An open source focused Cloudflare MCP and shared CLI with 29 tools, private profiles and explicit mutation approval.
Key takeaways
This free Cloudflare MCP server and CLI gives your AI real access to current DNS, cache, zone settings, Rulesets, Worker metadata and read-only analytics. Inspect the selected zone and complete native input, preview locally, then submit only the exact change you approve.
It's one install with 2 ways in. Claude, Codex, Cursor or any other MCP app calls its 29 tools for you, and the same tools work as a CLI that agents like Claude Code, Codex and OpenCode run, or that you type yourself.
Here's what the Cloudflare MCP server and CLI is, how to set it up in each app, and every tool it has.
What is the Cloudflare MCP server & CLI?
The Cloudflare MCP server & CLI is a free, open source program that lets AI agents read zone/DNS information and perform specifically approved management requests for you, in 2 ways. The MCP server is what an AI app like Claude, Codex or Cursor connects to, through MCP (Model Context Protocol), the open standard AI apps use to call outside tools.
You ask in plain language. Your AI picks the right tool, and the server makes the call directly to the fixed Cloudflare API origin.
The CLI is the same program as commands. cloudflare-cli list-zones runs the same code your AI runs when you ask to inspect the zones accessible to your private token, whether an agent like Claude Code runs it or you do.
What can you ask it?
Once it's set up, you ask the way you'd ask an assistant. These are real prompts it handles:
Try askingRead DNS for this exact zone without changing records.
Show the complete current schema for a DNS record.
Preview this small DNS batch locally.
Apply only the same reviewed zone, profile and JSON body.
Read the selected zone setting before approving a change.
Inspect current Rulesets and their entrypoint.
Query the eligible analytics dataset for this time window.
Cloudflare already offers Code Mode and service MCPs, the general cf CLI and Wrangler. This owned package adds consistent local mandatory confirmation, isolated private profiles, no automatic request replay and an exact-request DNS batch review. Official coverage is much broader; current pinned comparisons acknowledge profiles, dry-run, delete confirmation and sandboxed credential handling.
How to install the Cloudflare MCP server
Use the existing install box for local MCP, the shared CLI or the versioned desktop bundle. Codex is the primary documented agent; complete client and OS setup follows below.
Set up Cloudflare access
Private API tokens and resource access
- Choose the intended Cloudflare user/account and zone. Create a least-privilege API token through My Profile > API Tokens, or Manage account > Account API tokens for an account-owned token.
- Choose only the permissions needed below and restrict account/zone resources. Check optional expiry and IP filters. Save the secret privately outside every repository; never use the Global API Key with this Bearer-only package.
- Configure CLOUDFLARE_TOKEN_FILE as an absolute token-only file, or privately set CLOUDFLARE_API_TOKEN. Optional CLOUDFLARE_ACCOUNT_ID and CLOUDFLARE_ZONE_ID supply input defaults. A default does not restrict token permissions.
- Run cloudflare-cli doctor for local configuration checks. Deliberately run doctor --network to verify token status: user tokens use GET /user/tokens/verify; account-owned tokens need CLOUDFLARE_TOKEN_KIND=account and a private account ID, using GET /accounts/{account_id}/tokens/verify. Only an active result is accepted; token IDs/status bodies are not printed.
- Read the exact zone and DNS records, inspect the complete current input schema, preview the intended change locally and approve only the chosen request. A local preview does not verify provider permissions, conflicts or current remote state.
Requests use Authorization: Bearer on the fixed https://api.cloudflare.com/client/v4 origin. Token-kind selection changes the diagnostic route, not ordinary authorization or resource access. The wrapper does not implement OAuth login, refresh, saved official cf sessions, automatic .env loading or global CLI config ingestion. login prints instructions; it neither opens consent nor saves credentials.
User tokens inherit permitted user access. Account-owned tokens act as service principals; creation requires the provider's token-provisioning capability or Super Administrator role and grants cannot exceed the creator's permissions. Some products still have compatibility restrictions; verify the exact operation in the account-token compatibility documentation.
- Permission to review with the provider
- Zone: Read
- Resource scope
- Intended zone(s)
- Permission to review with the provider
- DNS: Read
- Resource scope
- Intended zone(s)
- Permission to review with the provider
- DNS: Edit
- Resource scope
- Intended zone(s)
- Permission to review with the provider
- Cache Purge permission
- Resource scope
- Intended zone(s)
- Permission to review with the provider
- Zone Settings: Read / Edit
- Resource scope
- Intended zone(s) and supported setting
- Permission to review with the provider
- The permission for its Ruleset phase, such as zone WAF or Transform Rules read/edit
- Resource scope
- Intended zone(s); phase/plan restrictions apply
- Permission to review with the provider
- Workers Scripts: Read
- Resource scope
- Intended account(s)
- Permission to review with the provider
- Analytics: Read and current dataset access
- Resource scope
- Intended account/zone(s)
- Permission to review with the provider
- Page Rules: Read
- Resource scope
- Intended zone(s)
- Permission to review with the provider
- Account Settings: Read or provider-documented account listing grant
- Resource scope
- Accessible intended accounts
Review API token permissions and the selected endpoint's accepted grant list; this table is task guidance, not a complete static authorization manifest. Do not grant token-management, account administration or every zone solely for installation.
Use a private 0700 directory and regular 0600 token-only file on macOS/Linux. Windows users must restrict the file ACL to their own user; POSIX checks do not establish Windows ACL protection. Token files cannot be symlinks or exceed 64 KiB. File credentials override environment credentials and are cached until restart. GUI applications may have a different environment from your terminal.
Plans and limits
This AGPL wrapper is free; Cloudflare services and plan restrictions remain separate. DNS, proxy, cache purge, setting values, Ruleset phases and analytics availability are controlled by Cloudflare. Read metadata for the selected setting or dataset rather than assuming every write is allowed on every plan.
Current general API limits list 1200 requests per five minutes for a user/account token and 200 per second per IP, with cumulative user limits and endpoint-specific exceptions. Other sessions and processes consume the same upstream quota. Local pacing defaults to 200 ms per profile/process; it does not reserve quota. No reads or mutations retry automatically after 429, timeout, network failure or HTTP 200 provider errors. Wait according to current provider response/reset policy and inspect state before a deliberate repeat.
GraphQL analytics limits separately describe a default 300-query/five-minute user quota, up to ten zones or one account per scoped query, and dataset-specific retention/record limits. The general limits table uses a different GraphQL maximum figure; use the current analytics rules and returned policy for the actual query. Account-based limiting can be enabled through provider controls; the wrapper does not opt you into it. Inspect the provider's settings node for your dataset and resource. Adaptive analytics may be sampled; an aggregate is not necessarily an exact event ledger.
Reviewed DNS batches have a local cap of 1–50 total actions, deliberately below many provider plan limits. The underlying native batch command uses the reviewed source schema and provider limits. Request JSON is capped at 1 MiB; responses at 5 MiB; GraphQL query text at 64 KiB and 10000 parsed tokens; default timeout is 30 seconds. These caps do not raise Cloudflare quotas or plan allowances.
Rotation and revocation
Revoke or rotate the selected user/account token in its Cloudflare settings, update private configuration and restart every client using it. npm uninstall does not revoke the token, restore DNS, remove Rulesets or undo a cache purge. Keep account exports, DNS TXT values, signed URLs and diagnostic responses out of public issues.
Check that it works
Start with local configuration, then deliberately verify the configured user/account token route and active status without returning token details.
cloudflare-cli --version
cloudflare-cli doctor
cloudflare-cli doctor --network
cloudflare-cli list-accounts --agent
cloudflare-cli list-zones --per-page 10 --agentcloudflare-cli doctor
cloudflare-cli doctor --network
cloudflare-cli list-accounts --agent
cloudflare-cli list-zones --per-page 10 --agent
cloudflare-cli get-zone --zone-id YOUR_ZONE_ID --agentLocal doctor reports configuration, not credentials validated. --network checks an active token through its configured token-kind route; it does not prove access to every endpoint. First provider read should be the exact zone needed for the task. Do not create DNS records or purge cache merely to verify installation.
Full discovery has 29 tools; CLOUDFLARE_READ_ONLY=1 hides eleven mutations and direct calls still refuse. Local helpers expose no tokens or provider IDs. A missing credential exits 10; a valid install is not proof of provider account access.
Use the Cloudflare CLI
The CLI is the same 29 tools as commands. AI agents that run commands, like Claude Code, Codex and OpenCode, use it on their own, and you can type the same commands in a terminal or a script.
Every tool name becomes a command with dashes, so get_dns_record runs as cloudflare-cli get-dns-record.
cloudflare-cli tools
cloudflare-cli create-dns-record --help
cloudflare-cli schema create-dns-record
cloudflare-cli list-zones --per-page 10 --agent
cloudflare-cli get-zone --zone-id YOUR_ZONE_ID --agentThe bare cloudflare-cli lists every command, and cloudflare-cli <command> --help shows what a command takes. All eleven mutations require --confirm. --agent/--yes do not approve changes. Use a complete native payload or payload_file; local previews do not validate provider permissions or state.
These flags work on every command:
| Flag | What it does |
|---|---|
| --json | Structured JSON |
| --compact | One-line JSON |
| --agent | Compact JSON without prompts/color; no mutation approval |
| --select a,b.c | Trim local result after receipt |
| --confirm | Approve the exact requested mutation |
| --account NAME | Select one private profile |
| --payload / --payload-file | One complete native body, never both |
A script can branch on the exit code:
| Exit code | What it means |
|---|---|
| 0 | Success |
| 2 | Invalid input or refused mutation |
| 3 | Not found |
| 4 | Authentication/permission failure |
| 5 | Provider/transport failure |
| 7 | Rate limit |
| 10 | No private credential configured |
MCP server or CLI: which one?
Both surfaces call the same tools. Codex can connect to the local MCP server or run the CLI directly. Neither requires Claude Code.
MCP provides structured tool discovery; the CLI supports scripts, compact JSON, field selection and command/schema discovery. Official hosted MCP connection and local CLI authentication have different setup requirements.
Codex-specific token measurements are pending. Record the actual client/model versions, discovery configuration, input/output usage, caching, latency and equivalent successful outcomes. Standing definitions and full task cost are separate measurements; CLI commands, selected help, results and reasoning still consume tokens.
No efficiency percentage or Claude-derived figure is presented as a Codex result. Other-client benchmarks can be added separately.
DNS, Rulesets, cache and analytics workflows
A deliberate DNS change
Read list_zones, get_zone and list_dns_records to establish the exact zone and record. Inspect get_operation_schema for create_dns_record or update_dns_record. A PATCH edits provided fields; a PUT replacement can alter omitted-field behavior. Choose ttl/proxied/type/content deliberately rather than assuming every record should be proxied. DNS conflicts, plan constraints and semantic validity are finally decided by Cloudflare.
cloudflare-cli preview-operation --operation create_dns_record --arguments '{"zone_id":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa","payload":{"name":"review.example.com","type":"A","content":"192.0.2.1","ttl":1,"proxied":false}}' --agent
cloudflare-cli create-dns-record --zone-id YOUR_ZONE_ID --payload-file /absolute/private/approved-dns.json --account work --confirm --agentThe first command is a local illustration using documentation-only IDs/IPs. It makes no provider request. The second is a real mutation only when private credentials, a real resource and the explicitly approved body are supplied. After any approved change, read the returned record and check the intended resolver/service.
Review a small DNS batch
Save only the chosen native deletes/patches/puts/posts body in a private JSON file. preview_dns_batch validates the same native schema and 1–50 total-action cap, then returns a SHA-256 digest of method, exact zone path, profile label and canonically sorted JSON object keys. Array order is preserved. Read and approve the full body, target and profile before apply_dns_batch.
cloudflare-cli preview-dns-batch --zone-id YOUR_ZONE_ID --payload-file /absolute/private/approved-dns-batch.json --account work --agent
cloudflare-cli apply-dns-batch --zone-id YOUR_ZONE_ID --payload-file /absolute/private/approved-dns-batch.json --account work --preview-sha256 REVIEWED_64_CHARACTER_HASH --confirm --agentAny change to that reviewed request requires a new preview. This does not detect concurrent remote edits, credential rotation under the same label or changes in token grants. The digest is not an authorization secret, human approval signature or remote-state transaction lock. The direct native batch_dns_records command also exists, requires --confirm and does not require a digest; choose the review/apply workflow when you need exact local review.
Cloudflare batch semantics execute deletes, patches, puts, then posts in a database transaction; distributed DNS propagation remains non-atomic. If provider validation fails, no batch changes apply. A network failure after submission can leave the outcome unknown; read the affected records before repeating. The wrapper never promises all resolvers change at once or supplies a rollback.
Settings and Rulesets
get_zone_setting with setting_id=ssl replaces the older SSL helper. Inspect the setting's editable/value metadata before update_zone_setting. Ruleset actions and phases have distinct plan/grant requirements; read list_zone_rulesets, get_zone_ruleset and get_zone_entrypoint before creation/update/deletion. Source schemas are broad and cannot establish that a chosen expression or action is appropriate. This release has no deprecated firewall-rule writer and no misleading Page Rule redirect shortcut.
Page Rules are readable for migration inventory; no Page Rules writer is exposed. A redirect should use a consciously selected modern Ruleset phase/action and full approved body. Cloudflare's modern Rules product is not a drop-in rename of every old rule.
Cache, Workers and analytics
purge_cache changes edge cache only for the specified native request; it requires confirmation even for a single URL. It does not delete source files. list_workers reads script metadata, not script content, secrets or deployment state. Use Wrangler/cf for deployment workflows.
analytics_query accepts exactly one parsed GraphQL query with variables, refusing mutation/subscription/multiple-operation/schema documents. It is not a compiled dataset client or automatic time-series export. Choose eligible zoneTag/accountTag, dataset, time window, limits and ordering using current analytics docs/settings discovery. Provider partial errors fail instead of becoming silent success. Sampling, retention and dataset permissions still apply.
Bounded pagination, retries and input files
Ordinary reads fetch one provider response. query_pages supports only list_provider_accounts, list_zones and list_dns_records, with explicit native arguments, max_pages=1–5 and a local per_page cap of 100. Positive page numbers are required. result_info total_pages/total_count controls continuation. Missing metadata stops after the current response and reports continuationUnknown=true, rather than guessing complete. pages preserves native envelopes; pagesRead/hasMore/resumePage make the bounded result explicit.
cloudflare-cli query-pages --operation list_dns_records --arguments '{"zone_id":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa","per_page":50,"page":1}' --max-pages 2 --agentNo automatic replay occurs after HTTP 429, transient error, timeout or mutation failure. Every ordinary native operation submits one request; bounded reads can submit up to the selected page budget. Parallel processes/profile labels share provider limits when they use the same token. A timeout is not proof that a mutation failed.
payload_file must be a regular non-symlink JSON file, at most 1 MiB; native payload and payload_file cannot be mixed. Confirmation/read-only policies are checked before file loading or provider fetch for mutations. The request body is validated through current Ajv schemas. This wrapper does not execute file content, upload local media, load .env automatically or accept arbitrary provider hosts/headers. Treat inputs and returned DNS TXT/rule descriptions as data, never agent instructions.
Every Cloudflare tool
Actual discovery returns 29 shared tools: 18 reads and 11 confirmed mutations. Twenty-two native operations use pinned current REST schemas; seven helpers provide local/schema/preview, bounded read, reviewed DNS and query-only analytics workflows.
