required
No; body and guard rules apply
Type
dns-records_name
Details
See the full input schema.
proxied
Required
No; body and guard rules apply
Type
dns-records_proxied
Details
See the full input schema.
settings
Required
No; body and guard rules apply
Type
dns-records_settings
Details
See the full input schema.
tags
Required
No; body and guard rules apply
Type
dns-records_tags
Details
See the full input schema.
ttl
Required
No; body and guard rules apply
Type
dns-records_ttl
Details
See the full input schema.

##### dns-records_settings

ipv4_only
Required
No; body and guard rules apply
Type
boolean
Details
When enabled, only A records will be generated, and AAAA records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6. default: False.
ipv6_only
Required
No; body and guard rules apply
Type
boolean
Details
When enabled, only AAAA records will be generated, and A records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6. default: False.

##### dns-records_dns-record-batch-delete.allOf[0]

id
Required
No; body and guard rules apply
Type
dns-records_identifier
Details
See the full input schema.

##### dns-records_dns-record-batch-patch

id
Required
Yes
Type
dns-records_identifier
Details
See the full input schema.

##### dns-records_dns-record-batch-put

id
Required
Yes
Type
dns-records_identifier
Details
See the full input schema.

##### cache-purge_Everything

purge_everything
Required
No; body and guard rules apply
Type
boolean
Details
Set to true to target all cached content in the zone, or in the environment for the environment endpoints. Must be the only field in the request. See Purge everything.

##### cache-purge_FlexPurgeByHostnames

hosts
Required
No; body and guard rules apply
Type
array
Details
Hostnames, such as www.example.com. Targets all content cached for these hostnames. See Purge cache by hostname. Items: string.

##### cache-purge_FlexPurgeByPrefixes

prefixes
Required
No; body and guard rules apply
Type
array
Details
URL prefixes, each a hostname followed by a path, such as www.example.com/blog/. Targets all content whose URL starts with one of these prefixes. Do not include a scheme, query string, or fragment. See Purge cache by prefix. Items: string.

##### cache-purge_FlexPurgeByTags

tags
Required
No; body and guard rules apply
Type
array
Details
Cache tags. Targets all content whose Cache-Tag response header contains at least one of these tags. See Purge cache by cache-tags. Items: string.

##### cache-purge_SingleFile

files
Required
No; body and guard rules apply
Type
array
Details
Full URLs, such as https://www.example.com/css/styles.css. Targets the content cached for each URL. If your cache key includes request headers, send objects with url and headers instead. See Purge by single-file. Items: string.

##### cache-purge_SingleFileWithUrlAndHeaders

files
Required
No; body and guard rules apply
Type
array
Details
URLs with the request headers your cache key uses. Use this form when your cache key includes request headers, or the visitor's device type, country, or language: send the header values each URL was cached with, such as CF-Device-Type, CF-IPCountry, or Accept-Language. When you send the Origin header, include the scheme and hostname. Include the port unless it is the default for the scheme: 80 for http, 443 for https. See Purge by single-file. Items: object.

##### cache-purge_SingleFileWithUrlAndHeaders.files[]

headers
Required
No; body and guard rules apply
Type
object
Details
Request headers and the values the content was cached with.
url
Required
No; body and guard rules apply
Type
string
Details
Full URL of the content.

##### zones_automatic_platform_optimization

cache_by_device_type
Required
Yes
Type
boolean
Details
Indicates whether or not cache by device type is enabled.
cf
Required
Yes
Type
boolean
Details
Indicates whether or not Cloudflare proxy is enabled. default: False.
enabled
Required
Yes
Type
boolean
Details
Indicates whether or not Automatic Platform Optimization is enabled. default: False.
hostnames
Required
Yes
Type
array
Details
An array of hostnames where Automatic Platform Optimization for WordPress is activated. Items: string.
wordpress
Required
Yes
Type
boolean
Details
Indicates whether or not site is powered by WordPress. default: False.
wp_plugin
Required
Yes
Type
boolean
Details
Indicates whether or not Cloudflare for WordPress plugin is installed. default: False.

##### zones_cache-rules_aegis_value

enabled
Required
No; body and guard rules apply
Type
boolean
Details
Whether the feature is enabled or not.
pool_id
Required
No; body and guard rules apply
Type
string
Details
Egress pool id which refers to a grouping of dedicated egress IPs through which Cloudflare will connect to origin.

##### zones_nel_value

enabled
Required
No; body and guard rules apply
Type
boolean
Details
See the full input schema. default: False.

##### zones_security_header_value

strict_transport_security
Required
No; body and guard rules apply
Type
object
Details
Strict Transport Security.

##### zones_security_header_value.strict_transport_security

enabled
Required
No; body and guard rules apply
Type
boolean
Details
Whether or not strict transport security is enabled.
include_subdomains
Required
No; body and guard rules apply
Type
boolean
Details
Include all subdomains for strict transport security.
max_age
Required
No; body and guard rules apply
Type
number
Details
Max age in seconds of the strict transport security.
nosniff
Required
No; body and guard rules apply
Type
boolean
Details
Whether or not to include 'X-Content-Type-Options: nosniff' header.
preload
Required
No; body and guard rules apply
Type
boolean
Details
Enable automatic preload of the HSTS configuration.

##### rulesets_BlockRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: block.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_BlockRule.allOf[1].action_parameters

response
Required
No; body and guard rules apply
Type
object
Details
The response to show when the block is applied.

##### rulesets_BlockRule.allOf[1].action_parameters.response

content
Required
Yes
Type
string
Details
The content to return. minLength: 1.
content_type
Required
Yes
Type
string
Details
The type of the content to return. minLength: 1.
status_code
Required
Yes
Type
integer
Details
The status code to return. minimum: 400. maximum: 499.

##### rulesets_ChallengeRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: challenge.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_CompressResponseRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: compress_response.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_CompressResponseRule.allOf[1].action_parameters

algorithms
Required
Yes
Type
array
Details
Custom order for compression algorithms. minItems: 1. Items: object.

##### rulesets_CompressResponseRule.allOf[1].action_parameters.algorithms[]

name
Required
No; body and guard rules apply
Type
string
Details
Name of the compression algorithm to enable. Values: none, auto, default, gzip, brotli, zstd.

##### rulesets_DDoSDynamicRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: ddos_dynamic.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_ExecuteCategoryOverrides[]

action
Required
No; body and guard rules apply
Type
JSON
Details
See the full input schema.
category
Required
Yes
Type
JSON
Details
See the full input schema.
enabled
Required
No; body and guard rules apply
Type
JSON
Details
See the full input schema.
sensitivity_level
Required
No; body and guard rules apply
Type
JSON
Details
See the full input schema.

##### rulesets_ExecuteMatchedData

public_key
Required
Yes
Type
string
Details
The public key to encrypt matched data logs with. minLength: 1.