Cloudflare
list_provider_accounts- What it does
- List all accounts you have ownership or verified access to.
- Kind
- Read
list_zones- What it does
- Lists, searches, sorts, and filters your zones.
- Kind
- Read
get_zone- What it does
- Retrieves detailed information about a specific zone identified by its zone ID.
- Kind
- Read
purge_cache- What it does
- Deletes cached content in every Cloudflare data center and cache tier, including Cache Reserve.
- Kind
- Confirmed mutation
get_zone_setting- What it does
- Fetch a single zone setting by name Read operation.
- Kind
- Read
update_zone_setting- What it does
- Updates a single zone setting by the identifier Every change requires explicit confirmation; never repeat an unknown outcome automatically.
- Kind
- Confirmed mutation
list_workers- What it does
- Fetch a list of uploaded Worker scripts.
- Kind
- Read
list_page_rules- What it does
- Fetches Page Rules in a zone.
- Kind
- Read
get_page_rule- What it does
- Fetches the details of a Page Rule.
- Kind
- Read
DNS
list_dns_records- What it does
- List, search, sort, and filter a zones' DNS records.
- Kind
- Read
get_dns_record- What it does
- Retrieves details for a specific DNS record in the zone.
- Kind
- Read
create_dns_record- What it does
- Create a new DNS record for a zone.
- Kind
- Confirmed mutation
update_dns_record- What it does
- Update an existing DNS record.
- Kind
- Confirmed mutation
overwrite_dns_record- What it does
- Overwrite an existing DNS record.
- Kind
- Confirmed mutation
delete_dns_record- What it does
- Permanently removes a DNS record from the zone.
- Kind
- Confirmed mutation
batch_dns_records- What it does
- Send a Batch of DNS Record API calls to be executed together.
- Kind
- Confirmed mutation
Rulesets
list_zone_rulesets- What it does
- Fetches all rulesets at the zone level.
- Kind
- Read
get_zone_ruleset- What it does
- Fetches the latest version of a zone ruleset.
- Kind
- Read
get_zone_entrypoint- What it does
- Fetches the latest version of the zone entry point ruleset for a given phase.
- Kind
- Read
create_zone_ruleset- What it does
- Creates a ruleset at the zone level.
- Kind
- Confirmed mutation
update_zone_ruleset- What it does
- Updates a zone ruleset, creating a new version.
- Kind
- Confirmed mutation
delete_zone_ruleset- What it does
- Deletes all versions of an existing zone ruleset.
- Kind
- Confirmed mutation
Local
list_accounts- What it does
- Local profile labels/default/auth method only.
- Kind
- Read
get_operation_schema- What it does
- Complete selected current API input, path and query schema.
- Kind
- Read
preview_operation- What it does
- Validate a named operation and return its exact local method/path/query/body/profile.
- Kind
- Read
Reads
query_pages- What it does
- Read at most five pages of a supported paginated named operation.
- Kind
- Read
DNS review
preview_dns_batch- What it does
- Local schema-validated DNS batch review capped at 50 actions.
- Kind
- Read
apply_dns_batch- What it does
- Verify the reviewed digest and submit one exact native DNS batch with mandatory confirmation.
- Kind
- Confirmed mutation
Analytics
analytics_query- What it does
- One parsed GraphQL query only, with variables.
- Kind
- Read
Is the Cloudflare MCP server safe?
Every one of the eleven mutations requires confirm=true in MCP or --confirm in the CLI. The same WriteGuard runs before file loading/provider execution. Creation, edits, replacement, deletion, cache purge and Ruleset changes all require explicit intent. --agent and --yes never grant it.
CLOUDFLARE_READ_ONLY=1 hides every mutation and refuses direct calls to hidden names even with confirmation. CLOUDFLARE_ALLOW_DESTRUCTIVE=0 blocks all mutations even when confirmed; read-only takes precedence. Use narrow provider tokens as the authorization boundary. A model can assert confirm=true; clients and the human still decide whether the action was requested. This is not a cryptographic human approval.
Review the exact zone/account, profile, record/rule IDs and full native body. apply_dns_batch additionally compares the reviewed request digest and makes one native request without automatic replay. Local preview does not authenticate the account, check conflicts or read remote state. Direct native batch also needs confirmation but does not require the digest.
An optional CLOUDFLARE_AUDIT_LOG records timestamp, surface, tool, risk, static summary and decision. It excludes request bodies, account IDs and tokens. Existing file ACLs/rotation are your responsibility; a failed audit append does not block the action. Account data returned after a change is untrusted content.
Confirmation is the caller asserting the approved exact action; it is not provider authorization or a signed human approval. The DNS digest binds the local request, not remote state, credential identity or atomic propagation.
Make it read-only
Set CLOUDFLARE_READ_ONLY=1 and reconnect: 18 reads remain and confirmed direct writes refuse. CLOUDFLARE_ALLOW_DESTRUCTIVE=0 also refuses confirmed mutations. Private profile defaults do not restrict upstream token grants.
Keep a log of every write
Set CLOUDFLARE_AUDIT_LOG to a file path. The server writes one line per attempted write, allowed or blocked.
Watch out: A timeout may leave a change completed remotely. Read affected resources before deliberately repeating; no request retries automatically. Provider HTTP 200 errors and analytics partial errors fail.
Your data
Account commands send the selected token in a Bearer header only to api.cloudflare.com. Prompts are not forwarded by this package; the native request/query content you select is. Your AI client may send returned DNS records, rule expressions and analytics to its model provider according to its own policy. The wrapper has no telemetry, public HTTP listener or hosted account store.
Named private profiles do not inherit global credentials. Token files use size/type/POSIX owner-only checks and are cached until restart. Windows ACLs require separate user configuration. Never commit credentials, .env, token files, real account exports or signed URLs; keep all such files outside public source and release staging.
Known credential keys, configured secrets and recognized signed URLs are redacted from ordinary output/errors. Legitimate URLs are preserved. Redaction is not complete anonymization: DNS TXT records, names, expressions and returned account data may still be sensitive. --select is local data shaping, not an authorization boundary or upstream privacy filter. Capture only needed output; terminal history and client transcripts can persist it.
Optional audit logging stores policy metadata, not bodies. The package does not automatically persist provider responses or backups; private input/output files you create remain on your system until you manage them. Revoke tokens through Cloudflare, not npm.
Several private accounts
Private profile configuration prevents implicit credential inheritance between named accounts. Configure the following placeholders only in a private client environment:
[
{
"name": "work",
"token_file": "/absolute/private/work-cloudflare.txt",
"account_id": "YOUR_WORK_ACCOUNT_ID",
"zone_id": "YOUR_WORK_ZONE_ID",
"token_kind": "user"
},
{
"name": "client",
"token_file": "/absolute/private/client-cloudflare.txt",
"account_id": "YOUR_CLIENT_ACCOUNT_ID",
"zone_id": "YOUR_CLIENT_ZONE_ID",
"token_kind": "account"
}
]Put the array in CLOUDFLARE_ACCOUNTS and set CLOUDFLARE_DEFAULT_ACCOUNT=work. Names must be unique and nonempty. --account selects the exact label; list_accounts returns only label/default/auth method, never token values, file paths or provider IDs. A profile lacking credentials does not fall back to a global token. Global account/zone defaults likewise do not leak into explicitly named entries.
account_id/zone_id are routing defaults; explicit operation inputs take precedence and can name another resource allowed by the token. Token-kind defaults to user and only changes the diagnostic verification route. Use provider token resource scopes for real access boundaries. Local profile separation is not a multi-user access-control service.
Cloudflare MCP server settings
Configure these in private shell/user-client settings; no automatic .env loading or global official CLI credentials are used.
- Default
- Credentials
- What it does
- Private Bearer API token; no Global API Key support
- Default
- Credentials
- What it does
- Absolute regular owner-only token-only file; max 64 KiB; takes precedence
- Default
- Credentials
- What it does
- Private JSON array of explicit named profiles; no global credential/default inheritance
- Default
- Credentials
- What it does
- Exact profile name; first profile default when omitted
- Default
- Credentials
- What it does
- Optional default account ID when using the single global profile
- Default
- Credentials
- What it does
- Optional default zone ID when using the single global profile
- Default
- Credentials
- What it does
- user (default) or account; doctor verification route only
- Default
- Safety
- What it does
- 1/true hides/refuses every mutation
- Default
- Safety
- What it does
- 0/false refuses confirmed mutations; otherwise enabled
- Default
- Safety
- What it does
- Optional private append-only metadata path
- Default
- Tuning
- What it does
- Default 30000; integer 100–300000; no automatic retry
- Default
- Tuning
- What it does
- Default 200; integer 0–10000; per profile/process
Troubleshooting
Run the doctor first. It names the step that failed and the fix.
| What you see | What to do |
|---|---|
| Exit 10 | Check selected private token/file and GUI environment. |
| 401/403 | Check intended resource, token grants, expiry/IP filters and membership. |
| Doctor status fails | Set user/account token kind; account verification needs the account ID; only active status succeeds. |
| Mutation refused | Confirm only the human-requested action and inspect policy. |
| Native body invalid | Use complete type-specific current payload schema. |
| Batch digest changed | Re-preview the exact body, zone and profile. |
| Continuation unknown | Missing result_info stops; do not claim complete. |
| HTTP 200 failure | Inspect provider success/errors or analytics partial errors. |
| 429 / timeout | Wait for upstream policy and inspect remote state before deliberate retry. |
| Missing analytics | Dataset grant, plan, settings/time window, retention and sampling. |
| Expected deployment/OAuth | Use official cf, Wrangler or hosted MCP for those workflows. |
| Desktop rejected | Check actual host/runtime, extension policy and private settings. |
If the server doesn't show up in your app at all, run the command your app runs, in a terminal, and read the error.
Every argument and nested native input
Twenty-two current native operations and seven helpers. Each schema below comes from actual stdio discovery. Native payload bodies preserve required keys, enums, unions, nested references and source constraints. Missing zone_id/account_id may use the selected private profile default; other required arguments remain required. Confirmation is enforced outside ordinary schema-required lists.
list_provider_accounts- CLI command
cloudflare-cli list-provider-accounts- Policy
- Read / local helper
list_zones- CLI command
cloudflare-cli list-zones- Policy
- Read / local helper
get_zone- CLI command
cloudflare-cli get-zone- Policy
- Read / local helper
list_dns_records- CLI command
cloudflare-cli list-dns-records- Policy
- Read / local helper
get_dns_record- CLI command
cloudflare-cli get-dns-record- Policy
- Read / local helper
create_dns_record- CLI command
cloudflare-cli create-dns-record- Policy
- Explicit confirmation required
update_dns_record- CLI command
cloudflare-cli update-dns-record- Policy
- Explicit confirmation required
overwrite_dns_record- CLI command
cloudflare-cli overwrite-dns-record- Policy
- Explicit confirmation required
delete_dns_record- CLI command
cloudflare-cli delete-dns-record- Policy
- Explicit confirmation required
batch_dns_records- CLI command
cloudflare-cli batch-dns-records- Policy
- Explicit confirmation required
purge_cache- CLI command
cloudflare-cli purge-cache- Policy
- Explicit confirmation required
get_zone_setting- CLI command
cloudflare-cli get-zone-setting- Policy
- Read / local helper
update_zone_setting- CLI command
cloudflare-cli update-zone-setting- Policy
- Explicit confirmation required
list_workers- CLI command
cloudflare-cli list-workers- Policy
- Read / local helper
list_zone_rulesets- CLI command
cloudflare-cli list-zone-rulesets- Policy
- Read / local helper
get_zone_ruleset- CLI command
cloudflare-cli get-zone-ruleset- Policy
- Read / local helper
get_zone_entrypoint- CLI command
cloudflare-cli get-zone-entrypoint- Policy
- Read / local helper
create_zone_ruleset- CLI command
cloudflare-cli create-zone-ruleset- Policy
- Explicit confirmation required
update_zone_ruleset- CLI command
cloudflare-cli update-zone-ruleset- Policy
- Explicit confirmation required
delete_zone_ruleset- CLI command
cloudflare-cli delete-zone-ruleset- Policy
- Explicit confirmation required
list_page_rules- CLI command
cloudflare-cli list-page-rules- Policy
- Read / local helper
get_page_rule- CLI command
cloudflare-cli get-page-rule- Policy
- Read / local helper
list_accounts- CLI command
cloudflare-cli list-accounts- Policy
- Read / local helper
get_operation_schema- CLI command
cloudflare-cli get-operation-schema- Policy
- Read / local helper
preview_operation- CLI command
cloudflare-cli preview-operation- Policy
- Read / local helper
query_pages- CLI command
cloudflare-cli query-pages- Policy
- Read / local helper
preview_dns_batch- CLI command
cloudflare-cli preview-dns-batch- Policy
- Read / local helper
apply_dns_batch- CLI command
cloudflare-cli apply-dns-batch- Policy
- Explicit confirmation required
analytics_query- CLI command
cloudflare-cli analytics-query- Policy
- Read / local helper
list_provider_accounts
cloudflare-cli list-provider-accounts
List all accounts you have ownership or verified access to. Read operation.
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Name of the account.
page- Required
- No; body and guard rules apply
- Type
- number
- Details
- Page number of paginated results. minimum:
1. default:1.
per_page- Required
- No; body and guard rules apply
- Type
- number
- Details
- Maximum number of results per page. minimum:
5. maximum:50. default:20.
direction- Required
- No; body and guard rules apply
- Type
- string
- Details
- Direction to order results. Values:
asc,desc.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /accounts; accounts-list-accounts. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
list_zones
cloudflare-cli list-zones
Lists, searches, sorts, and filters your zones. Listing zones across more than 500 accounts is currently not allowed. Read operation.
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- A domain name. Optional filter operators can be provided to extend refine the search: *
equal(default) *not_equal*starts_with*ends_with*contains*starts_with_case_sensitive*ends_with_case_sensitive*contains_case_sensitivemaxLength:253.
status- Required
- No; body and guard rules apply
- Type
- string
- Details
- Specify a zone status to filter by. Values:
initializing,pending,active,moved.
type- Required
- No; body and guard rules apply
- Type
- array
- Details
- Zone types to filter by. Multiple types can be specified as a comma-separated list (e.g., ?type=full,partial,secondary). When this parameter is not provided, zones with type "internal" are excluded from the results. Items: string.
account_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter by an account ID.
account_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- An account Name. Optional filter operators can be provided to extend refine the search: *
equal(default) *not_equal*starts_with*ends_with*contains*starts_with_case_sensitive*ends_with_case_sensitive*contains_case_sensitivemaxLength:253.
page- Required
- No; body and guard rules apply
- Type
- number
- Details
- Page number of paginated results. minimum:
1. default:1.
per_page- Required
- No; body and guard rules apply
- Type
- number
- Details
- Number of zones per page. minimum:
5. maximum:50. default:20.
order- Required
- No; body and guard rules apply
- Type
- string
- Details
- Field to order zones by. Values:
name,status,account.id,account.name,plan.id.
direction- Required
- No; body and guard rules apply
- Type
- string
- Details
- Direction to order zones. Values:
asc,desc.
match- Required
- No; body and guard rules apply
- Type
- string
- Details
- Whether to match all search requirements or at least one (any). Values:
any,all. default:all.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /zones; zones-get. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
get_zone
cloudflare-cli get-zone
Retrieves detailed information about a specific zone identified by its zone ID.
Returns zone configuration, status, nameservers, and associated metadata. Read operation.
zone_id- Required
- No; body and guard rules apply
- Type
- zones_identifier
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /zones/{zone_id}; zones-0-get. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
list_dns_records
cloudflare-cli list-dns-records
List, search, sort, and filter a zones' DNS records. Read operation.
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record name. This is a convenience alias for
name.exact.
name_exact- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record name. Name filters are case-insensitive.
name_contains- Required
- No; body and guard rules apply
- Type
- string
- Details
- Substring of the DNS record name. Name filters are case-insensitive.
name_startswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Prefix of the DNS record name. Name filters are case-insensitive.
name_endswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Suffix of the DNS record name. Name filters are case-insensitive.
type- Required
- No; body and guard rules apply
- Type
- dns-records_type
- Details
- See current schema
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record content. This is a convenience alias for
content.exact.
content_exact- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record content. Content filters are case-insensitive.
content_contains- Required
- No; body and guard rules apply
- Type
- string
- Details
- Substring of the DNS record content. Content filters are case-insensitive.
content_startswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Prefix of the DNS record content. Content filters are case-insensitive.
content_endswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Suffix of the DNS record content. Content filters are case-insensitive.
proxied- Required
- No; body and guard rules apply
- Type
- dns-records_proxied
- Details
- See current schema
match- Required
- No; body and guard rules apply
- Type
- dns-records_match
- Details
- See current schema
comment- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record comment. This is a convenience alias for
comment.exact.
comment_present- Required
- No; body and guard rules apply
- Type
- string
- Details
- If this parameter is present, only records with a comment are returned.
comment_absent- Required
- No; body and guard rules apply
- Type
- string
- Details
- If this parameter is present, only records without a comment are returned.
comment_exact- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record comment. Comment filters are case-insensitive.
comment_contains- Required
- No; body and guard rules apply
- Type
- string
- Details
- Substring of the DNS record comment. Comment filters are case-insensitive.
comment_startswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Prefix of the DNS record comment. Comment filters are case-insensitive.
comment_endswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Suffix of the DNS record comment. Comment filters are case-insensitive.
tag- Required
- No; body and guard rules apply
- Type
- string
- Details
- Condition on the DNS record tag. Parameter values can be of the form
:to search for an exactname:valuepair, or just `to search for records with a specific tag name regardless of its value. This is a convenience shorthand for the more powerfultag.parameters. Examples: -tag=importantis equivalent totag.present=important-tag=team:DNSis equivalent totag.exact=team:DNS`
tag_present- Required
- No; body and guard rules apply
- Type
- string
- Details
- Name of a tag which must be present on the DNS record. Tag filters are case-insensitive.
tag_absent- Required
- No; body and guard rules apply
- Type
- string
- Details
- Name of a tag which must not be present on the DNS record. Tag filters are case-insensitive.
tag_exact- Required
- No; body and guard rules apply
- Type
- string
- Details
- A tag and value, of the form
:. The API will only return DNS records that have a tag named `whose value is`. Tag filters are case-insensitive.
tag_contains- Required
- No; body and guard rules apply
- Type
- string
- Details
- A tag and value, of the form
:. The API will only return DNS records that have a tag named `whose value contains`. Tag filters are case-insensitive.
tag_startswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- A tag and value, of the form
:. The API will only return DNS records that have a tag named `whose value starts with`. Tag filters are case-insensitive.
tag_endswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- A tag and value, of the form
:. The API will only return DNS records that have a tag named `whose value ends with`. Tag filters are case-insensitive.
search- Required
- No; body and guard rules apply
- Type
- dns-records_search
- Details
- See current schema
tag_match- Required
- No; body and guard rules apply
- Type
- dns-records_tag_match
- Details
- See current schema
page- Required
- No; body and guard rules apply
- Type
- dns-records_page
- Details
- See current schema
per_page- Required
- No; body and guard rules apply
- Type
- dns-records_per_page
- Details
- See current schema
order- Required
- No; body and guard rules apply
- Type
- dns-records_order
- Details
- See current schema
direction- Required
- No; body and guard rules apply
- Type
- dns-records_direction
- Details
- See current schema
include_shadow_metadata- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include shadow metadata in the
metafield of each record in the response. See Shadowed records. default:False.
shadowed_by_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filters the response to records at or below the specified NS delegation name. NS, DS, and NSEC records at the delegation name are excluded because they are not shadowed by that delegation. Those record types are included only when they exist below the delegation. The value must be a non-apex subdomain of the zone. Requires
include_shadow_metadata=true. See Shadowed records.
shadowing_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Returns NS records that shadow the given name, searching at the name itself and each of its ancestor names within the zone, excluding the zone apex. The value must be a subdomain of the zone; the zone apex is not accepted. See Shadowed records.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /zones/{zone_id}/dns_records; dns-records-for-a-zone-list-dns-records. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
get_dns_record
cloudflare-cli get-dns-record
Retrieves details for a specific DNS record in the zone. Read operation.
dns_record_id- Required
- Yes
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
include_shadow_metadata- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include shadow metadata in the
metafield of each record in the response. See Shadowed records. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /zones/{zone_id}/dns_records/{dns_record_id}; dns-records-for-a-zone-dns-record-details. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
create_dns_record
cloudflare-cli create-dns-record
Create a new DNS record for a zone.
Notes: - A/AAAA records cannot exist on the same name as CNAME records. - NS records cannot exist on the same name as any other record type. - Domain names are always represented in Punycode, even if Unicode characters were used when creating the record. Every change requires explicit confirmation; never repeat an unknown outcome automatically.
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
include_shadow_metadata- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include shadow metadata in the
metafield of each record in the response. See Shadowed records. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
Native operation: POST /zones/{zone_id}/dns_records; dns-records-for-a-zone-create-dns-record. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
update_dns_record
cloudflare-cli update-dns-record
Update an existing DNS record.
Notes: - A/AAAA records cannot exist on the same name as CNAME records. - NS records cannot exist on the same name as any other record type. - Domain names are always represented in Punycode, even if Unicode characters were used when creating the record. Every change requires explicit confirmation; never repeat an unknown outcome automatically.
dns_record_id- Required
- Yes
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
include_shadow_metadata- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include shadow metadata in the
metafield of each record in the response. See Shadowed records. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
Native operation: PATCH /zones/{zone_id}/dns_records/{dns_record_id}; dns-records-for-a-zone-patch-dns-record. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
overwrite_dns_record
cloudflare-cli overwrite-dns-record
Overwrite an existing DNS record.
Notes: - A/AAAA records cannot exist on the same name as CNAME records. - NS records cannot exist on the same name as any other record type. - Domain names are always represented in Punycode, even if Unicode characters were used when creating the record. Every change requires explicit confirmation; never repeat an unknown outcome automatically.
dns_record_id- Required
- Yes
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
include_shadow_metadata- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include shadow metadata in the
metafield of each record in the response. See Shadowed records. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
Native operation: PUT /zones/{zone_id}/dns_records/{dns_record_id}; dns-records-for-a-zone-update-dns-record. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
delete_dns_record
cloudflare-cli delete-dns-record
Permanently removes a DNS record from the zone. Every change requires explicit confirmation; never repeat an unknown outcome automatically.
dns_record_id- Required
- Yes
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
Native operation: DELETE /zones/{zone_id}/dns_records/{dns_record_id}; dns-records-for-a-zone-delete-dns-record. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
batch_dns_records
cloudflare-cli batch-dns-records
Send a Batch of DNS Record API calls to be executed together.
Notes: - Although Cloudflare will execute the batched operations in a single database transaction, Cloudflare's distributed KV store must treat each record change as a single key-value pair. This means that the propagation of changes is not atomic. See [the documentation](https://developers.cloudflare.com/dns/manage-dns-records/how-to/batch-record-changes/ "Batch DNS records") for more information. - The operations you specify within the /batch request body are always executed in the following order:
- Deletes - Patches - Puts - Posts Every change requires explicit confirmation; never repeat an unknown outcome automatically.
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
include_shadow_metadata- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include shadow metadata in the
metafield of each record in the response. See Shadowed records. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
Native operation: POST /zones/{zone_id}/dns_records/batch; dns-records-for-a-zone-batch-dns-records. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
purge_cache
cloudflare-cli purge-cache
Deletes cached content in every Cloudflare data center and cache tier, including Cache Reserve. The next request for purged content is a cache MISS: Cloudflare fetches the full response from your origin and caches it again. Cloudflare does not serve purged content from cache again, even if your origin is unavailable.
To keep content cached and have Cloudflare revalidate it with your origin instead, use POST /zones/{zone_id}/invalidate_cache.
Choose what to purge
Send one of these fields in the request body:
files: specific URLs. If your cache key includes request headers, send each URL with the header values it was cached with.tags: all content whoseCache-Tagresponse header contains one of the tags.hosts: all content cached for the hostnames.prefixes: all content whose URL starts with one of the prefixes.purge_everything: all cached content in the zone.
Check the result
A 200 response with success: true means Cloudflare accepted the request. It does not confirm that any content was cached or removed. To check, request a purged URL and confirm that the CF-Cache-Status response header is MISS.
Availability and limits
Rate limits and the number of items you can send in one request depend on your plan. See Purge cache: availability and limits. Every change requires explicit confirmation; never repeat an unknown outcome automatically.
zone_id- Required
- No; body and guard rules apply
- Type
- cache-purge_identifier
- Details
- The zone ID. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- Union
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
Native operation: POST /zones/{zone_id}/purge_cache; zone-purge. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
get_zone_setting
cloudflare-cli get-zone-setting
Fetch a single zone setting by name Read operation.
zone_id- Required
- No; body and guard rules apply
- Type
- zones_identifier
- Details
- See current schema minLength:
1.
setting_id- Required
- Yes
- Type
- zones_setting_name
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /zones/{zone_id}/settings/{setting_id}; zone-settings-get-single-setting. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
update_zone_setting
cloudflare-cli update-zone-setting
Updates a single zone setting by the identifier Every change requires explicit confirmation; never repeat an unknown outcome automatically.
zone_id- Required
- No; body and guard rules apply
- Type
- zones_identifier
- Details
- See current schema minLength:
1.
setting_id- Required
- Yes
- Type
- zones_setting_name
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- Union
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
Native operation: PATCH /zones/{zone_id}/settings/{setting_id}; zone-settings-edit-single-setting. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
list_workers
cloudflare-cli list-workers
Fetch a list of uploaded Worker scripts. Read operation.
account_id- Required
- No; body and guard rules apply
- Type
- workers_identifier
- Details
- See current schema minLength:
1.
tags- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter scripts by tags. Format: comma-separated list of tag:allowed pairs where allowed is 'yes' or 'no'.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /accounts/{account_id}/workers/scripts; worker-script-list-workers. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
list_zone_rulesets
cloudflare-cli list-zone-rulesets
Fetches all rulesets at the zone level. Read operation.
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
cursor- Required
- No; body and guard rules apply
- Type
- rulesets_Cursor
- Details
- See current schema
per_page- Required
- No; body and guard rules apply
- Type
- rulesets_PerPage
- Details
- See current schema
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /zones/{zone_id}/rulesets; listZoneRulesets. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
get_zone_ruleset
cloudflare-cli get-zone-ruleset
Fetches the latest version of a zone ruleset. Read operation.
ruleset_id- Required
- Yes
- Type
- rulesets_RulesetId
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /zones/{zone_id}/rulesets/{ruleset_id}; getZoneRuleset. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
get_zone_entrypoint
cloudflare-cli get-zone-entrypoint
Fetches the latest version of the zone entry point ruleset for a given phase. Read operation.
ruleset_phase- Required
- Yes
- Type
- rulesets_RulesetPhase
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /zones/{zone_id}/rulesets/phases/{ruleset_phase}/entrypoint; getZoneEntrypointRuleset. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
create_zone_ruleset
cloudflare-cli create-zone-ruleset
Creates a ruleset at the zone level. Every change requires explicit confirmation; never repeat an unknown outcome automatically.
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
dry_run- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Validates the request without persisting changes when set to
true. Responses that normally return 200 returnresult: null; endpoints that normally return 204 continue to return 204. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
Native operation: POST /zones/{zone_id}/rulesets; createZoneRuleset. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
update_zone_ruleset
cloudflare-cli update-zone-ruleset
Updates a zone ruleset, creating a new version. Every change requires explicit confirmation; never repeat an unknown outcome automatically.
ruleset_id- Required
- Yes
- Type
- rulesets_RulesetId
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
dry_run- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Validates the request without persisting changes when set to
true. Responses that normally return 200 returnresult: null; endpoints that normally return 204 continue to return 204. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
Native operation: PUT /zones/{zone_id}/rulesets/{ruleset_id}; updateZoneRuleset. Native body required through payload or payload_file. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
delete_zone_ruleset
cloudflare-cli delete-zone-ruleset
Deletes all versions of an existing zone ruleset. Every change requires explicit confirmation; never repeat an unknown outcome automatically.
ruleset_id- Required
- Yes
- Type
- rulesets_RulesetId
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
dry_run- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Validates the request without persisting changes when set to
true. Responses that normally return 200 returnresult: null; endpoints that normally return 204 continue to return 204. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
Native operation: DELETE /zones/{zone_id}/rulesets/{ruleset_id}; deleteZoneRuleset. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
list_page_rules
cloudflare-cli list-page-rules
Fetches Page Rules in a zone. Read operation.
zone_id- Required
- No; body and guard rules apply
- Type
- zones_identifier-2
- Details
- See current schema minLength:
1.
order- Required
- No; body and guard rules apply
- Type
- string
- Details
- The field used to sort returned Page Rules. Values:
status,priority. default:priority.
direction- Required
- No; body and guard rules apply
- Type
- string
- Details
- The direction used to sort returned Page Rules. Values:
asc,desc. default:desc.
match- Required
- No; body and guard rules apply
- Type
- string
- Details
- When set to
all, all the search requirements must match. When set toany, only one of the search requirements has to match. Values:any,all. default:all.
status- Required
- No; body and guard rules apply
- Type
- string
- Details
- The status of the Page Rule. Values:
active,disabled. default:disabled.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /zones/{zone_id}/pagerules; page-rules-list-page-rules. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
get_page_rule
cloudflare-cli get-page-rule
Fetches the details of a Page Rule. Read operation.
pagerule_id- Required
- Yes
- Type
- zones_identifier-2
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- zones_identifier-2
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
Native operation: GET /zones/{zone_id}/pagerules/{pagerule_id}; page-rules-get-a-page-rule. Native body not required. Schema discovery is local; endpoint permissions/plan decisions remain provider controlled.
list_accounts
cloudflare-cli list-accounts
Local profile labels/default/auth method only. No provider IDs, credential values or paths. No network.