##### rulesets_ExecuteOverrides

action
Required
No; body and guard rules apply
Type
JSON
Details
See the full input schema.
categories
Required
No; body and guard rules apply
Type
rulesets_ExecuteCategoryOverrides
Details
See the full input schema.
enabled
Required
No; body and guard rules apply
Type
JSON
Details
See the full input schema.
rules
Required
No; body and guard rules apply
Type
rulesets_ExecuteRuleOverrides
Details
See the full input schema.
sensitivity_level
Required
No; body and guard rules apply
Type
JSON
Details
See the full input schema.

##### rulesets_ExecuteRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: execute.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_ExecuteRule.allOf[1].action_parameters

id
Required
Yes
Type
JSON
Details
See the full input schema.
matched_data
Required
No; body and guard rules apply
Type
rulesets_ExecuteMatchedData
Details
See the full input schema.
overrides
Required
No; body and guard rules apply
Type
rulesets_ExecuteOverrides
Details
See the full input schema.

##### rulesets_ExecuteRuleOverrides[]

action
Required
No; body and guard rules apply
Type
JSON
Details
See the full input schema.
enabled
Required
No; body and guard rules apply
Type
JSON
Details
See the full input schema.
id
Required
Yes
Type
JSON
Details
See the full input schema.
score_threshold
Required
No; body and guard rules apply
Type
integer
Details
The score threshold to use for the rule.
sensitivity_level
Required
No; body and guard rules apply
Type
JSON
Details
See the full input schema.

##### rulesets_ForceConnectionCloseRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: force_connection_close.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_JsChallengeRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: js_challenge.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_LogCustomFieldCookieFields[]

name
Required
Yes
Type
string
Details
The name of the cookie. minLength: 1.

##### rulesets_LogCustomFieldRawResponseFields[]

name
Required
Yes
Type
string
Details
The name of the response header. minLength: 1.
preserve_duplicates
Required
No; body and guard rules apply
Type
boolean
Details
Whether to log duplicate values of the same header. default: False.

##### rulesets_LogCustomFieldRequestFields[]

name
Required
Yes
Type
string
Details
The name of the header. minLength: 1.

##### rulesets_LogCustomFieldResponseFields[]

name
Required
Yes
Type
string
Details
The name of the response header. minLength: 1.
preserve_duplicates
Required
No; body and guard rules apply
Type
boolean
Details
Whether to log duplicate values of the same header. default: False.

##### rulesets_LogCustomFieldRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: log_custom_field.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_LogCustomFieldRule.allOf[1].action_parameters

cookie_fields
Required
No; body and guard rules apply
Type
rulesets_LogCustomFieldCookieFields
Details
See the full input schema.
raw_response_fields
Required
No; body and guard rules apply
Type
rulesets_LogCustomFieldRawResponseFields
Details
See the full input schema.
request_fields
Required
No; body and guard rules apply
Type
rulesets_LogCustomFieldRequestFields
Details
See the full input schema.
response_fields
Required
No; body and guard rules apply
Type
rulesets_LogCustomFieldResponseFields
Details
See the full input schema.
transformed_request_fields
Required
No; body and guard rules apply
Type
rulesets_LogCustomFieldTransformedRequestFields
Details
See the full input schema.

##### rulesets_LogCustomFieldTransformedRequestFields[]

name
Required
Yes
Type
string
Details
The name of the header. minLength: 1.

##### rulesets_LogRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: log.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_ManagedChallengeRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: managed_challenge.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_RedirectFromList

key
Required
Yes
Type
string
Details
An expression that evaluates to the list lookup key. minLength: 1.
name
Required
Yes
Type
string
Details
The name of the list to match against. pattern: ^[a-zA-Z0-9_]+$.

##### rulesets_RedirectFromValue

preserve_query_string
Required
No; body and guard rules apply
Type
boolean
Details
Whether to keep the query string of the original request. default: False.
status_code
Required
No; body and guard rules apply
Type
integer
Details
The status code to use for the redirect. Values: 301, 302, 303, 307, 308.
target_url
Required
Yes
Type
object
Details
A URL to redirect the request to.

##### rulesets_RedirectFromValue.target_url

expression
Required
No; body and guard rules apply
Type
string
Details
An expression that evaluates to a URL to redirect the request to. minLength: 1.
value
Required
No; body and guard rules apply
Type
string
Details
A URL to redirect the request to. minLength: 1.

##### rulesets_RedirectRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: redirect.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_RedirectRule.allOf[1].action_parameters

from_list
Required
No; body and guard rules apply
Type
rulesets_RedirectFromList
Details
See the full input schema.
from_value
Required
No; body and guard rules apply
Type
rulesets_RedirectFromValue
Details
See the full input schema.

##### rulesets_RewriteRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: rewrite.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_RewriteRule.allOf[1].action_parameters

headers
Required
No; body and guard rules apply
Type
rulesets_RewriteHeaders
Details
See the full input schema.
uri
Required
No; body and guard rules apply
Type
rulesets_RewriteUri
Details
See the full input schema.

##### rulesets_RewriteUri.allOf[0].anyOf[0]

path
Required
Yes
Type
rulesets_RewriteUriPath
Details
See the full input schema.

##### rulesets_RewriteUri.allOf[0].anyOf[1]

query
Required
Yes
Type
rulesets_RewriteUriQuery
Details
See the full input schema.

##### rulesets_RewriteUri.allOf[1]

origin
Required
No; body and guard rules apply
Type
boolean
Details
Whether to propagate the rewritten URI to origin.

##### rulesets_RewriteUriPath

expression
Required
No; body and guard rules apply
Type
string
Details
An expression that evaluates to a value to rewrite the URI path to. minLength: 1.
value
Required
No; body and guard rules apply
Type
string
Details
A value to rewrite the URI path to. minLength: 1.

##### rulesets_RewriteUriQuery

expression
Required
No; body and guard rules apply
Type
string
Details
An expression that evaluates to a value to rewrite the URI query to. minLength: 1.
value
Required
No; body and guard rules apply
Type
string
Details
A value to rewrite the URI query to.

##### rulesets_RouteOrigin

host
Required
No; body and guard rules apply
Type
string
Details
A resolved host to route to. minLength: 1.
port
Required
No; body and guard rules apply
Type
integer
Details
A destination port to route to. minimum: 1. maximum: 65535.

##### rulesets_RouteRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: route.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_RouteRule.allOf[1].action_parameters

host_header
Required
No; body and guard rules apply
Type
rulesets_RouteHostHeader
Details
See the full input schema.
origin
Required
No; body and guard rules apply
Type
rulesets_RouteOrigin
Details
See the full input schema.
sni
Required
No; body and guard rules apply
Type
rulesets_RouteSNI
Details
See the full input schema.

##### rulesets_RouteSNI

value
Required
Yes
Type
string
Details
A value to override the SNI to. minLength: 1.