- Required
- No
- Type
- None
- Details
- No arguments
get_operation_schema
cloudflare-cli get-operation-schema
Complete selected current API input, path and query schema. Local metadata only.
operation- Required
- Yes
- Type
- string
- Details
- See the full input schema. Values:
list_provider_accounts,list_zones,get_zone,list_dns_records,get_dns_record,create_dns_record,update_dns_record,overwrite_dns_record,delete_dns_record,batch_dns_records,purge_cache,get_zone_setting,update_zone_setting,list_workers,list_zone_rulesets,get_zone_ruleset,get_zone_entrypoint,create_zone_ruleset,update_zone_ruleset,delete_zone_ruleset,list_page_rules,get_page_rule.
preview_operation
cloudflare-cli preview-operation
Validate a named operation and return its exact local method/path/query/body/profile. No request, auth validation or provider policy checks.
operation- Required
- Yes
- Type
- string
- Details
- See the full input schema. Values:
list_provider_accounts,list_zones,get_zone,list_dns_records,get_dns_record,create_dns_record,update_dns_record,overwrite_dns_record,delete_dns_record,batch_dns_records,purge_cache,get_zone_setting,update_zone_setting,list_workers,list_zone_rulesets,get_zone_ruleset,get_zone_entrypoint,create_zone_ruleset,update_zone_ruleset,delete_zone_ruleset,list_page_rules,get_page_rule.
arguments- Required
- Yes
- Type
- object
- Details
- See the full input schema.
query_pages
cloudflare-cli query-pages
Read at most five pages of a supported paginated named operation. Provider page metadata determines continuation; missing metadata stops with an explicit unknown continuation.
operation- Required
- Yes
- Type
- string
- Details
- See the full input schema. Values:
list_provider_accounts,list_zones,list_dns_records.
arguments- Required
- Yes
- Type
- object
- Details
- See the full input schema.
max_pages- Required
- No; body and guard rules apply
- Type
- integer
- Details
- See the full input schema. minimum:
1. maximum:5. default:1.
preview_dns_batch
cloudflare-cli preview-dns-batch
Local schema-validated DNS batch review capped at 50 actions. Digest binds exact JSON body, zone path and profile label; no account or DNS state read. Not a provider authorization grant.
zone_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. minLength:
1. maxLength:32.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. minLength:
1.
apply_dns_batch
cloudflare-cli apply-dns-batch
Verify the reviewed digest and submit one exact native DNS batch with mandatory confirmation. Does not assert remote-state consistency or atomic DNS propagation; no retry.
zone_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. minLength:
1. maxLength:32.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. minLength:
1.
preview_sha256- Required
- Yes
- Type
- string
- Details
- See the full input schema. pattern:
^[0-9a-f]{64}$.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- See the full input schema.
analytics_query
cloudflare-cli analytics-query
One parsed GraphQL query only, with variables. No mutations, subscriptions or multiple operations. Permissions, dataset retention, sampling and query limits remain provider controlled.
query- Required
- Yes
- Type
- string
- Details
- See the full input schema. minLength:
1. maxLength:65536.
variables- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
Nested native input definitions
Identical object shapes are listed once below. References point to the named definitions; union branches retain their individual requirements. Some provider JSON-schema conditions do not fit a flat table; use schema COMMAND or get_operation_schema for complete validation. Unknown native root body keys are refused locally; provider constraints still apply.
##### list_provider_accounts
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Name of the account.
page- Required
- No; body and guard rules apply
- Type
- number
- Details
- Page number of paginated results. minimum:
1. default:1.
per_page- Required
- No; body and guard rules apply
- Type
- number
- Details
- Maximum number of results per page. minimum:
5. maximum:50. default:20.
direction- Required
- No; body and guard rules apply
- Type
- string
- Details
- Direction to order results. Values:
asc,desc.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### list_zones
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- A domain name. Optional filter operators can be provided to extend refine the search: *
equal(default) *not_equal*starts_with*ends_with*contains*starts_with_case_sensitive*ends_with_case_sensitive*contains_case_sensitivemaxLength:253.
status- Required
- No; body and guard rules apply
- Type
- string
- Details
- Specify a zone status to filter by. Values:
initializing,pending,active,moved.
type- Required
- No; body and guard rules apply
- Type
- array
- Details
- Zone types to filter by. Multiple types can be specified as a comma-separated list (e.g., ?type=full,partial,secondary). When this parameter is not provided, zones with type "internal" are excluded from the results. Items: string.
account_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter by an account ID.
account_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- An account Name. Optional filter operators can be provided to extend refine the search: *
equal(default) *not_equal*starts_with*ends_with*contains*starts_with_case_sensitive*ends_with_case_sensitive*contains_case_sensitivemaxLength:253.
page- Required
- No; body and guard rules apply
- Type
- number
- Details
- Page number of paginated results. minimum:
1. default:1.
per_page- Required
- No; body and guard rules apply
- Type
- number
- Details
- Number of zones per page. minimum:
5. maximum:50. default:20.
order- Required
- No; body and guard rules apply
- Type
- string
- Details
- Field to order zones by. Values:
name,status,account.id,account.name,plan.id.
direction- Required
- No; body and guard rules apply
- Type
- string
- Details
- Direction to order zones. Values:
asc,desc.
match- Required
- No; body and guard rules apply
- Type
- string
- Details
- Whether to match all search requirements or at least one (any). Values:
any,all. default:all.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### get_zone
zone_id- Required
- No; body and guard rules apply
- Type
- zones_identifier
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### list_dns_records
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record name. This is a convenience alias for
name.exact.
name_exact- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record name. Name filters are case-insensitive.
name_contains- Required
- No; body and guard rules apply
- Type
- string
- Details
- Substring of the DNS record name. Name filters are case-insensitive.
name_startswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Prefix of the DNS record name. Name filters are case-insensitive.
name_endswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Suffix of the DNS record name. Name filters are case-insensitive.
type- Required
- No; body and guard rules apply
- Type
- dns-records_type
- Details
- See current schema
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record content. This is a convenience alias for
content.exact.
content_exact- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record content. Content filters are case-insensitive.
content_contains- Required
- No; body and guard rules apply
- Type
- string
- Details
- Substring of the DNS record content. Content filters are case-insensitive.
content_startswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Prefix of the DNS record content. Content filters are case-insensitive.
content_endswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Suffix of the DNS record content. Content filters are case-insensitive.
proxied- Required
- No; body and guard rules apply
- Type
- dns-records_proxied
- Details
- See current schema
match- Required
- No; body and guard rules apply
- Type
- dns-records_match
- Details
- See current schema
comment- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record comment. This is a convenience alias for
comment.exact.
comment_present- Required
- No; body and guard rules apply
- Type
- string
- Details
- If this parameter is present, only records with a comment are returned.
comment_absent- Required
- No; body and guard rules apply
- Type
- string
- Details
- If this parameter is present, only records without a comment are returned.
comment_exact- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact value of the DNS record comment. Comment filters are case-insensitive.
comment_contains- Required
- No; body and guard rules apply
- Type
- string
- Details
- Substring of the DNS record comment. Comment filters are case-insensitive.
comment_startswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Prefix of the DNS record comment. Comment filters are case-insensitive.
comment_endswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- Suffix of the DNS record comment. Comment filters are case-insensitive.
tag- Required
- No; body and guard rules apply
- Type
- string
- Details
- Condition on the DNS record tag. Parameter values can be of the form
:to search for an exactname:valuepair, or just `to search for records with a specific tag name regardless of its value. This is a convenience shorthand for the more powerfultag.parameters. Examples: -tag=importantis equivalent totag.present=important-tag=team:DNSis equivalent totag.exact=team:DNS`
tag_present- Required
- No; body and guard rules apply
- Type
- string
- Details
- Name of a tag which must be present on the DNS record. Tag filters are case-insensitive.
tag_absent- Required
- No; body and guard rules apply
- Type
- string
- Details
- Name of a tag which must not be present on the DNS record. Tag filters are case-insensitive.
tag_exact- Required
- No; body and guard rules apply
- Type
- string
- Details
- A tag and value, of the form
:. The API will only return DNS records that have a tag named `whose value is`. Tag filters are case-insensitive.
tag_contains- Required
- No; body and guard rules apply
- Type
- string
- Details
- A tag and value, of the form
:. The API will only return DNS records that have a tag named `whose value contains`. Tag filters are case-insensitive.
tag_startswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- A tag and value, of the form
:. The API will only return DNS records that have a tag named `whose value starts with`. Tag filters are case-insensitive.
tag_endswith- Required
- No; body and guard rules apply
- Type
- string
- Details
- A tag and value, of the form
:. The API will only return DNS records that have a tag named `whose value ends with`. Tag filters are case-insensitive.
search- Required
- No; body and guard rules apply
- Type
- dns-records_search
- Details
- See current schema
tag_match- Required
- No; body and guard rules apply
- Type
- dns-records_tag_match
- Details
- See current schema
page- Required
- No; body and guard rules apply
- Type
- dns-records_page
- Details
- See current schema
per_page- Required
- No; body and guard rules apply
- Type
- dns-records_per_page
- Details
- See current schema
order- Required
- No; body and guard rules apply
- Type
- dns-records_order
- Details
- See current schema
direction- Required
- No; body and guard rules apply
- Type
- dns-records_direction
- Details
- See current schema
include_shadow_metadata- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include shadow metadata in the
metafield of each record in the response. See Shadowed records. default:False.
shadowed_by_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filters the response to records at or below the specified NS delegation name. NS, DS, and NSEC records at the delegation name are excluded because they are not shadowed by that delegation. Those record types are included only when they exist below the delegation. The value must be a non-apex subdomain of the zone. Requires
include_shadow_metadata=true. See Shadowed records.
shadowing_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Returns NS records that shadow the given name, searching at the name itself and each of its ancestor names within the zone, excluding the zone apex. The value must be a subdomain of the zone; the zone apex is not accepted. See Shadowed records.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### get_dns_record
dns_record_id- Required
- Yes
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
include_shadow_metadata- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include shadow metadata in the
metafield of each record in the response. See Shadowed records. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### create_dns_record
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
include_shadow_metadata- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include shadow metadata in the
metafield of each record in the response. See Shadowed records. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
##### update_dns_record
dns_record_id- Required
- Yes
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
include_shadow_metadata- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include shadow metadata in the
metafield of each record in the response. See Shadowed records. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
##### delete_dns_record
dns_record_id- Required
- Yes
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
##### batch_dns_records
zone_id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See current schema minLength:
1.
include_shadow_metadata- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include shadow metadata in the
metafield of each record in the response. See Shadowed records. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
##### batch_dns_records.payload
deletes- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. Items: dns-records_dns-record-batch-delete.
patches- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. Items: dns-records_dns-record-batch-patch.
posts- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. Items: dns-records_dns-record-batch-post.
puts- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. Items: dns-records_dns-record-batch-put.
##### purge_cache
zone_id- Required
- No; body and guard rules apply
- Type
- cache-purge_identifier
- Details
- The zone ID. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- Union
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
##### get_zone_setting
zone_id- Required
- No; body and guard rules apply
- Type
- zones_identifier
- Details
- See current schema minLength:
1.
setting_id- Required
- Yes
- Type
- zones_setting_name
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### update_zone_setting
zone_id- Required
- No; body and guard rules apply
- Type
- zones_identifier
- Details
- See current schema minLength:
1.
setting_id- Required
- Yes
- Type
- zones_setting_name
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- Union
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
##### update_zone_setting.payload.oneOf[0]
enabled- Required
- No; body and guard rules apply
- Type
- zones_ssl_recommender_enabled
- Details
- See the full input schema.
##### update_zone_setting.payload.oneOf[1]
value- Required
- No; body and guard rules apply
- Type
- zones_setting_value
- Details
- See the full input schema.
##### list_workers
account_id- Required
- No; body and guard rules apply
- Type
- workers_identifier
- Details
- See current schema minLength:
1.
tags- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter scripts by tags. Format: comma-separated list of tag:allowed pairs where allowed is 'yes' or 'no'.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### list_zone_rulesets
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
cursor- Required
- No; body and guard rules apply
- Type
- rulesets_Cursor
- Details
- See current schema
per_page- Required
- No; body and guard rules apply
- Type
- rulesets_PerPage
- Details
- See current schema
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### get_zone_ruleset
ruleset_id- Required
- Yes
- Type
- rulesets_RulesetId
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### get_zone_entrypoint
ruleset_phase- Required
- Yes
- Type
- rulesets_RulesetPhase
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### create_zone_ruleset
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
dry_run- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Validates the request without persisting changes when set to
true. Responses that normally return 200 returnresult: null; endpoints that normally return 204 continue to return 204. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
##### create_zone_ruleset.payload.allOf[1]
kind- Required
- No; body and guard rules apply
- Type
- rulesets_RulesetKind
- Details
- See the full input schema.
phase- Required
- No; body and guard rules apply
- Type
- rulesets_RulesetPhase
- Details
- See the full input schema.
rules- Required
- No; body and guard rules apply
- Type
- rulesets_RequestRules
- Details
- See the full input schema.
##### update_zone_ruleset
ruleset_id- Required
- Yes
- Type
- rulesets_RulesetId
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
dry_run- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Validates the request without persisting changes when set to
true. Responses that normally return 200 returnresult: null; endpoints that normally return 204 continue to return 204. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
payload- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- Complete current native JSON request body. Do not mix with payload_file.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular non-symlink local JSON request file, at most 1 MiB. No credentials in public files. minLength:
1.
##### delete_zone_ruleset
ruleset_id- Required
- Yes
- Type
- rulesets_RulesetId
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- rulesets_ZoneId
- Details
- See current schema minLength:
1.
dry_run- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Validates the request without persisting changes when set to
true. Responses that normally return 200 returnresult: null; endpoints that normally return 204 continue to return 204. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for the exact selected mutation, target and reviewed request.
##### list_page_rules
zone_id- Required
- No; body and guard rules apply
- Type
- zones_identifier-2
- Details
- See current schema minLength:
1.
order- Required
- No; body and guard rules apply
- Type
- string
- Details
- The field used to sort returned Page Rules. Values:
status,priority. default:priority.
direction- Required
- No; body and guard rules apply
- Type
- string
- Details
- The direction used to sort returned Page Rules. Values:
asc,desc. default:desc.
match- Required
- No; body and guard rules apply
- Type
- string
- Details
- When set to
all, all the search requirements must match. When set toany, only one of the search requirements has to match. Values:any,all. default:all.
status- Required
- No; body and guard rules apply
- Type
- string
- Details
- The status of the Page Rule. Values:
active,disabled. default:disabled.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### get_page_rule
pagerule_id- Required
- Yes
- Type
- zones_identifier-2
- Details
- See current schema minLength:
1.
zone_id- Required
- No; body and guard rules apply
- Type
- zones_identifier-2
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Exact private profile label. Account/zone defaults route inputs; token permissions remain provider controlled.
##### get_operation_schema
operation- Required
- Yes
- Type
- string
- Details
- See the full input schema. Values:
list_provider_accounts,list_zones,get_zone,list_dns_records,get_dns_record,create_dns_record,update_dns_record,overwrite_dns_record,delete_dns_record,batch_dns_records,purge_cache,get_zone_setting,update_zone_setting,list_workers,list_zone_rulesets,get_zone_ruleset,get_zone_entrypoint,create_zone_ruleset,update_zone_ruleset,delete_zone_ruleset,list_page_rules,get_page_rule.
##### preview_operation
operation- Required
- Yes
- Type
- string
- Details
- See the full input schema. Values:
list_provider_accounts,list_zones,get_zone,list_dns_records,get_dns_record,create_dns_record,update_dns_record,overwrite_dns_record,delete_dns_record,batch_dns_records,purge_cache,get_zone_setting,update_zone_setting,list_workers,list_zone_rulesets,get_zone_ruleset,get_zone_entrypoint,create_zone_ruleset,update_zone_ruleset,delete_zone_ruleset,list_page_rules,get_page_rule.
arguments- Required
- Yes
- Type
- object
- Details
- See the full input schema.