##### rulesets_Rule

action
Required
No; body and guard rules apply
Type
rulesets_RuleAction
Details
See the full input schema.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
The parameters configuring the rule's action. default: {}.
categories
Required
No; body and guard rules apply
Type
rulesets_RuleCategories
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
An informative description of the rule. default: See current schema.
enabled
Required
No; body and guard rules apply
Type
JSON
Details
See the full input schema.
exposed_credential_check
Required
No; body and guard rules apply
Type
rulesets_RuleExposedCredentialCheck
Details
See the full input schema.
expression
Required
No; body and guard rules apply
Type
string
Details
The expression defining which traffic will match the rule. minLength: 1.
id
Required
No; body and guard rules apply
Type
rulesets_RuleId
Details
See the full input schema.
last_updated
Required
Yes
Type
string
Details
The timestamp of when the rule was last modified. format: date-time.
logging
Required
No; body and guard rules apply
Type
rulesets_RuleLogging
Details
See the full input schema.
ratelimit
Required
No; body and guard rules apply
Type
rulesets_RuleRatelimit
Details
See the full input schema.
ref
Required
No; body and guard rules apply
Type
string
Details
The reference of the rule (the rule's ID by default). minLength: 1.
version
Required
Yes
Type
string
Details
The version of the rule. pattern: ^[0-9]+$.

##### rulesets_RuleExposedCredentialCheck

password_expression
Required
Yes
Type
string
Details
An expression that selects the password used in the credentials check. minLength: 1.
username_expression
Required
Yes
Type
string
Details
An expression that selects the user ID used in the credentials check. minLength: 1.

##### rulesets_RuleLogging

enabled
Required
Yes
Type
boolean
Details
Whether to generate a log when the rule matches.

##### rulesets_RuleRatelimit

characteristics
Required
Yes
Type
array
Details
Characteristics of the request on which the rate limit counter will be incremented. minItems: 1. Items: string.
counting_expression
Required
No; body and guard rules apply
Type
string
Details
An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule's expression. minLength: 1.
mitigation_timeout
Required
No; body and guard rules apply
Type
integer
Details
Period of time in seconds after which the action will be disabled following its first execution.
period
Required
Yes
Type
integer
Details
Period in seconds over which the counter is being incremented. minimum: 0.
requests_per_period
Required
No; body and guard rules apply
Type
integer
Details
The threshold of requests per period after which the action will be executed for the first time. minimum: 1.
requests_to_origin
Required
No; body and guard rules apply
Type
boolean
Details
Whether counting is only performed when an origin is reached. default: False.
score_per_period
Required
No; body and guard rules apply
Type
integer
Details
The score threshold per period for which the action will be executed the first time.
score_response_header_name
Required
No; body and guard rules apply
Type
string
Details
A response header name provided by the origin, which contains the score to increment rate limit counter with. minLength: 1.

##### rulesets_Ruleset

description
Required
No; body and guard rules apply
Type
string
Details
An informative description of the ruleset. default: See current schema.
id
Required
Yes
Type
JSON
Details
See the full input schema.
last_updated
Required
Yes
Type
string
Details
The timestamp of when the ruleset was last modified. format: date-time.
name
Required
No; body and guard rules apply
Type
string
Details
The human-readable name of the ruleset. minLength: 1.
version
Required
Yes
Type
JSON
Details
See the full input schema.

##### rulesets_ScoreRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: score.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_ScoreRule.allOf[1].action_parameters

increment
Required
Yes
Type
rulesets_ScoreIncrement
Details
See the full input schema.

##### rulesets_ServeErrorRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: serve_error.
action_parameters
Required
No; body and guard rules apply
Type
JSON
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_ServeErrorRule.allOf[1].action_parameters.allOf[0]

content_type
Required
Yes
Type
rulesets_ServeErrorContentType
Details
See the full input schema.
status_code
Required
No; body and guard rules apply
Type
rulesets_ServeErrorStatusCode
Details
See the full input schema.

##### rulesets_ServeErrorRule.allOf[1].action_parameters.allOf[1].oneOf[0]

content
Required
Yes
Type
rulesets_ServeErrorContent
Details
See the full input schema.

##### rulesets_ServeErrorRule.allOf[1].action_parameters.allOf[1].oneOf[1]

asset_name
Required
Yes
Type
rulesets_ServeErrorAssetName
Details
See the full input schema.

##### rulesets_SetCacheControlDirective.oneOf[0]

cloudflare_only
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlCloudflareOnly
Details
See the full input schema.
operation
Required
Yes
Type
JSON
Details
See the full input schema.

##### rulesets_SetCacheControlDirective.oneOf[1]

cloudflare_only
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlCloudflareOnly
Details
See the full input schema.
operation
Required
Yes
Type
JSON
Details
See the full input schema.

##### rulesets_SetCacheControlDirectiveWithQualifiers.oneOf[0]

cloudflare_only
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlCloudflareOnly
Details
See the full input schema.
operation
Required
Yes
Type
JSON
Details
See the full input schema.
qualifiers
Required
No; body and guard rules apply
Type
array
Details
Optional list of header names to qualify the directive (e.g., for "private" or "no-cache" directives). Items: string.

##### rulesets_SetCacheControlDirectiveWithValue.oneOf[0]

cloudflare_only
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlCloudflareOnly
Details
See the full input schema.
operation
Required
Yes
Type
JSON
Details
See the full input schema.
value
Required
Yes
Type
integer
Details
The duration value in seconds for the directive. minimum: 0.

##### rulesets_SetCacheControlRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: set_cache_control.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_SetCacheControlRule.allOf[1].action_parameters

immutable
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirective
Details
See the full input schema.
max-age
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirectiveWithValue
Details
See the full input schema.
must-revalidate
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirective
Details
See the full input schema.
must-understand
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirective
Details
See the full input schema.
no-cache
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirectiveWithQualifiers
Details
See the full input schema.
no-store
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirective
Details
See the full input schema.
no-transform
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirective
Details
See the full input schema.
private
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirectiveWithQualifiers
Details
See the full input schema.
proxy-revalidate
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirective
Details
See the full input schema.
public
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirective
Details
See the full input schema.
s-maxage
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirectiveWithValue
Details
See the full input schema.
stale-if-error
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirectiveWithValue
Details
See the full input schema.
stale-while-revalidate
Required
No; body and guard rules apply
Type
rulesets_SetCacheControlDirectiveWithValue
Details
See the full input schema.

##### rulesets_SetCacheSettingsBrowserTTL

default
Required
No; body and guard rules apply
Type
integer
Details
The browser TTL (in seconds) if you choose the "override_origin" mode. minimum: 0.
mode
Required
Yes
Type
string
Details
The browser TTL mode. Values: respect_origin, bypass_by_default, override_origin, bypass.

##### rulesets_SetCacheSettingsCacheKey

cache_by_device_type
Required
No; body and guard rules apply
Type
boolean
Details
Whether to separate cached content based on the visitor's device type.
cache_deception_armor
Required
No; body and guard rules apply
Type
boolean
Details
Whether to protect from web cache deception attacks, while allowing static assets to be cached.
custom_key
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsCustomCacheKey
Details
See the full input schema.
ignore_query_strings_order
Required
No; body and guard rules apply
Type
boolean
Details
Whether to treat requests with the same query parameters the same, regardless of the order those query parameters are in.

##### rulesets_SetCacheSettingsCacheReserve

eligible
Required
Yes
Type
boolean
Details
Whether Cache Reserve is enabled. If this is true and a request meets eligibility criteria, Cloudflare will write the resource to Cache Reserve.
minimum_file_size
Required
No; body and guard rules apply
Type
integer
Details
The minimum file size eligible for storage in Cache Reserve. minimum: 0.

##### rulesets_SetCacheSettingsCustomCacheKey

cookie
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsCustomCacheKeyCookie
Details
See the full input schema.
header
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsCustomCacheKeyHeader
Details
See the full input schema.
host
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsCustomCacheKeyHost
Details
See the full input schema.
query_string
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsCustomCacheKeyQueryString
Details
See the full input schema.
user
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsCustomCacheKeyUser
Details
See the full input schema.

##### rulesets_SetCacheSettingsCustomCacheKeyCookie

check_presence
Required
No; body and guard rules apply
Type
array
Details
A list of cookies to check for the presence of. The presence of these cookies is included in the cache key. minItems: 1. Items: string.
include
Required
No; body and guard rules apply
Type
array
Details
A list of cookies to include in the cache key. minItems: 1. Items: string.

##### rulesets_SetCacheSettingsCustomCacheKeyHeader

check_presence
Required
No; body and guard rules apply
Type
array
Details
A list of headers to check for the presence of. The presence of these headers is included in the cache key. minItems: 1. Items: string.
contains
Required
No; body and guard rules apply
Type
object
Details
A mapping of header names to a list of values. If a header is present in the request and contains any of the values provided, its value is included in the cache key.
exclude_origin
Required
No; body and guard rules apply
Type
boolean
Details
Whether to exclude the origin header in the cache key.
include
Required
No; body and guard rules apply
Type
array
Details
A list of headers to include in the cache key. minItems: 1. Items: string.

##### rulesets_SetCacheSettingsCustomCacheKeyHost

resolved
Required
No; body and guard rules apply
Type
boolean
Details
Whether to use the resolved host in the cache key.

##### rulesets_SetCacheSettingsCustomCacheKeyQueryString

exclude
Required
No; body and guard rules apply
Type
object
Details
Which query string parameters to exclude from the cache key.
include
Required
No; body and guard rules apply
Type
object
Details
Which query string parameters to include in the cache key.

##### rulesets_SetCacheSettingsCustomCacheKeyQueryString.exclude

all
Required
No; body and guard rules apply
Type
boolean
Details
Whether to exclude all query string parameters from the cache key. Values: True.
list
Required
No; body and guard rules apply
Type
array
Details
A list of query string parameters to exclude from the cache key. minItems: 1. Items: string.

##### rulesets_SetCacheSettingsCustomCacheKeyQueryString.include

all
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include all query string parameters in the cache key. Values: True.
list
Required
No; body and guard rules apply
Type
array
Details
A list of query string parameters to include in the cache key. minItems: 1. Items: string.

##### rulesets_SetCacheSettingsCustomCacheKeyUser

device_type
Required
No; body and guard rules apply
Type
boolean
Details
Whether to use the user agent's device type in the cache key.
geo
Required
No; body and guard rules apply
Type
boolean
Details
Whether to use the user agents's country in the cache key.
lang
Required
No; body and guard rules apply
Type
boolean
Details
Whether to use the user agent's language in the cache key.

##### rulesets_SetCacheSettingsEdgeTTL

default
Required
No; body and guard rules apply
Type
integer
Details
The edge TTL (in seconds) if you choose the "override_origin" mode. minimum: 0.
mode
Required
Yes
Type
string
Details
The edge TTL mode. Values: respect_origin, bypass_by_default, override_origin.
status_code_ttl
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsStatusCodeTTL
Details
See the full input schema.

##### rulesets_SetCacheSettingsOriginRangeRequests

mode
Required
Yes
Type
string
Details
Whether to use range requests. default is the behaviour the zone gets without this rule. Values: on, off, default.

##### rulesets_SetCacheSettingsRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: set_cache_settings.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_SetCacheSettingsRule.allOf[1].action_parameters

additional_cacheable_ports
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsAdditionalCacheablePorts
Details
See the full input schema.
browser_ttl
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsBrowserTTL
Details
See the full input schema.
cache
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsCache
Details
See the full input schema.
cache_key
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsCacheKey
Details
See the full input schema.
cache_reserve
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsCacheReserve
Details
See the full input schema.
edge_ttl
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsEdgeTTL
Details
See the full input schema.
origin_cache_control
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsOriginCacheControl
Details
See the full input schema.
origin_error_page_passthru
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsOriginErrorPagePassthru
Details
See the full input schema.
origin_range_requests
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsOriginRangeRequests
Details
See the full input schema.
read_timeout
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsReadTimeout
Details
See the full input schema.
respect_strong_etags
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsRespectStrongEtags
Details
See the full input schema.
serve_stale
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsServeStale
Details
See the full input schema.
shared_dictionary
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsSharedDictionary
Details
See the full input schema.
strip_etags
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsStripETags
Details
See the full input schema.
strip_last_modified
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsStripLastModified
Details
See the full input schema.
strip_set_cookie
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsStripSetCookie
Details
See the full input schema.
vary
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsVary
Details
See the full input schema.

##### rulesets_SetCacheSettingsServeStale

disable_stale_while_updating
Required
No; body and guard rules apply
Type
boolean
Details
Whether Cloudflare should disable serving stale content while getting the latest content from the origin.

##### rulesets_SetCacheSettingsSharedDictionary

match_pattern
Required
Yes
Type
string
Details
URL pattern for the Use-As-Dictionary match field. This pattern specifies which URLs can use this response as a dictionary. minLength: 1. maxLength: 1024.

##### rulesets_SetCacheSettingsStatusCodeTTL[]

status_code
Required
No; body and guard rules apply
Type
integer
Details
A single status code to apply the TTL to. minimum: 100. maximum: 999.
status_code_range
Required
No; body and guard rules apply
Type
object
Details
A range of status codes to apply the TTL to.
value
Required
Yes
Type
integer
Details
The time to cache the response for (in seconds). A value of 0 is equivalent to setting the cache control header with the value "no-cache". A value of -1 is equivalent to setting the cache control header with the value of "no-store".

##### rulesets_SetCacheSettingsStatusCodeTTL[].status_code_range

from
Required
No; body and guard rules apply
Type
integer
Details
The lower bound of the range. minimum: 100. maximum: 999.
to
Required
No; body and guard rules apply
Type
integer
Details
The upper bound of the range. minimum: 100. maximum: 999.

##### rulesets_SetCacheSettingsVary

default
Required
No; body and guard rules apply
Type
rulesets_SetCacheSettingsVaryDefault
Details
See the full input schema.
headers
Required
No; body and guard rules apply
Type
object
Details
A mapping of lowercase request header names to their vary configuration.