##### query_pages
operation- Required
- Yes
- Type
- string
- Details
- See the full input schema. Values:
list_provider_accounts,list_zones,list_dns_records.
arguments- Required
- Yes
- Type
- object
- Details
- See the full input schema.
max_pages- Required
- No; body and guard rules apply
- Type
- integer
- Details
- See the full input schema. minimum:
1. maximum:5. default:1.
##### preview_dns_batch
zone_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. minLength:
1. maxLength:32.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. minLength:
1.
##### preview_dns_batch.payload
deletes- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. Items: dns-records_dns-record-batch-delete.
patches- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. Items: dns-records_dns-record-batch-patch.
posts- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. Items: dns-records_dns-record-batch-post.
puts- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. Items: dns-records_dns-record-batch-put.
##### apply_dns_batch
zone_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. minLength:
1. maxLength:32.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. minLength:
1.
preview_sha256- Required
- Yes
- Type
- string
- Details
- See the full input schema. pattern:
^[0-9a-f]{64}$.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- See the full input schema.
##### analytics_query
query- Required
- Yes
- Type
- string
- Details
- See the full input schema. minLength:
1. maxLength:65536.
variables- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### dns-records_AAAARecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- A valid IPv6 address. format:
ipv6.
private_routing- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Enables private network routing to the origin. default:
False.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
AAAA.
##### dns-records_ARecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- A valid IPv4 address. format:
ipv4.
private_routing- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Enables private network routing to the origin. default:
False.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
A.
##### dns-records_CAARecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted CAA content. See 'data' to set CAA properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a CAA record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
CAA.
##### dns-records_CAARecord.allOf[1].data
flags- Required
- No; body and guard rules apply
- Type
- number
- Details
- Flags for the CAA record. minimum:
0. maximum:255.
tag- Required
- No; body and guard rules apply
- Type
- string
- Details
- Name of the property controlled by this record (e.g.: issue, issuewild, iodef).
value- Required
- No; body and guard rules apply
- Type
- string
- Details
- Value of the record. This field's semantics depend on the chosen tag.
##### dns-records_CERTRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted CERT content. See 'data' to set CERT properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a CERT record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
CERT.
##### dns-records_CERTRecord.allOf[1].data
algorithm- Required
- No; body and guard rules apply
- Type
- number
- Details
- Algorithm. minimum:
0. maximum:255.
certificate- Required
- No; body and guard rules apply
- Type
- string
- Details
- Certificate.
key_tag- Required
- No; body and guard rules apply
- Type
- number
- Details
- Key Tag. minimum:
0. maximum:65535.
type- Required
- No; body and guard rules apply
- Type
- number
- Details
- Type. minimum:
0. maximum:65535.
##### dns-records_CNAMERecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- A valid hostname. Must not match the record's name.
settings- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
CNAME.
##### dns-records_CNAMERecord.allOf[1].settings
flatten_cname- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- If enabled, causes the CNAME record to be resolved externally and the resulting address records (e.g., A and AAAA) to be returned instead of the CNAME record itself. This setting is unavailable for proxied records, since they are always flattened. default:
False.
##### dns-records_DNSKEYRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted DNSKEY content. See 'data' to set DNSKEY properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a DNSKEY record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
DNSKEY.
##### dns-records_DNSKEYRecord.allOf[1].data
algorithm- Required
- No; body and guard rules apply
- Type
- number
- Details
- Algorithm. minimum:
0. maximum:255.
flags- Required
- No; body and guard rules apply
- Type
- number
- Details
- Flags. minimum:
0. maximum:65535.
protocol- Required
- No; body and guard rules apply
- Type
- number
- Details
- Protocol. minimum:
0. maximum:255.
public_key- Required
- No; body and guard rules apply
- Type
- string
- Details
- Public Key.
##### dns-records_DSRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted DS content. See 'data' to set DS properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a DS record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
DS.
##### dns-records_DSRecord.allOf[1].data
algorithm- Required
- No; body and guard rules apply
- Type
- number
- Details
- Algorithm. minimum:
0. maximum:255.
digest- Required
- No; body and guard rules apply
- Type
- string
- Details
- Digest.
digest_type- Required
- No; body and guard rules apply
- Type
- number
- Details
- Digest Type. minimum:
0. maximum:255.
key_tag- Required
- No; body and guard rules apply
- Type
- number
- Details
- Key Tag. minimum:
0. maximum:65535.
##### dns-records_HTTPSRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted HTTPS content. See 'data' to set HTTPS properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a HTTPS record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
HTTPS.
##### dns-records_HTTPSRecord.allOf[1].data
priority- Required
- No; body and guard rules apply
- Type
- number
- Details
- Priority. minimum:
0. maximum:65535.
target- Required
- No; body and guard rules apply
- Type
- string
- Details
- Target.
value- Required
- No; body and guard rules apply
- Type
- string
- Details
- Value.
##### dns-records_LOCRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted LOC content. See 'data' to set LOC properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a LOC record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
LOC.
##### dns-records_LOCRecord.allOf[1].data
altitude- Required
- No; body and guard rules apply
- Type
- number
- Details
- Altitude of location in meters. minimum:
-100000. maximum:42849672.95.
lat_degrees- Required
- No; body and guard rules apply
- Type
- number
- Details
- Degrees of latitude. minimum:
0. maximum:90.
lat_direction- Required
- No; body and guard rules apply
- Type
- string
- Details
- Latitude direction. Values:
N,S.
lat_minutes- Required
- No; body and guard rules apply
- Type
- number
- Details
- Minutes of latitude. minimum:
0. maximum:59.
lat_seconds- Required
- No; body and guard rules apply
- Type
- number
- Details
- Seconds of latitude. minimum:
0. maximum:59.999.
long_degrees- Required
- No; body and guard rules apply
- Type
- number
- Details
- Degrees of longitude. minimum:
0. maximum:180.
long_direction- Required
- No; body and guard rules apply
- Type
- string
- Details
- Longitude direction. Values:
E,W.
long_minutes- Required
- No; body and guard rules apply
- Type
- number
- Details
- Minutes of longitude. minimum:
0. maximum:59.
long_seconds- Required
- No; body and guard rules apply
- Type
- number
- Details
- Seconds of longitude. minimum:
0. maximum:59.999.
precision_horz- Required
- No; body and guard rules apply
- Type
- number
- Details
- Horizontal precision of location. minimum:
0. maximum:90000000.
precision_vert- Required
- No; body and guard rules apply
- Type
- number
- Details
- Vertical precision of location. minimum:
0. maximum:90000000.
size- Required
- No; body and guard rules apply
- Type
- number
- Details
- Size of location in meters. minimum:
0. maximum:90000000.
##### dns-records_MXRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- A valid mail server hostname. format:
hostname.
priority- Required
- No; body and guard rules apply
- Type
- dns-records_priority
- Details
- See the full input schema.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
MX.
##### dns-records_NAPTRRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted NAPTR content. See 'data' to set NAPTR properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a NAPTR record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
NAPTR.
##### dns-records_NAPTRRecord.allOf[1].data
flags- Required
- No; body and guard rules apply
- Type
- string
- Details
- Flags.
order- Required
- No; body and guard rules apply
- Type
- number
- Details
- Order. minimum:
0. maximum:65535.
preference- Required
- No; body and guard rules apply
- Type
- number
- Details
- Preference. minimum:
0. maximum:65535.
regex- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regex.
replacement- Required
- No; body and guard rules apply
- Type
- string
- Details
- Replacement.
service- Required
- No; body and guard rules apply
- Type
- string
- Details
- Service.
##### dns-records_NSRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- A valid name server host name.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
NS.
##### dns-records_OPENPGPKEYRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- A single Base64-encoded OpenPGP Transferable Public Key (RFC 4880 Section 11.1)
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
OPENPGPKEY.
##### dns-records_PTRRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Domain name pointing to the address.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
PTR.
##### dns-records_SMIMEARecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted SMIMEA content. See 'data' to set SMIMEA properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a SMIMEA record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
SMIMEA.
##### dns-records_SMIMEARecord.allOf[1].data
certificate- Required
- No; body and guard rules apply
- Type
- string
- Details
- Certificate.
matching_type- Required
- No; body and guard rules apply
- Type
- number
- Details
- Matching Type. minimum:
0. maximum:255.
selector- Required
- No; body and guard rules apply
- Type
- number
- Details
- Selector. minimum:
0. maximum:255.
usage- Required
- No; body and guard rules apply
- Type
- number
- Details
- Usage. minimum:
0. maximum:255.
##### dns-records_SRVRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Priority, weight, port, and SRV target. See 'data' for setting the individual component values.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a SRV record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
SRV.
##### dns-records_SRVRecord.allOf[1].data
port- Required
- No; body and guard rules apply
- Type
- number
- Details
- The port of the service. minimum:
0. maximum:65535.
priority- Required
- No; body and guard rules apply
- Type
- dns-records_priority
- Details
- See the full input schema.
target- Required
- No; body and guard rules apply
- Type
- string
- Details
- A valid hostname. format:
hostname.
weight- Required
- No; body and guard rules apply
- Type
- number
- Details
- The record weight. minimum:
0. maximum:65535.
##### dns-records_SSHFPRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted SSHFP content. See 'data' to set SSHFP properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a SSHFP record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
SSHFP.
##### dns-records_SSHFPRecord.allOf[1].data
algorithm- Required
- No; body and guard rules apply
- Type
- number
- Details
- Algorithm. minimum:
0. maximum:255.
fingerprint- Required
- No; body and guard rules apply
- Type
- string
- Details
- Fingerprint.
type- Required
- No; body and guard rules apply
- Type
- number
- Details
- Type. minimum:
0. maximum:255.
##### dns-records_SVCBRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted SVCB content. See 'data' to set SVCB properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a SVCB record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
SVCB.
##### dns-records_SVCBRecord.allOf[1].data
priority- Required
- No; body and guard rules apply
- Type
- number
- Details
- Priority. minimum:
0. maximum:65535.
target- Required
- No; body and guard rules apply
- Type
- string
- Details
- Target.
value- Required
- No; body and guard rules apply
- Type
- string
- Details
- Value.
##### dns-records_TLSARecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted TLSA content. See 'data' to set TLSA properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a TLSA record.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
TLSA.
##### dns-records_TLSARecord.allOf[1].data
certificate- Required
- No; body and guard rules apply
- Type
- string
- Details
- Certificate.
matching_type- Required
- No; body and guard rules apply
- Type
- number
- Details
- Matching Type. minimum:
0. maximum:255.
selector- Required
- No; body and guard rules apply
- Type
- number
- Details
- Selector. minimum:
0. maximum:255.
usage- Required
- No; body and guard rules apply
- Type
- number
- Details
- Usage. minimum:
0. maximum:255.
##### dns-records_TXTRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Text content for the record. The content must consist of quoted "character strings" (RFC 1035), each with a length of up to 255 bytes. Strings exceeding this allowed maximum length are automatically split. Learn more at .
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
TXT.
##### dns-records_URIRecord.allOf[1]
content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Formatted URI content. See 'data' to set URI properties.
data- Required
- No; body and guard rules apply
- Type
- object
- Details
- Components of a URI record.
priority- Required
- No; body and guard rules apply
- Type
- dns-records_priority
- Details
- See the full input schema.
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Record type. Values:
URI.
##### dns-records_URIRecord.allOf[1].data
target- Required
- No; body and guard rules apply
- Type
- string
- Details
- The record content.
weight- Required
- No; body and guard rules apply
- Type
- number
- Details
- The record weight. minimum:
0. maximum:65535.
##### dns-records_dns-record-shared-fields
comment- Required
- No; body and guard rules apply
- Type
- dns-records_comment
- Details
- See the full input schema.
name- Required
- No; body and guard rules apply
- Type
- dns-records_name
- Details
- See the full input schema.
proxied- Required
- No; body and guard rules apply
- Type
- dns-records_proxied
- Details
- See the full input schema.
settings- Required
- No; body and guard rules apply
- Type
- dns-records_settings
- Details
- See the full input schema.
tags- Required
- No; body and guard rules apply
- Type
- dns-records_tags
- Details
- See the full input schema.
ttl- Required
- No; body and guard rules apply
- Type
- dns-records_ttl
- Details
- See the full input schema.
##### dns-records_settings
ipv4_only- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- When enabled, only A records will be generated, and AAAA records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6. default:
False.
ipv6_only- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- When enabled, only AAAA records will be generated, and A records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6. default:
False.
##### dns-records_dns-record-batch-delete.allOf[0]
id- Required
- No; body and guard rules apply
- Type
- dns-records_identifier
- Details
- See the full input schema.
##### dns-records_dns-record-batch-patch
id- Required
- Yes
- Type
- dns-records_identifier
- Details
- See the full input schema.
##### dns-records_dns-record-batch-put
id- Required
- Yes
- Type
- dns-records_identifier
- Details
- See the full input schema.
##### cache-purge_Everything
purge_everything- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Set to
trueto target all cached content in the zone, or in the environment for the environment endpoints. Must be the only field in the request. See Purge everything.
##### cache-purge_FlexPurgeByHostnames
hosts- Required
- No; body and guard rules apply
- Type
- array
- Details
- Hostnames, such as
www.example.com. Targets all content cached for these hostnames. See Purge cache by hostname. Items: string.
##### cache-purge_FlexPurgeByPrefixes
prefixes- Required
- No; body and guard rules apply
- Type
- array
- Details
- URL prefixes, each a hostname followed by a path, such as
www.example.com/blog/. Targets all content whose URL starts with one of these prefixes. Do not include a scheme, query string, or fragment. See Purge cache by prefix. Items: string.
##### cache-purge_FlexPurgeByTags
tags- Required
- No; body and guard rules apply
- Type
- array
- Details
- Cache tags. Targets all content whose
Cache-Tagresponse header contains at least one of these tags. See Purge cache by cache-tags. Items: string.
##### cache-purge_SingleFile
files- Required
- No; body and guard rules apply
- Type
- array
- Details
- Full URLs, such as
https://www.example.com/css/styles.css. Targets the content cached for each URL. If your cache key includes request headers, send objects withurlandheadersinstead. See Purge by single-file. Items: string.
##### cache-purge_SingleFileWithUrlAndHeaders
files- Required
- No; body and guard rules apply
- Type
- array
- Details
- URLs with the request headers your cache key uses. Use this form when your cache key includes request headers, or the visitor's device type, country, or language: send the header values each URL was cached with, such as
CF-Device-Type,CF-IPCountry, orAccept-Language. When you send theOriginheader, include the scheme and hostname. Include the port unless it is the default for the scheme: 80 forhttp, 443 forhttps. See Purge by single-file. Items: object.
##### cache-purge_SingleFileWithUrlAndHeaders.files[]
headers- Required
- No; body and guard rules apply
- Type
- object
- Details
- Request headers and the values the content was cached with.
url- Required
- No; body and guard rules apply
- Type
- string
- Details
- Full URL of the content.