##### rulesets_SetCacheSettingsVaryDefault

action
Required
Yes
Type
string
Details
How the header value is treated when building the cache key. Values: bypass, passthrough, normalize.

##### rulesets_SetCacheSettingsVaryHeader

action
Required
Yes
Type
string
Details
How the header value is treated when building the cache key. Values: bypass, passthrough, normalize.
languages
Required
No; body and guard rules apply
Type
array
Details
The set of languages to normalize against. Only valid for the accept-language header. maxItems: 20. Items: string.
media_types
Required
No; body and guard rules apply
Type
array
Details
The set of media types to normalize against. Only valid for the accept header. maxItems: 10. Items: string.

##### rulesets_SetCacheTagsRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: set_cache_tags.
action_parameters
Required
No; body and guard rules apply
Type
Union
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[0]

operation
Required
Yes
Type
JSON
Details
See the full input schema.
values
Required
Yes
Type
rulesets_SetCacheTagsValues
Details
See the full input schema.

##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[1]

expression
Required
Yes
Type
rulesets_SetCacheTagsExpression
Details
See the full input schema.
operation
Required
Yes
Type
JSON
Details
See the full input schema.

##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[2]

operation
Required
Yes
Type
JSON
Details
See the full input schema.
values
Required
Yes
Type
rulesets_SetCacheTagsValues
Details
See the full input schema.

##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[3]

expression
Required
Yes
Type
rulesets_SetCacheTagsExpression
Details
See the full input schema.
operation
Required
Yes
Type
JSON
Details
See the full input schema.

##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[4]

operation
Required
Yes
Type
JSON
Details
See the full input schema.
values
Required
Yes
Type
rulesets_SetCacheTagsValues
Details
See the full input schema.

##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[5]

expression
Required
Yes
Type
rulesets_SetCacheTagsExpression
Details
See the full input schema.
operation
Required
Yes
Type
JSON
Details
See the full input schema.

##### rulesets_SetConfigAutominify

css
Required
No; body and guard rules apply
Type
boolean
Details
Whether to minify CSS files. default: False.
html
Required
No; body and guard rules apply
Type
boolean
Details
Whether to minify HTML files. default: False.
js
Required
No; body and guard rules apply
Type
boolean
Details
Whether to minify JavaScript files. default: False.

##### rulesets_SetConfigRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: set_config.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_SetConfigRule.allOf[1].action_parameters

automatic_https_rewrites
Required
No; body and guard rules apply
Type
boolean
Details
Whether to enable Automatic HTTPS Rewrites.
autominify
Required
No; body and guard rules apply
Type
rulesets_SetConfigAutominify
Details
See the full input schema.
bic
Required
No; body and guard rules apply
Type
boolean
Details
Whether to enable Browser Integrity Check (BIC).
content_converter
Required
No; body and guard rules apply
Type
boolean
Details
Whether to enable content conversion (e.g., HTML to Markdown).
disable_apps
Required
No; body and guard rules apply
Type
boolean
Details
Whether to disable Cloudflare Apps. Values: True.
disable_pay_per_crawl
Required
No; body and guard rules apply
Type
boolean
Details
Whether to disable Pay Per Crawl. Values: True.
disable_rum
Required
No; body and guard rules apply
Type
boolean
Details
Whether to disable Real User Monitoring (RUM). Values: True.
disable_zaraz
Required
No; body and guard rules apply
Type
boolean
Details
Whether to disable Zaraz. Values: True.
email_obfuscation
Required
No; body and guard rules apply
Type
boolean
Details
Whether to enable Email Obfuscation.
fonts
Required
No; body and guard rules apply
Type
boolean
Details
Whether to enable Cloudflare Fonts.
hotlink_protection
Required
No; body and guard rules apply
Type
boolean
Details
Whether to enable Hotlink Protection.
mirage
Required
No; body and guard rules apply
Type
boolean
Details
Whether to enable Mirage.
opportunistic_encryption
Required
No; body and guard rules apply
Type
boolean
Details
Whether to enable Opportunistic Encryption.
polish
Required
No; body and guard rules apply
Type
string
Details
The Polish level to configure. Values: off, lossless, lossy, webp.
redirects_for_ai_training
Required
No; body and guard rules apply
Type
boolean
Details
Whether to redirect verified AI training crawlers to canonical URLs found in the HTML response.
request_body_buffering
Required
No; body and guard rules apply
Type
string
Details
The request body buffering mode. Values: none, standard, full.
response_body_buffering
Required
No; body and guard rules apply
Type
string
Details
The response body buffering mode. Values: none, standard.
rocket_loader
Required
No; body and guard rules apply
Type
boolean
Details
Whether to enable Rocket Loader.
security_level
Required
No; body and guard rules apply
Type
string
Details
The Security Level to configure. Values: off, essentially_off, low, medium, high, under_attack.
server_side_excludes
Required
No; body and guard rules apply
Type
boolean
Details
Whether to enable Server-Side Excludes.
ssl
Required
No; body and guard rules apply
Type
string
Details
The SSL level to configure. Values: off, flexible, full, strict, origin_pull.
sxg
Required
No; body and guard rules apply
Type
boolean
Details
Whether to enable Signed Exchanges (SXG).
webmcp_enabled
Required
No; body and guard rules apply
Type
boolean
Details
Whether to serve the WebMCP bridge script, which exposes the page's tools to browser AI agents.
webmcp_packs
Required
No; body and guard rules apply
Type
array
Details
Bundled WebMCP tool packs to activate for matching requests. An empty array disables all packs. Omitting this parameter leaves the pack selection unchanged. Does not enable the WebMCP bridge itself. Non-empty selections require the WebMCP Configuration Rules entitlement. maxItems: 100. Items: string.

##### rulesets_SkipRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: skip.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_SkipRule.allOf[1].action_parameters

phase
Required
No; body and guard rules apply
Type
rulesets_SkipPhase
Details
See the full input schema.
phases
Required
No; body and guard rules apply
Type
rulesets_SkipPhases
Details
See the full input schema.
products
Required
No; body and guard rules apply
Type
rulesets_SkipProducts
Details
See the full input schema.
rules
Required
No; body and guard rules apply
Type
rulesets_SkipRules
Details
See the full input schema.
ruleset
Required
No; body and guard rules apply
Type
rulesets_SkipRuleset
Details
See the full input schema.
rulesets
Required
No; body and guard rules apply
Type
rulesets_SkipRulesets
Details
See the full input schema.

##### rulesets_TransformResponseHTMLRule.allOf[1]

action
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: transform_response_html.
action_parameters
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
description
Required
No; body and guard rules apply
Type
string
Details
See the full input schema.

##### rulesets_TransformResponseHTMLRule.allOf[1].action_parameters

link_maze
Required
Yes
Type
object
Details
Enables the link maze transformation on the response.

Complete client, OS and desktop setup

Codex

Codex is the current validation priority. Private token paths must exist in the process or remote environment where the server runs.

codex mcp add cloudflare -- npx -y @thenavidm/cloudflare-mcp-cli@latest
codex mcp list

Account credentials must reach the server through private environment settings. codex mcp add --env NAME=value stores values in your local config, so never commit that config or put secrets in a shared command. In TOML, the equivalent server is:

[mcp_servers.cloudflare]
command = "npx"
args = ["-y", "@thenavidm/cloudflare-mcp-cli@latest"]
env_vars = ["CLOUDFLARE_API_TOKEN", "CLOUDFLARE_TOKEN_FILE", "CLOUDFLARE_ACCOUNTS", "CLOUDFLARE_DEFAULT_ACCOUNT", "CLOUDFLARE_ZONE_ID", "CLOUDFLARE_ACCOUNT_ID", "CLOUDFLARE_TOKEN_KIND", "CLOUDFLARE_READ_ONLY", "CLOUDFLARE_ALLOW_DESTRUCTIVE"]

env_vars forwards those names from the environment available to Codex. If that environment does not contain them, configure private env settings locally. Codex can also call the CLI directly with SKILL.md and --agent output.

Claude Code

For a user-scoped connection, after privately configuring credentials:

claude mcp add --scope user cloudflare -- npx -y @thenavidm/cloudflare-mcp-cli@latest
claude mcp list

Use the client's private local environment settings for the account variable if they are not inherited. Claude's -e NAME=value registration option writes values into its config; only use it locally through your secret manager, with no shared command transcript. Never place credentials in a project .mcp.json. Reconnect and ask Claude to verify credentials.

Alternatively install the CLI, make SKILL.md available to Claude, and use shell commands. Registering both surfaces is optional.

Claude Desktop

Install the .mcpb extension

  1. Download cloudflare-2.0.0.mcpb from GitHub Releases.
  2. In a supported Claude Desktop build, open Settings > Extensions > Advanced settings > Install Extension… and select it.
  3. Enter a private API token in the sensitive setting, or an absolute private token-file path. Leave the unused credential method empty. Requests use Authorization: Bearer at the fixed Cloudflare endpoint. Configure optional account/zone defaults and user/account token kind privately; defaults do not narrow provider permissions.
  4. Enable read-only if you want only the 18 read operations. Reconnect and ask for account verification.

The bundle includes production dependencies and no credentials. Use a regular private token-only file if you prefer file-based credentials. The manifest requires Node 22 or newer from a compatible host. Organization policy may restrict custom extensions. Manual bundle updates require installing the new version; no automatic directory updates are promised. GUI installation remains unverified separately from archive/protocol checks.

Manual config

Open Settings > Developer > Edit Config, or use your platform's config file:

OSTypical config path
macOS~/Library/Application Support/Claude/claude_desktop_config.json
Windows%APPDATA%\Claude\claude_desktop_config.json
Linux~/.config/Claude/claude_desktop_config.json; confirm the location through Edit Config in your installed build
{
"mcpServers": {
"cloudflare": {
"command": "npx",
"args": ["-y", "@thenavidm/cloudflare-mcp-cli@latest"],
"env": {
"CLOUDFLARE_API_TOKEN": "YOUR_PRIVATE_API_TOKEN",
"CLOUDFLARE_TOKEN_FILE": "",
"CLOUDFLARE_ZONE_ID": "YOUR_ZONE_ID",
"CLOUDFLARE_ACCOUNT_ID": "YOUR_ACCOUNT_ID",
"CLOUDFLARE_TOKEN_KIND": "user"}
}
}
}

Replace the placeholders only in your private file. Merge the server entry into an existing mcpServers object instead of replacing other integrations. Fully quit and reopen Claude Desktop. Do not enable an extension and a manual entry with the same name; choose one route.

If a Windows launcher cannot execute npx directly, use "command": "cmd" with "args": ["/c", "npx", "-y", "@thenavidm/cloudflare-mcp-cli@latest"]. An absolute node executable and installed dist/index.js path also avoids launcher/PATH problems.

Cursor

Use private user settings at ~/.cursor/mcp.json, or Settings > Tools & MCP. Cursor documents environment interpolation and envFile support.

{
"mcpServers": {
"cloudflare": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@thenavidm/cloudflare-mcp-cli@latest"],
"env": {
"CLOUDFLARE_API_TOKEN": "${env:CLOUDFLARE_API_TOKEN}",
"CLOUDFLARE_TOKEN_FILE": "${env:CLOUDFLARE_TOKEN_FILE}",
"CLOUDFLARE_ZONE_ID": "${env:CLOUDFLARE_ZONE_ID}"}
}
}
}

The environment values must exist for the Cursor process. If you use envFile, keep that file private and outside version control. A project's .cursor/mcp.json must not contain actual credentials. Reconnect the server after saving.

VS Code and Copilot

Use MCP: Open User Configuration. VS Code uses servers and secure inputs, rather than a mcpServers root:

{
"inputs": [
{"type": "promptString", "id": "cloudflare-api-token", "description": "Cloudflare API token (leave empty for a private token file)", "password": true},
{"type": "promptString", "id": "cloudflare-token-file", "description": "Optional private token-file path (leave empty for API token)"},
{"type": "promptString", "id": "cloudflare-zone-id", "description": "Optional Cloudflare zone input default"}],
"servers": {
"cloudflare": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@thenavidm/cloudflare-mcp-cli@latest"],
"env": {
"CLOUDFLARE_API_TOKEN": "${input:cloudflare-api-token}",
"CLOUDFLARE_TOKEN_FILE": "${input:cloudflare-token-file}",
"CLOUDFLARE_ZONE_ID": "${input:cloudflare-zone-id}"}
}
}
}

Start Cloudflare through the MCP controls, approve trust if prompted, and enter credentials in the private input prompts. Workspace .vscode/mcp.json may contain this placeholder-only structure, but never resolved secret values. Remote development runs the server in the selected remote environment, so local file paths refer to that environment.

Windsurf

Open Cascade's MCP settings or edit the private user file ~/.codeium/windsurf/mcp_config.json. Use the Claude Desktop manual mcpServers block above with your locally configured env values. See Windsurf's current MCP documentation. Restart or reconnect Cloudflare in Cascade; project files must not contain secrets.

Zed

Open Settings > AI > MCP Servers > Add Server > Add Local Server, or your user settings file. Zed uses context_servers:

{
"context_servers": {
"cloudflare": {
"command": "npx",
"args": ["-y", "@thenavidm/cloudflare-mcp-cli@latest"],
"env": {
"CLOUDFLARE_API_TOKEN": "YOUR_PRIVATE_API_TOKEN",
"CLOUDFLARE_TOKEN_FILE": "",
"CLOUDFLARE_ZONE_ID": "YOUR_ZONE_ID",
"CLOUDFLARE_ACCOUNT_ID": "YOUR_ACCOUNT_ID",
"CLOUDFLARE_TOKEN_KIND": "user"}
}
}
}

Enter actual values only in private user settings. Check the active-server indicator before prompting. Do not wrap command and args inside a nested command object from older Zed examples.