##### zones_automatic_platform_optimization
cache_by_device_type- Required
- Yes
- Type
- boolean
- Details
- Indicates whether or not cache by device type is enabled.
cf- Required
- Yes
- Type
- boolean
- Details
- Indicates whether or not Cloudflare proxy is enabled. default:
False.
enabled- Required
- Yes
- Type
- boolean
- Details
- Indicates whether or not Automatic Platform Optimization is enabled. default:
False.
hostnames- Required
- Yes
- Type
- array
- Details
- An array of hostnames where Automatic Platform Optimization for WordPress is activated. Items: string.
wordpress- Required
- Yes
- Type
- boolean
- Details
- Indicates whether or not site is powered by WordPress. default:
False.
wp_plugin- Required
- Yes
- Type
- boolean
- Details
- Indicates whether or not Cloudflare for WordPress plugin is installed. default:
False.
##### zones_cache-rules_aegis_value
enabled- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether the feature is enabled or not.
pool_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Egress pool id which refers to a grouping of dedicated egress IPs through which Cloudflare will connect to origin.
##### zones_nel_value
enabled- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- See the full input schema. default:
False.
##### zones_security_header_value
strict_transport_security- Required
- No; body and guard rules apply
- Type
- object
- Details
- Strict Transport Security.
##### zones_security_header_value.strict_transport_security
enabled- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether or not strict transport security is enabled.
include_subdomains- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Include all subdomains for strict transport security.
max_age- Required
- No; body and guard rules apply
- Type
- number
- Details
- Max age in seconds of the strict transport security.
nosniff- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether or not to include 'X-Content-Type-Options: nosniff' header.
preload- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Enable automatic preload of the HSTS configuration.
##### rulesets_BlockRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
block.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_BlockRule.allOf[1].action_parameters
response- Required
- No; body and guard rules apply
- Type
- object
- Details
- The response to show when the block is applied.
##### rulesets_BlockRule.allOf[1].action_parameters.response
content- Required
- Yes
- Type
- string
- Details
- The content to return. minLength:
1.
content_type- Required
- Yes
- Type
- string
- Details
- The type of the content to return. minLength:
1.
status_code- Required
- Yes
- Type
- integer
- Details
- The status code to return. minimum:
400. maximum:499.
##### rulesets_ChallengeRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
challenge.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_CompressResponseRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
compress_response.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_CompressResponseRule.allOf[1].action_parameters
algorithms- Required
- Yes
- Type
- array
- Details
- Custom order for compression algorithms. minItems:
1. Items: object.
##### rulesets_CompressResponseRule.allOf[1].action_parameters.algorithms[]
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Name of the compression algorithm to enable. Values:
none,auto,default,gzip,brotli,zstd.
##### rulesets_DDoSDynamicRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
ddos_dynamic.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_ExecuteCategoryOverrides[]
action- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- See the full input schema.
category- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
enabled- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- See the full input schema.
sensitivity_level- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- See the full input schema.
##### rulesets_ExecuteMatchedData
public_key- Required
- Yes
- Type
- string
- Details
- The public key to encrypt matched data logs with. minLength:
1.
##### rulesets_ExecuteOverrides
action- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- See the full input schema.
categories- Required
- No; body and guard rules apply
- Type
- rulesets_ExecuteCategoryOverrides
- Details
- See the full input schema.
enabled- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- See the full input schema.
rules- Required
- No; body and guard rules apply
- Type
- rulesets_ExecuteRuleOverrides
- Details
- See the full input schema.
sensitivity_level- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- See the full input schema.
##### rulesets_ExecuteRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
execute.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_ExecuteRule.allOf[1].action_parameters
id- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
matched_data- Required
- No; body and guard rules apply
- Type
- rulesets_ExecuteMatchedData
- Details
- See the full input schema.
overrides- Required
- No; body and guard rules apply
- Type
- rulesets_ExecuteOverrides
- Details
- See the full input schema.
##### rulesets_ExecuteRuleOverrides[]
action- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- See the full input schema.
enabled- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- See the full input schema.
id- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
score_threshold- Required
- No; body and guard rules apply
- Type
- integer
- Details
- The score threshold to use for the rule.
sensitivity_level- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- See the full input schema.
##### rulesets_ForceConnectionCloseRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
force_connection_close.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_JsChallengeRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
js_challenge.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_LogCustomFieldCookieFields[]
name- Required
- Yes
- Type
- string
- Details
- The name of the cookie. minLength:
1.
##### rulesets_LogCustomFieldRawResponseFields[]
name- Required
- Yes
- Type
- string
- Details
- The name of the response header. minLength:
1.
preserve_duplicates- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to log duplicate values of the same header. default:
False.
##### rulesets_LogCustomFieldRequestFields[]
name- Required
- Yes
- Type
- string
- Details
- The name of the header. minLength:
1.
##### rulesets_LogCustomFieldResponseFields[]
name- Required
- Yes
- Type
- string
- Details
- The name of the response header. minLength:
1.
preserve_duplicates- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to log duplicate values of the same header. default:
False.
##### rulesets_LogCustomFieldRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
log_custom_field.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_LogCustomFieldRule.allOf[1].action_parameters
cookie_fields- Required
- No; body and guard rules apply
- Type
- rulesets_LogCustomFieldCookieFields
- Details
- See the full input schema.
raw_response_fields- Required
- No; body and guard rules apply
- Type
- rulesets_LogCustomFieldRawResponseFields
- Details
- See the full input schema.
request_fields- Required
- No; body and guard rules apply
- Type
- rulesets_LogCustomFieldRequestFields
- Details
- See the full input schema.
response_fields- Required
- No; body and guard rules apply
- Type
- rulesets_LogCustomFieldResponseFields
- Details
- See the full input schema.
transformed_request_fields- Required
- No; body and guard rules apply
- Type
- rulesets_LogCustomFieldTransformedRequestFields
- Details
- See the full input schema.
##### rulesets_LogCustomFieldTransformedRequestFields[]
name- Required
- Yes
- Type
- string
- Details
- The name of the header. minLength:
1.
##### rulesets_LogRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
log.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_ManagedChallengeRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
managed_challenge.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_RedirectFromList
key- Required
- Yes
- Type
- string
- Details
- An expression that evaluates to the list lookup key. minLength:
1.
name- Required
- Yes
- Type
- string
- Details
- The name of the list to match against. pattern:
^[a-zA-Z0-9_]+$.
##### rulesets_RedirectFromValue
preserve_query_string- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to keep the query string of the original request. default:
False.
status_code- Required
- No; body and guard rules apply
- Type
- integer
- Details
- The status code to use for the redirect. Values:
301,302,303,307,308.
target_url- Required
- Yes
- Type
- object
- Details
- A URL to redirect the request to.
##### rulesets_RedirectFromValue.target_url
expression- Required
- No; body and guard rules apply
- Type
- string
- Details
- An expression that evaluates to a URL to redirect the request to. minLength:
1.
value- Required
- No; body and guard rules apply
- Type
- string
- Details
- A URL to redirect the request to. minLength:
1.
##### rulesets_RedirectRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
redirect.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_RedirectRule.allOf[1].action_parameters
from_list- Required
- No; body and guard rules apply
- Type
- rulesets_RedirectFromList
- Details
- See the full input schema.
from_value- Required
- No; body and guard rules apply
- Type
- rulesets_RedirectFromValue
- Details
- See the full input schema.
##### rulesets_RewriteRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
rewrite.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_RewriteRule.allOf[1].action_parameters
headers- Required
- No; body and guard rules apply
- Type
- rulesets_RewriteHeaders
- Details
- See the full input schema.
uri- Required
- No; body and guard rules apply
- Type
- rulesets_RewriteUri
- Details
- See the full input schema.
##### rulesets_RewriteUri.allOf[0].anyOf[0]
path- Required
- Yes
- Type
- rulesets_RewriteUriPath
- Details
- See the full input schema.
##### rulesets_RewriteUri.allOf[0].anyOf[1]
query- Required
- Yes
- Type
- rulesets_RewriteUriQuery
- Details
- See the full input schema.
##### rulesets_RewriteUri.allOf[1]
origin- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to propagate the rewritten URI to origin.
##### rulesets_RewriteUriPath
expression- Required
- No; body and guard rules apply
- Type
- string
- Details
- An expression that evaluates to a value to rewrite the URI path to. minLength:
1.
value- Required
- No; body and guard rules apply
- Type
- string
- Details
- A value to rewrite the URI path to. minLength:
1.
##### rulesets_RewriteUriQuery
expression- Required
- No; body and guard rules apply
- Type
- string
- Details
- An expression that evaluates to a value to rewrite the URI query to. minLength:
1.
value- Required
- No; body and guard rules apply
- Type
- string
- Details
- A value to rewrite the URI query to.
##### rulesets_RouteOrigin
host- Required
- No; body and guard rules apply
- Type
- string
- Details
- A resolved host to route to. minLength:
1.
port- Required
- No; body and guard rules apply
- Type
- integer
- Details
- A destination port to route to. minimum:
1. maximum:65535.
##### rulesets_RouteRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
route.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_RouteRule.allOf[1].action_parameters
host_header- Required
- No; body and guard rules apply
- Type
- rulesets_RouteHostHeader
- Details
- See the full input schema.
origin- Required
- No; body and guard rules apply
- Type
- rulesets_RouteOrigin
- Details
- See the full input schema.
sni- Required
- No; body and guard rules apply
- Type
- rulesets_RouteSNI
- Details
- See the full input schema.
##### rulesets_RouteSNI
value- Required
- Yes
- Type
- string
- Details
- A value to override the SNI to. minLength:
1.
##### rulesets_Rule
action- Required
- No; body and guard rules apply
- Type
- rulesets_RuleAction
- Details
- See the full input schema.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- The parameters configuring the rule's action. default:
{}.
categories- Required
- No; body and guard rules apply
- Type
- rulesets_RuleCategories
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- An informative description of the rule. default:
See current schema.
enabled- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- See the full input schema.
exposed_credential_check- Required
- No; body and guard rules apply
- Type
- rulesets_RuleExposedCredentialCheck
- Details
- See the full input schema.
expression- Required
- No; body and guard rules apply
- Type
- string
- Details
- The expression defining which traffic will match the rule. minLength:
1.
id- Required
- No; body and guard rules apply
- Type
- rulesets_RuleId
- Details
- See the full input schema.
last_updated- Required
- Yes
- Type
- string
- Details
- The timestamp of when the rule was last modified. format:
date-time.
logging- Required
- No; body and guard rules apply
- Type
- rulesets_RuleLogging
- Details
- See the full input schema.
ratelimit- Required
- No; body and guard rules apply
- Type
- rulesets_RuleRatelimit
- Details
- See the full input schema.
ref- Required
- No; body and guard rules apply
- Type
- string
- Details
- The reference of the rule (the rule's ID by default). minLength:
1.
version- Required
- Yes
- Type
- string
- Details
- The version of the rule. pattern:
^[0-9]+$.
##### rulesets_RuleExposedCredentialCheck
password_expression- Required
- Yes
- Type
- string
- Details
- An expression that selects the password used in the credentials check. minLength:
1.
username_expression- Required
- Yes
- Type
- string
- Details
- An expression that selects the user ID used in the credentials check. minLength:
1.
##### rulesets_RuleLogging
enabled- Required
- Yes
- Type
- boolean
- Details
- Whether to generate a log when the rule matches.
##### rulesets_RuleRatelimit
characteristics- Required
- Yes
- Type
- array
- Details
- Characteristics of the request on which the rate limit counter will be incremented. minItems:
1. Items: string.
counting_expression- Required
- No; body and guard rules apply
- Type
- string
- Details
- An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule's expression. minLength:
1.
mitigation_timeout- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Period of time in seconds after which the action will be disabled following its first execution.
period- Required
- Yes
- Type
- integer
- Details
- Period in seconds over which the counter is being incremented. minimum:
0.
requests_per_period- Required
- No; body and guard rules apply
- Type
- integer
- Details
- The threshold of requests per period after which the action will be executed for the first time. minimum:
1.
requests_to_origin- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether counting is only performed when an origin is reached. default:
False.
score_per_period- Required
- No; body and guard rules apply
- Type
- integer
- Details
- The score threshold per period for which the action will be executed the first time.
score_response_header_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- A response header name provided by the origin, which contains the score to increment rate limit counter with. minLength:
1.
##### rulesets_Ruleset
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- An informative description of the ruleset. default:
See current schema.
id- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
last_updated- Required
- Yes
- Type
- string
- Details
- The timestamp of when the ruleset was last modified. format:
date-time.
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- The human-readable name of the ruleset. minLength:
1.
version- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
##### rulesets_ScoreRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
score.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_ScoreRule.allOf[1].action_parameters
increment- Required
- Yes
- Type
- rulesets_ScoreIncrement
- Details
- See the full input schema.
##### rulesets_ServeErrorRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
serve_error.
action_parameters- Required
- No; body and guard rules apply
- Type
- JSON
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_ServeErrorRule.allOf[1].action_parameters.allOf[0]
content_type- Required
- Yes
- Type
- rulesets_ServeErrorContentType
- Details
- See the full input schema.
status_code- Required
- No; body and guard rules apply
- Type
- rulesets_ServeErrorStatusCode
- Details
- See the full input schema.
##### rulesets_ServeErrorRule.allOf[1].action_parameters.allOf[1].oneOf[0]
content- Required
- Yes
- Type
- rulesets_ServeErrorContent
- Details
- See the full input schema.
##### rulesets_ServeErrorRule.allOf[1].action_parameters.allOf[1].oneOf[1]
asset_name- Required
- Yes
- Type
- rulesets_ServeErrorAssetName
- Details
- See the full input schema.
##### rulesets_SetCacheControlDirective.oneOf[0]
cloudflare_only- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlCloudflareOnly
- Details
- See the full input schema.
operation- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
##### rulesets_SetCacheControlDirective.oneOf[1]
cloudflare_only- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlCloudflareOnly
- Details
- See the full input schema.
operation- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
##### rulesets_SetCacheControlDirectiveWithQualifiers.oneOf[0]
cloudflare_only- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlCloudflareOnly
- Details
- See the full input schema.
operation- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
qualifiers- Required
- No; body and guard rules apply
- Type
- array
- Details
- Optional list of header names to qualify the directive (e.g., for "private" or "no-cache" directives). Items: string.
##### rulesets_SetCacheControlDirectiveWithValue.oneOf[0]
cloudflare_only- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlCloudflareOnly
- Details
- See the full input schema.
operation- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
value- Required
- Yes
- Type
- integer
- Details
- The duration value in seconds for the directive. minimum:
0.
##### rulesets_SetCacheControlRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
set_cache_control.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_SetCacheControlRule.allOf[1].action_parameters
immutable- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirective
- Details
- See the full input schema.
max-age- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirectiveWithValue
- Details
- See the full input schema.
must-revalidate- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirective
- Details
- See the full input schema.
must-understand- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirective
- Details
- See the full input schema.
no-cache- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirectiveWithQualifiers
- Details
- See the full input schema.
no-store- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirective
- Details
- See the full input schema.
no-transform- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirective
- Details
- See the full input schema.
private- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirectiveWithQualifiers
- Details
- See the full input schema.
proxy-revalidate- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirective
- Details
- See the full input schema.
public- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirective
- Details
- See the full input schema.
s-maxage- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirectiveWithValue
- Details
- See the full input schema.
stale-if-error- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirectiveWithValue
- Details
- See the full input schema.
stale-while-revalidate- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheControlDirectiveWithValue
- Details
- See the full input schema.
##### rulesets_SetCacheSettingsBrowserTTL
default- Required
- No; body and guard rules apply
- Type
- integer
- Details
- The browser TTL (in seconds) if you choose the "override_origin" mode. minimum:
0.
mode- Required
- Yes
- Type
- string
- Details
- The browser TTL mode. Values:
respect_origin,bypass_by_default,override_origin,bypass.