Gemini CLI

Merge the Claude Desktop manual mcpServers block into your private ~/.gemini/settings.json. Configure the private credential values locally, then restart Gemini CLI and inspect /mcp. See Gemini CLI's MCP configuration. Its project settings must not contain real credentials. You can instead use the CLI from an agent shell.

Other local stdio clients use the same command and arguments, adapted to their config format. A client that only accepts a remote MCP URL cannot connect directly: this package does not ship a public HTTP listener. ChatGPT's remote connector setup is not a substitute for local stdio installation.

Docker

Build locally from the reviewed source; no prebuilt registry image is claimed:

git clone https://github.com/thenavidm/cloudflare-mcp-cli.git
cd cloudflare-mcp-cli
docker build -t cloudflare-mcp-cli .
docker run --rm -i -e CLOUDFLARE_API_TOKEN cloudflare-mcp-cli

Cline and other local MCP clients

Use the client's Add MCP server flow with command npx, arguments -y and @thenavidm/cloudflare-mcp-cli@latest, stdio transport, and private local CLOUDFLARE_API_TOKEN or CLOUDFLARE_TOKEN_FILE settings. UI names depend on the installed client. Reconnect and discover tools before an account call. Browser-only clients need a remote HTTPS connector; use Cloudflare's official server rather than this local stdio command.

Output, flags and exit codes

The house CLI derives tool flags from the same input schemas used by MCP. Tool names use underscores in MCP and hyphens in the shell. Native path/query arguments are top-level flags; current native request bodies use --payload JSON or --payload-file PATH, never both. --select filters returned data locally; it does not change Cloudflare's upstream fields or quota.

Flag / commandContract
tools / no commandDiscover every command; confirmed mutations are marked
COMMAND --helpActual tool schema arguments
schema COMMANDComplete JSON input schema, including native payload unions/references
--agent--json --compact --no-input --no-color --yes; never implies --confirm
--json / --compactMachine JSON, optionally compact
--select a,b.cLocal dotted result selection
--payload / --payload-fileNative JSON body / private regular JSON file
--account NAMEExact private profile label
--confirmExplicit intent for the selected mutation only
--no-input / --no-color / --yesNoninteractive formatting/prompt policy; no mutation permission
ExitMeaning
0Success
2Invalid input or refused mutation
3Not found
4Authentication/permission error
5Provider or transport failure
7Rate limited
10No credentials configured

Provider REST results retain success/result/result_info envelopes; query-only analytics retains data. HTTP 200 with provider errors fails. JSON output is not proof that DNS has propagated or every downstream service accepted a setting.

Official and pinned community comparisons

Current surface
https://mcp.cloudflare.com/mcp; current pinned README lists docs/search/execute
Verified strengths and limits
OAuth or user/account token access, sandboxed code execution across the wider API, provider-maintained documentation search and configurable truncation. Individual endpoint tools are optional. Client approval and token permission boundaries remain relevant.
Current surface
cf 1.0.0-beta.12; Cloudflare documents more than 2900 commands
Verified strengths and limits
General account API coverage, command search, schemas, JSON, dry-run, named profiles, OAuth refresh, resource name resolution and local developer resources. Delete confirmation already exists.
Current surface
4.147.0 at this review
Verified strengths and limits
Workers development/deployment and related project workflows. This focused package does not replace the developer toolchain.
Current surface
Provider-hosted service-specific MCP endpoints
Verified strengths and limits
Specialized analytics, builds, browser rendering and other products; current /mcp endpoints use Streamable HTTP. These are distinct from a local stdio DNS task wrapper.
Current surface
Community MIT source 1.0.0; 11 documented tools; stdio/HTTP
Verified strengths and limits
DNS convenience, BIND export, edit snapshots, guarded raw passthrough and optional Worker deployment/secrets. Delete/passthrough confirmation is already present. No dedicated task CLI is declared in the pinned package.
This owned package
Current surface
29 shared local MCP tools / CLI commands; versioned desktop bundle
Verified strengths and limits
18 reads and 11 mandatory-confirmation mutations, isolated private profiles, complete selected native schemas, local previews, bounded page reads, reviewed DNS digest and no automatic replay. Narrower coverage than the official general API tools.

Checked October 3, 2026. Official MCP source: cloudflare/mcp commit 69ba3143bb8ffa2b3c1f12bfb7536c9ca4c57a2d. Selected API schema: cloudflare/api-schemas commit 37e7a4ae9c5123a2c58929a100c42cb4584edc57, API info 4.0.0. Community source is pinned above; its extra workflows are useful and are not claimed here.

The actual public cf@1.0.0-beta.12 package installed cleanly. Its complete binary passed version, command search, DNS-create schema and DNS-create dry-run checks with inherited provider credentials removed, telemetry disabled and fetch blocked. Its published DNS-create handler plus run wrapper were separately exercised in an isolated function fixture: a valid create without a confirmation flag reached an injected network-free SDK request once; dry-run reached it zero times. That fixture is not an authenticated Cloudflare operation or a whole-client approval test. Our equivalent shared handler refuses before fetch without explicit confirmation, including direct MCP calls.

Official cf already confirms deletes and has useful dry-run/profile features. Code Mode isolates credential injection from generated code; do not describe it as handing account tokens to the model. Reviewed official retry code can replay requests on transient/429 failures; this wrapper does not replay any request automatically. Confirmation is the caller asserting approved intent, not a cryptographic proof of a human approval or provider authorization.

The owned use case is a focused, repeatable DNS/zone task with consistent approval across CLI and MCP and an exact-request batch review. Choose official cf/Code Mode for broader API work and Wrangler for deployments. SEO, more tool names and metadata size do not establish better tasks or lower token cost. Live provider outcomes, GUI installation and actual matched Codex usage remain separately unverified.

Legacy command migration

list_zones/get_zone
Current route
Same names
Migration detail
Current native arguments/envelopes; use exact filters
list_dns_records/create/update/delete
Current route
Same names
Migration detail
Complete native payload schemas; every mutation confirmed
purge_cache
Current route
Same name
Migration detail
Native body and explicit approval
get_ssl_settings/update_ssl_settings
Current route
get_zone_setting/update_zone_setting
Migration detail
setting_id=ssl and current value schema
get_zone_settings/update_zone_setting
Current route
Per-setting read/update
Migration detail
Deprecated bulk settings route excluded
get_zone_analytics
Current route
analytics_query
Migration detail
Read-only current GraphQL dataset query, not deprecated REST dashboard
list_firewall_rules
Current route
list_zone_rulesets / get_zone_ruleset
Migration detail
Current Rulesets product; no deprecated firewall writer
create_redirect_rule/list_redirects
Current route
Explicit selected Ruleset workflow
Migration detail
Legacy helper created Page Rules; modern redirect phase/action must be reviewed
list_page_rules
Current route
Read-only Page Rules inventory
Migration detail
No legacy Page Rule writer
list_workers
Current route
Same name
Migration detail
Worker script metadata only, no deployment

Private legacy source is retained separately and never pushed into clean public history. The old source has 17 MCP tools and no declared task CLI. This release changes input/response/config contracts, so migration is deliberate rather than an unverified drop-in compatibility promise.

Versions and migration

ComponentReviewed version / source
Owned package / desktop2.0.0
Legacy source package1.0.0; private source b6fef82d992cefbfb4ea9a9ea49e17275609c34e
Cloudflare REST API schemaAPI info 4.0.0; commit 37e7a4ae9c5123a2c58929a100c42cb4584edc57
Official cf / Wrangler1.0.0-beta.12 / 4.147.0 at review
@modelcontextprotocol/sdk1.32.0
ajv8.20.0
ajv-formats3.0.1
graphql16.14.2
typescript7.0.2
vitest5.0.3
vite8.3.2
@anthropic-ai/mcpb2.1.2

See CHANGELOG.md for dated changes and GitHub Releases for annotated source tags and versioned desktop assets. Match npm, server, manifest and root lock versions. Future schema refreshes must record upstream commit/checksums, exclusions, changed inputs and comparison evidence; do not assume a provider beta stays the same. No prior public legacy npm/tag release is implied.

Updates and removal

npm install -g @thenavidm/cloudflare-mcp-cli@latest
cloudflare-cli --version
npm uninstall -g @thenavidm/cloudflare-mcp-cli
codex mcp remove cloudflare

npx @latest resolves again when the server starts; restart/reconnect to use the release. Global npm installs need an explicit update. Desktop extensions need the new versioned archive installed separately. Check CHANGELOG.md and the manifest; remove duplicate MCP entries rather than running two account servers accidentally.

Remove client configuration/skill references and deliberately manage private files. Uninstall does not revoke tokens or undo DNS, Rulesets/cache changes. Existing private legacy refs stay private; migrate configuration/commands deliberately using the map below. Pin 2.0.0 if reproducible installation matters more than automatically receiving the latest release.

Validation and remaining evidence

Forty-four behavior/shared-CLI tests, typecheck/build and actual credential-free stdio discovery pass: 29 tools, 18 reads and eleven confirmed mutations. The reviewed source schema and distributed metadata have recorded checksums. Schema maintenance checks local JSON without network or source-code execution. The actual public official cf binary passed discovery/schema/dry-run; its mutation comparison is a network-free published-handler fixture, not an authenticated provider operation.

Public source CI, clean npm install and downloaded desktop discovery are release gates, recorded separately in the maintained release proof. Runtime audit has zero findings. Private legacy history is retained separately; public source/npm/desktop artifacts are scanned for secrets. Provider account outcomes, desktop GUI installation, fresh matched Codex task/token usage and the private site scene/helper deployment batch remain pending. Neither surface needs Claude Code; its benchmarks are deferred.

More tools for your site workflow

Connect the tools needed for the exact work you want to do.

Cloudflare MCP Server & CLI FAQs

Official cf/Code Mode, scoped tokens, profiles, DNS review, Rulesets, analytics, desktop setup and safeguards.

A focused shared Cloudflare CLI/local MCP and desktop archive, with 29 tools: 18 reads and 11 explicitly confirmed mutations.

Its selected DNS/zone management surface is narrower than the official general API tools.

Yes.

Code Mode MCP, specialized provider MCPs, the general cf CLI and Wrangler already exist.

The comparison documents their strengths and our specific recurring workflow rather than claiming they are missing.

For consistent mandatory confirmation in both local surfaces, isolated private profiles and an exact-request DNS batch review.

These are tested local workflow differences; no universal superiority or measured token winner is claimed.

Yes: register the npx @latest stdio command, forward private environment settings, or use cloudflare-cli with SKILL.md.

Discovery works without provider authentication; account operations need the intended token grant.

A versioned .mcpb vendors production dependencies and exposes private token/file/default/policy settings.

Manual stdio is also documented.

A protocol handshake is not a verified desktop GUI installation.

The house setup covers Node 22+ on macOS, Windows and Linux and local stdio clients including Codex, Claude, Cursor, VS Code, Windsurf, Zed, Gemini CLI and Cline.

Client runtime, policy and launchers still matter; remote-only clients use official hosted MCP.

No.

This Bearer-only wrapper expects a least-privilege API token.

Restrict its Cloudflare permissions/resources; local profile defaults do not narrow upstream grants.

Yes when the intended endpoints support that token type.

Set token_kind=account and an account ID for doctor verification.

Token kind changes only the diagnostic route; provider compatibility and permissions remain authoritative.

No. login prints private token instructions.

The package neither opens consent nor reads/renews official cf OAuth sessions or global CLI configuration.

Set CLOUDFLARE_READ_ONLY=1 and reconnect.

Eleven mutations disappear and direct calls still refuse.

CLOUDFLARE_ALLOW_DESTRUCTIVE=0 additionally refuses confirmed mutations.

No.

Every mutation needs --confirm or confirm:true for the actual requested operation.

The client/human still determine that it was approved; this flag is not a signed human consent.

The exact method, zone path, profile label and canonical native JSON body, preserving array order.

Any change requires a new local preview.

It does not bind remote state or a token grant and does not prevent concurrent edits.

The review/apply helper does.

Direct native batch_dns_records also exists, requires explicit confirmation and follows the native schema/provider limits, but does not require a digest.

No.

Cloudflare executes the request in a database transaction but distributed propagation is not atomic.

Inspect affected records after an unknown outcome and do not automatically repeat submissions.

No.

Ordinary commands fetch one response. query_pages supports three named reads with a one-to-five-page budget and explicit continuation/unknown reporting.

No request retries automatically.

Wait for current upstream reset policy, inspect possible mutation state and deliberately repeat only if appropriate.

No. list_workers is metadata only.

Use official cf, Code Mode or Wrangler for broader/deployment tasks.

There is no unrestricted raw request tool here.

One parsed GraphQL query at a time, with variables and provider-controlled dataset permissions, retention, sampling and limits.

It refuses mutations and partial-error responses; it is not an automatic analytics export.

That requires identical successful tasks and actual client/model usage.

No fresh matched Codex token result is published; character estimates, schema counts and borrowed metrics are not evidence.

Restart npx @latest, explicitly update global npm installs and reinstall new desktop archives separately.

Remove client entries and revoke the intended token through Cloudflare.

Uninstall does not undo provider changes.

Navid Moazzez

AI business strategist & AI OS builder

Navid Moazzez helps creators and founders master AI and build their own AI Operating System (AI OS) to automate their business and life.

Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.

More MCP servers & CLIs

Related free tools

Free AI newsletter

The most actionable AI newsletter for founders

Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.

No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.

P.S. Sign up now to get free access to my ultimate AI tools guide for creators.

Loved by 10,000+ readers