##### rulesets_SetCacheSettingsCacheKey
cache_by_device_type- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to separate cached content based on the visitor's device type.
cache_deception_armor- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to protect from web cache deception attacks, while allowing static assets to be cached.
custom_key- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsCustomCacheKey
- Details
- See the full input schema.
ignore_query_strings_order- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to treat requests with the same query parameters the same, regardless of the order those query parameters are in.
##### rulesets_SetCacheSettingsCacheReserve
eligible- Required
- Yes
- Type
- boolean
- Details
- Whether Cache Reserve is enabled. If this is true and a request meets eligibility criteria, Cloudflare will write the resource to Cache Reserve.
minimum_file_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- The minimum file size eligible for storage in Cache Reserve. minimum:
0.
##### rulesets_SetCacheSettingsCustomCacheKey
cookie- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsCustomCacheKeyCookie
- Details
- See the full input schema.
header- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsCustomCacheKeyHeader
- Details
- See the full input schema.
host- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsCustomCacheKeyHost
- Details
- See the full input schema.
query_string- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsCustomCacheKeyQueryString
- Details
- See the full input schema.
user- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsCustomCacheKeyUser
- Details
- See the full input schema.
##### rulesets_SetCacheSettingsCustomCacheKeyCookie
check_presence- Required
- No; body and guard rules apply
- Type
- array
- Details
- A list of cookies to check for the presence of. The presence of these cookies is included in the cache key. minItems:
1. Items: string.
include- Required
- No; body and guard rules apply
- Type
- array
- Details
- A list of cookies to include in the cache key. minItems:
1. Items: string.
##### rulesets_SetCacheSettingsCustomCacheKeyHeader
check_presence- Required
- No; body and guard rules apply
- Type
- array
- Details
- A list of headers to check for the presence of. The presence of these headers is included in the cache key. minItems:
1. Items: string.
contains- Required
- No; body and guard rules apply
- Type
- object
- Details
- A mapping of header names to a list of values. If a header is present in the request and contains any of the values provided, its value is included in the cache key.
exclude_origin- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to exclude the origin header in the cache key.
include- Required
- No; body and guard rules apply
- Type
- array
- Details
- A list of headers to include in the cache key. minItems:
1. Items: string.
##### rulesets_SetCacheSettingsCustomCacheKeyHost
resolved- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to use the resolved host in the cache key.
##### rulesets_SetCacheSettingsCustomCacheKeyQueryString
exclude- Required
- No; body and guard rules apply
- Type
- object
- Details
- Which query string parameters to exclude from the cache key.
include- Required
- No; body and guard rules apply
- Type
- object
- Details
- Which query string parameters to include in the cache key.
##### rulesets_SetCacheSettingsCustomCacheKeyQueryString.exclude
all- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to exclude all query string parameters from the cache key. Values:
True.
list- Required
- No; body and guard rules apply
- Type
- array
- Details
- A list of query string parameters to exclude from the cache key. minItems:
1. Items: string.
##### rulesets_SetCacheSettingsCustomCacheKeyQueryString.include
all- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include all query string parameters in the cache key. Values:
True.
list- Required
- No; body and guard rules apply
- Type
- array
- Details
- A list of query string parameters to include in the cache key. minItems:
1. Items: string.
##### rulesets_SetCacheSettingsCustomCacheKeyUser
device_type- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to use the user agent's device type in the cache key.
geo- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to use the user agents's country in the cache key.
lang- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to use the user agent's language in the cache key.
##### rulesets_SetCacheSettingsEdgeTTL
default- Required
- No; body and guard rules apply
- Type
- integer
- Details
- The edge TTL (in seconds) if you choose the "override_origin" mode. minimum:
0.
mode- Required
- Yes
- Type
- string
- Details
- The edge TTL mode. Values:
respect_origin,bypass_by_default,override_origin.
status_code_ttl- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsStatusCodeTTL
- Details
- See the full input schema.
##### rulesets_SetCacheSettingsOriginRangeRequests
mode- Required
- Yes
- Type
- string
- Details
- Whether to use range requests.
defaultis the behaviour the zone gets without this rule. Values:on,off,default.
##### rulesets_SetCacheSettingsRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
set_cache_settings.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_SetCacheSettingsRule.allOf[1].action_parameters
additional_cacheable_ports- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsAdditionalCacheablePorts
- Details
- See the full input schema.
browser_ttl- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsBrowserTTL
- Details
- See the full input schema.
cache- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsCache
- Details
- See the full input schema.
cache_key- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsCacheKey
- Details
- See the full input schema.
cache_reserve- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsCacheReserve
- Details
- See the full input schema.
edge_ttl- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsEdgeTTL
- Details
- See the full input schema.
origin_cache_control- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsOriginCacheControl
- Details
- See the full input schema.
origin_error_page_passthru- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsOriginErrorPagePassthru
- Details
- See the full input schema.
origin_range_requests- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsOriginRangeRequests
- Details
- See the full input schema.
read_timeout- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsReadTimeout
- Details
- See the full input schema.
respect_strong_etags- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsRespectStrongEtags
- Details
- See the full input schema.
serve_stale- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsServeStale
- Details
- See the full input schema.
shared_dictionary- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsSharedDictionary
- Details
- See the full input schema.
strip_etags- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsStripETags
- Details
- See the full input schema.
strip_last_modified- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsStripLastModified
- Details
- See the full input schema.
strip_set_cookie- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsStripSetCookie
- Details
- See the full input schema.
vary- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsVary
- Details
- See the full input schema.
##### rulesets_SetCacheSettingsServeStale
disable_stale_while_updating- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether Cloudflare should disable serving stale content while getting the latest content from the origin.
##### rulesets_SetCacheSettingsSharedDictionary
match_pattern- Required
- Yes
- Type
- string
- Details
- URL pattern for the Use-As-Dictionary match field. This pattern specifies which URLs can use this response as a dictionary. minLength:
1. maxLength:1024.
##### rulesets_SetCacheSettingsStatusCodeTTL[]
status_code- Required
- No; body and guard rules apply
- Type
- integer
- Details
- A single status code to apply the TTL to. minimum:
100. maximum:999.
status_code_range- Required
- No; body and guard rules apply
- Type
- object
- Details
- A range of status codes to apply the TTL to.
value- Required
- Yes
- Type
- integer
- Details
- The time to cache the response for (in seconds). A value of 0 is equivalent to setting the cache control header with the value "no-cache". A value of -1 is equivalent to setting the cache control header with the value of "no-store".
##### rulesets_SetCacheSettingsStatusCodeTTL[].status_code_range
from- Required
- No; body and guard rules apply
- Type
- integer
- Details
- The lower bound of the range. minimum:
100. maximum:999.
to- Required
- No; body and guard rules apply
- Type
- integer
- Details
- The upper bound of the range. minimum:
100. maximum:999.
##### rulesets_SetCacheSettingsVary
default- Required
- No; body and guard rules apply
- Type
- rulesets_SetCacheSettingsVaryDefault
- Details
- See the full input schema.
headers- Required
- No; body and guard rules apply
- Type
- object
- Details
- A mapping of lowercase request header names to their vary configuration.
##### rulesets_SetCacheSettingsVaryDefault
action- Required
- Yes
- Type
- string
- Details
- How the header value is treated when building the cache key. Values:
bypass,passthrough,normalize.
##### rulesets_SetCacheSettingsVaryHeader
action- Required
- Yes
- Type
- string
- Details
- How the header value is treated when building the cache key. Values:
bypass,passthrough,normalize.
languages- Required
- No; body and guard rules apply
- Type
- array
- Details
- The set of languages to normalize against. Only valid for the
accept-languageheader. maxItems:20. Items: string.
media_types- Required
- No; body and guard rules apply
- Type
- array
- Details
- The set of media types to normalize against. Only valid for the
acceptheader. maxItems:10. Items: string.
##### rulesets_SetCacheTagsRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
set_cache_tags.
action_parameters- Required
- No; body and guard rules apply
- Type
- Union
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[0]
operation- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
values- Required
- Yes
- Type
- rulesets_SetCacheTagsValues
- Details
- See the full input schema.
##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[1]
expression- Required
- Yes
- Type
- rulesets_SetCacheTagsExpression
- Details
- See the full input schema.
operation- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[2]
operation- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
values- Required
- Yes
- Type
- rulesets_SetCacheTagsValues
- Details
- See the full input schema.
##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[3]
expression- Required
- Yes
- Type
- rulesets_SetCacheTagsExpression
- Details
- See the full input schema.
operation- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[4]
operation- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
values- Required
- Yes
- Type
- rulesets_SetCacheTagsValues
- Details
- See the full input schema.
##### rulesets_SetCacheTagsRule.allOf[1].action_parameters.oneOf[5]
expression- Required
- Yes
- Type
- rulesets_SetCacheTagsExpression
- Details
- See the full input schema.
operation- Required
- Yes
- Type
- JSON
- Details
- See the full input schema.
##### rulesets_SetConfigAutominify
css- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to minify CSS files. default:
False.
html- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to minify HTML files. default:
False.
js- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to minify JavaScript files. default:
False.
##### rulesets_SetConfigRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
set_config.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_SetConfigRule.allOf[1].action_parameters
automatic_https_rewrites- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to enable Automatic HTTPS Rewrites.
autominify- Required
- No; body and guard rules apply
- Type
- rulesets_SetConfigAutominify
- Details
- See the full input schema.
bic- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to enable Browser Integrity Check (BIC).
content_converter- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to enable content conversion (e.g., HTML to Markdown).
disable_apps- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to disable Cloudflare Apps. Values:
True.
disable_pay_per_crawl- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to disable Pay Per Crawl. Values:
True.
disable_rum- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to disable Real User Monitoring (RUM). Values:
True.
disable_zaraz- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to disable Zaraz. Values:
True.
email_obfuscation- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to enable Email Obfuscation.
fonts- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to enable Cloudflare Fonts.
hotlink_protection- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to enable Hotlink Protection.
mirage- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to enable Mirage.
opportunistic_encryption- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to enable Opportunistic Encryption.
polish- Required
- No; body and guard rules apply
- Type
- string
- Details
- The Polish level to configure. Values:
off,lossless,lossy,webp.
redirects_for_ai_training- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to redirect verified AI training crawlers to canonical URLs found in the HTML response.
request_body_buffering- Required
- No; body and guard rules apply
- Type
- string
- Details
- The request body buffering mode. Values:
none,standard,full.
response_body_buffering- Required
- No; body and guard rules apply
- Type
- string
- Details
- The response body buffering mode. Values:
none,standard.
rocket_loader- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to enable Rocket Loader.
security_level- Required
- No; body and guard rules apply
- Type
- string
- Details
- The Security Level to configure. Values:
off,essentially_off,low,medium,high,under_attack.
server_side_excludes- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to enable Server-Side Excludes.
ssl- Required
- No; body and guard rules apply
- Type
- string
- Details
- The SSL level to configure. Values:
off,flexible,full,strict,origin_pull.
sxg- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to enable Signed Exchanges (SXG).
webmcp_enabled- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to serve the WebMCP bridge script, which exposes the page's tools to browser AI agents.
webmcp_packs- Required
- No; body and guard rules apply
- Type
- array
- Details
- Bundled WebMCP tool packs to activate for matching requests. An empty array disables all packs. Omitting this parameter leaves the pack selection unchanged. Does not enable the WebMCP bridge itself. Non-empty selections require the WebMCP Configuration Rules entitlement. maxItems:
100. Items: string.
##### rulesets_SkipRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
skip.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_SkipRule.allOf[1].action_parameters
phase- Required
- No; body and guard rules apply
- Type
- rulesets_SkipPhase
- Details
- See the full input schema.
phases- Required
- No; body and guard rules apply
- Type
- rulesets_SkipPhases
- Details
- See the full input schema.
products- Required
- No; body and guard rules apply
- Type
- rulesets_SkipProducts
- Details
- See the full input schema.
rules- Required
- No; body and guard rules apply
- Type
- rulesets_SkipRules
- Details
- See the full input schema.
ruleset- Required
- No; body and guard rules apply
- Type
- rulesets_SkipRuleset
- Details
- See the full input schema.
rulesets- Required
- No; body and guard rules apply
- Type
- rulesets_SkipRulesets
- Details
- See the full input schema.
##### rulesets_TransformResponseHTMLRule.allOf[1]
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
transform_response_html.
action_parameters- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
description- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema.
##### rulesets_TransformResponseHTMLRule.allOf[1].action_parameters
link_maze- Required
- Yes
- Type
- object
- Details
- Enables the link maze transformation on the response.
Complete client, OS and desktop setup
Codex
Codex is the current validation priority. Private token paths must exist in the process or remote environment where the server runs.
codex mcp add cloudflare -- npx -y @thenavidm/cloudflare-mcp-cli@latest
codex mcp listAccount credentials must reach the server through private environment settings. codex mcp add --env NAME=value stores values in your local config, so never commit that config or put secrets in a shared command. In TOML, the equivalent server is:
[mcp_servers.cloudflare]
command = "npx"
args = ["-y", "@thenavidm/cloudflare-mcp-cli@latest"]
env_vars = ["CLOUDFLARE_API_TOKEN", "CLOUDFLARE_TOKEN_FILE", "CLOUDFLARE_ACCOUNTS", "CLOUDFLARE_DEFAULT_ACCOUNT", "CLOUDFLARE_ZONE_ID", "CLOUDFLARE_ACCOUNT_ID", "CLOUDFLARE_TOKEN_KIND", "CLOUDFLARE_READ_ONLY", "CLOUDFLARE_ALLOW_DESTRUCTIVE"]env_vars forwards those names from the environment available to Codex. If that environment does not contain them, configure private env settings locally. Codex can also call the CLI directly with SKILL.md and --agent output.
Claude Code
For a user-scoped connection, after privately configuring credentials:
claude mcp add --scope user cloudflare -- npx -y @thenavidm/cloudflare-mcp-cli@latest
claude mcp listUse the client's private local environment settings for the account variable if they are not inherited. Claude's -e NAME=value registration option writes values into its config; only use it locally through your secret manager, with no shared command transcript. Never place credentials in a project .mcp.json. Reconnect and ask Claude to verify credentials.
Alternatively install the CLI, make SKILL.md available to Claude, and use shell commands. Registering both surfaces is optional.
Claude Desktop
Install the .mcpb extension
- Download
cloudflare-2.0.0.mcpbfrom GitHub Releases. - In a supported Claude Desktop build, open Settings > Extensions > Advanced settings > Install Extension… and select it.
- Enter a private API token in the sensitive setting, or an absolute private token-file path. Leave the unused credential method empty. Requests use Authorization: Bearer at the fixed Cloudflare endpoint. Configure optional account/zone defaults and user/account token kind privately; defaults do not narrow provider permissions.
- Enable read-only if you want only the 18 read operations. Reconnect and ask for account verification.
The bundle includes production dependencies and no credentials. Use a regular private token-only file if you prefer file-based credentials. The manifest requires Node 22 or newer from a compatible host. Organization policy may restrict custom extensions. Manual bundle updates require installing the new version; no automatic directory updates are promised. GUI installation remains unverified separately from archive/protocol checks.
Manual config
Open Settings > Developer > Edit Config, or use your platform's config file:
| OS | Typical config path |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json |
| Linux | ~/.config/Claude/claude_desktop_config.json; confirm the location through Edit Config in your installed build |
{
"mcpServers": {
"cloudflare": {
"command": "npx",
"args": ["-y", "@thenavidm/cloudflare-mcp-cli@latest"],
"env": {
"CLOUDFLARE_API_TOKEN": "YOUR_PRIVATE_API_TOKEN",
"CLOUDFLARE_TOKEN_FILE": "",
"CLOUDFLARE_ZONE_ID": "YOUR_ZONE_ID",
"CLOUDFLARE_ACCOUNT_ID": "YOUR_ACCOUNT_ID",
"CLOUDFLARE_TOKEN_KIND": "user"}
}
}
}Replace the placeholders only in your private file. Merge the server entry into an existing mcpServers object instead of replacing other integrations. Fully quit and reopen Claude Desktop. Do not enable an extension and a manual entry with the same name; choose one route.
If a Windows launcher cannot execute npx directly, use "command": "cmd" with "args": ["/c", "npx", "-y", "@thenavidm/cloudflare-mcp-cli@latest"]. An absolute node executable and installed dist/index.js path also avoids launcher/PATH problems.
Cursor
Use private user settings at ~/.cursor/mcp.json, or Settings > Tools & MCP. Cursor documents environment interpolation and envFile support.
{
"mcpServers": {
"cloudflare": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@thenavidm/cloudflare-mcp-cli@latest"],
"env": {
"CLOUDFLARE_API_TOKEN": "${env:CLOUDFLARE_API_TOKEN}",
"CLOUDFLARE_TOKEN_FILE": "${env:CLOUDFLARE_TOKEN_FILE}",
"CLOUDFLARE_ZONE_ID": "${env:CLOUDFLARE_ZONE_ID}"}
}
}
}The environment values must exist for the Cursor process. If you use envFile, keep that file private and outside version control. A project's .cursor/mcp.json must not contain actual credentials. Reconnect the server after saving.
VS Code and Copilot
Use MCP: Open User Configuration. VS Code uses servers and secure inputs, rather than a mcpServers root:
{
"inputs": [
{"type": "promptString", "id": "cloudflare-api-token", "description": "Cloudflare API token (leave empty for a private token file)", "password": true},
{"type": "promptString", "id": "cloudflare-token-file", "description": "Optional private token-file path (leave empty for API token)"},
{"type": "promptString", "id": "cloudflare-zone-id", "description": "Optional Cloudflare zone input default"}],
"servers": {
"cloudflare": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@thenavidm/cloudflare-mcp-cli@latest"],
"env": {
"CLOUDFLARE_API_TOKEN": "${input:cloudflare-api-token}",
"CLOUDFLARE_TOKEN_FILE": "${input:cloudflare-token-file}",
"CLOUDFLARE_ZONE_ID": "${input:cloudflare-zone-id}"}
}
}
}Start Cloudflare through the MCP controls, approve trust if prompted, and enter credentials in the private input prompts. Workspace .vscode/mcp.json may contain this placeholder-only structure, but never resolved secret values. Remote development runs the server in the selected remote environment, so local file paths refer to that environment.
Windsurf
Open Cascade's MCP settings or edit the private user file ~/.codeium/windsurf/mcp_config.json. Use the Claude Desktop manual mcpServers block above with your locally configured env values. See Windsurf's current MCP documentation. Restart or reconnect Cloudflare in Cascade; project files must not contain secrets.
Zed
Open Settings > AI > MCP Servers > Add Server > Add Local Server, or your user settings file. Zed uses context_servers:
{
"context_servers": {
"cloudflare": {
"command": "npx",
"args": ["-y", "@thenavidm/cloudflare-mcp-cli@latest"],
"env": {
"CLOUDFLARE_API_TOKEN": "YOUR_PRIVATE_API_TOKEN",
"CLOUDFLARE_TOKEN_FILE": "",
"CLOUDFLARE_ZONE_ID": "YOUR_ZONE_ID",
"CLOUDFLARE_ACCOUNT_ID": "YOUR_ACCOUNT_ID",
"CLOUDFLARE_TOKEN_KIND": "user"}
}
}
}Enter actual values only in private user settings. Check the active-server indicator before prompting. Do not wrap command and args inside a nested command object from older Zed examples.
Gemini CLI
Merge the Claude Desktop manual mcpServers block into your private ~/.gemini/settings.json. Configure the private credential values locally, then restart Gemini CLI and inspect /mcp. See Gemini CLI's MCP configuration. Its project settings must not contain real credentials. You can instead use the CLI from an agent shell.
Other local stdio clients use the same command and arguments, adapted to their config format. A client that only accepts a remote MCP URL cannot connect directly: this package does not ship a public HTTP listener. ChatGPT's remote connector setup is not a substitute for local stdio installation.
Docker
Build locally from the reviewed source; no prebuilt registry image is claimed:
git clone https://github.com/thenavidm/cloudflare-mcp-cli.git
cd cloudflare-mcp-cli
docker build -t cloudflare-mcp-cli .
docker run --rm -i -e CLOUDFLARE_API_TOKEN cloudflare-mcp-cliCline and other local MCP clients
Use the client's Add MCP server flow with command npx, arguments -y and @thenavidm/cloudflare-mcp-cli@latest, stdio transport, and private local CLOUDFLARE_API_TOKEN or CLOUDFLARE_TOKEN_FILE settings. UI names depend on the installed client. Reconnect and discover tools before an account call. Browser-only clients need a remote HTTPS connector; use Cloudflare's official server rather than this local stdio command.
Output, flags and exit codes
The house CLI derives tool flags from the same input schemas used by MCP. Tool names use underscores in MCP and hyphens in the shell. Native path/query arguments are top-level flags; current native request bodies use --payload JSON or --payload-file PATH, never both. --select filters returned data locally; it does not change Cloudflare's upstream fields or quota.
| Flag / command | Contract |
|---|---|
| tools / no command | Discover every command; confirmed mutations are marked |
| COMMAND --help | Actual tool schema arguments |
| schema COMMAND | Complete JSON input schema, including native payload unions/references |
| --agent | --json --compact --no-input --no-color --yes; never implies --confirm |
| --json / --compact | Machine JSON, optionally compact |
| --select a,b.c | Local dotted result selection |
| --payload / --payload-file | Native JSON body / private regular JSON file |
| --account NAME | Exact private profile label |
| --confirm | Explicit intent for the selected mutation only |
| --no-input / --no-color / --yes | Noninteractive formatting/prompt policy; no mutation permission |
| Exit | Meaning |
|---|---|
| 0 | Success |
| 2 | Invalid input or refused mutation |
| 3 | Not found |
| 4 | Authentication/permission error |
| 5 | Provider or transport failure |
| 7 | Rate limited |
| 10 | No credentials configured |
Provider REST results retain success/result/result_info envelopes; query-only analytics retains data. HTTP 200 with provider errors fails. JSON output is not proof that DNS has propagated or every downstream service accepted a setting.
Official and pinned community comparisons
- Current surface
- https://mcp.cloudflare.com/mcp; current pinned README lists docs/search/execute
- Verified strengths and limits
- OAuth or user/account token access, sandboxed code execution across the wider API, provider-maintained documentation search and configurable truncation. Individual endpoint tools are optional. Client approval and token permission boundaries remain relevant.
- Current surface
- cf 1.0.0-beta.12; Cloudflare documents more than 2900 commands
- Verified strengths and limits
- General account API coverage, command search, schemas, JSON, dry-run, named profiles, OAuth refresh, resource name resolution and local developer resources. Delete confirmation already exists.
- Current surface
- 4.147.0 at this review
- Verified strengths and limits
- Workers development/deployment and related project workflows. This focused package does not replace the developer toolchain.
- Current surface
- Provider-hosted service-specific MCP endpoints
- Verified strengths and limits
- Specialized analytics, builds, browser rendering and other products; current /mcp endpoints use Streamable HTTP. These are distinct from a local stdio DNS task wrapper.
- Current surface
- Community MIT source 1.0.0; 11 documented tools; stdio/HTTP
- Verified strengths and limits
- DNS convenience, BIND export, edit snapshots, guarded raw passthrough and optional Worker deployment/secrets. Delete/passthrough confirmation is already present. No dedicated task CLI is declared in the pinned package.
- Current surface
- 29 shared local MCP tools / CLI commands; versioned desktop bundle
- Verified strengths and limits
- 18 reads and 11 mandatory-confirmation mutations, isolated private profiles, complete selected native schemas, local previews, bounded page reads, reviewed DNS digest and no automatic replay. Narrower coverage than the official general API tools.
Checked October 3, 2026. Official MCP source: cloudflare/mcp commit 69ba3143bb8ffa2b3c1f12bfb7536c9ca4c57a2d. Selected API schema: cloudflare/api-schemas commit 37e7a4ae9c5123a2c58929a100c42cb4584edc57, API info 4.0.0. Community source is pinned above; its extra workflows are useful and are not claimed here.
The actual public cf@1.0.0-beta.12 package installed cleanly. Its complete binary passed version, command search, DNS-create schema and DNS-create dry-run checks with inherited provider credentials removed, telemetry disabled and fetch blocked. Its published DNS-create handler plus run wrapper were separately exercised in an isolated function fixture: a valid create without a confirmation flag reached an injected network-free SDK request once; dry-run reached it zero times. That fixture is not an authenticated Cloudflare operation or a whole-client approval test. Our equivalent shared handler refuses before fetch without explicit confirmation, including direct MCP calls.
Official cf already confirms deletes and has useful dry-run/profile features. Code Mode isolates credential injection from generated code; do not describe it as handing account tokens to the model. Reviewed official retry code can replay requests on transient/429 failures; this wrapper does not replay any request automatically. Confirmation is the caller asserting approved intent, not a cryptographic proof of a human approval or provider authorization.
The owned use case is a focused, repeatable DNS/zone task with consistent approval across CLI and MCP and an exact-request batch review. Choose official cf/Code Mode for broader API work and Wrangler for deployments. SEO, more tool names and metadata size do not establish better tasks or lower token cost. Live provider outcomes, GUI installation and actual matched Codex usage remain separately unverified.
Legacy command migration
- Current route
- Same names
- Migration detail
- Current native arguments/envelopes; use exact filters
- Current route
- Same names
- Migration detail
- Complete native payload schemas; every mutation confirmed
- Current route
- Same name
- Migration detail
- Native body and explicit approval
- Current route
- get_zone_setting/update_zone_setting
- Migration detail
- setting_id=ssl and current value schema
- Current route
- Per-setting read/update
- Migration detail
- Deprecated bulk settings route excluded
- Current route
- analytics_query
- Migration detail
- Read-only current GraphQL dataset query, not deprecated REST dashboard
- Current route
- list_zone_rulesets / get_zone_ruleset
- Migration detail
- Current Rulesets product; no deprecated firewall writer
- Current route
- Explicit selected Ruleset workflow
- Migration detail
- Legacy helper created Page Rules; modern redirect phase/action must be reviewed
- Current route
- Read-only Page Rules inventory
- Migration detail
- No legacy Page Rule writer
- Current route
- Same name
- Migration detail
- Worker script metadata only, no deployment
Private legacy source is retained separately and never pushed into clean public history. The old source has 17 MCP tools and no declared task CLI. This release changes input/response/config contracts, so migration is deliberate rather than an unverified drop-in compatibility promise.
Versions and migration
| Component | Reviewed version / source |
|---|---|
| Owned package / desktop | 2.0.0 |
| Legacy source package | 1.0.0; private source b6fef82d992cefbfb4ea9a9ea49e17275609c34e |
| Cloudflare REST API schema | API info 4.0.0; commit 37e7a4ae9c5123a2c58929a100c42cb4584edc57 |
| Official cf / Wrangler | 1.0.0-beta.12 / 4.147.0 at review |
| @modelcontextprotocol/sdk | 1.32.0 |
| ajv | 8.20.0 |
| ajv-formats | 3.0.1 |
| graphql | 16.14.2 |
| typescript | 7.0.2 |
| vitest | 5.0.3 |
| vite | 8.3.2 |
| @anthropic-ai/mcpb | 2.1.2 |
See CHANGELOG.md for dated changes and GitHub Releases for annotated source tags and versioned desktop assets. Match npm, server, manifest and root lock versions. Future schema refreshes must record upstream commit/checksums, exclusions, changed inputs and comparison evidence; do not assume a provider beta stays the same. No prior public legacy npm/tag release is implied.
Updates and removal
npm install -g @thenavidm/cloudflare-mcp-cli@latest
cloudflare-cli --version
npm uninstall -g @thenavidm/cloudflare-mcp-cli
codex mcp remove cloudflarenpx @latest resolves again when the server starts; restart/reconnect to use the release. Global npm installs need an explicit update. Desktop extensions need the new versioned archive installed separately. Check CHANGELOG.md and the manifest; remove duplicate MCP entries rather than running two account servers accidentally.
Remove client configuration/skill references and deliberately manage private files. Uninstall does not revoke tokens or undo DNS, Rulesets/cache changes. Existing private legacy refs stay private; migrate configuration/commands deliberately using the map below. Pin 2.0.0 if reproducible installation matters more than automatically receiving the latest release.
Validation and remaining evidence
Forty-four behavior/shared-CLI tests, typecheck/build and actual credential-free stdio discovery pass: 29 tools, 18 reads and eleven confirmed mutations. The reviewed source schema and distributed metadata have recorded checksums. Schema maintenance checks local JSON without network or source-code execution. The actual public official cf binary passed discovery/schema/dry-run; its mutation comparison is a network-free published-handler fixture, not an authenticated provider operation.
Public source CI, clean npm install and downloaded desktop discovery are release gates, recorded separately in the maintained release proof. Runtime audit has zero findings. Private legacy history is retained separately; public source/npm/desktop artifacts are scanned for secrets. Provider account outcomes, desktop GUI installation, fresh matched Codex task/token usage and the private site scene/helper deployment batch remain pending. Neither surface needs Claude Code; its benchmarks are deferred.
More tools for your site workflow
Connect the tools needed for the exact work you want to do.
Cloudflare MCP Server & CLI FAQs
Official cf/Code Mode, scoped tokens, profiles, DNS review, Rulesets, analytics, desktop setup and safeguards.
A focused shared Cloudflare CLI/local MCP and desktop archive, with 29 tools: 18 reads and 11 explicitly confirmed mutations.
Its selected DNS/zone management surface is narrower than the official general API tools.
Yes.
Code Mode MCP, specialized provider MCPs, the general cf CLI and Wrangler already exist.
The comparison documents their strengths and our specific recurring workflow rather than claiming they are missing.
For consistent mandatory confirmation in both local surfaces, isolated private profiles and an exact-request DNS batch review.
These are tested local workflow differences; no universal superiority or measured token winner is claimed.
Yes: register the npx @latest stdio command, forward private environment settings, or use cloudflare-cli with SKILL.md.
Discovery works without provider authentication; account operations need the intended token grant.
A versioned .mcpb vendors production dependencies and exposes private token/file/default/policy settings.
Manual stdio is also documented.
A protocol handshake is not a verified desktop GUI installation.
The house setup covers Node 22+ on macOS, Windows and Linux and local stdio clients including Codex, Claude, Cursor, VS Code, Windsurf, Zed, Gemini CLI and Cline.
Client runtime, policy and launchers still matter; remote-only clients use official hosted MCP.
No.
This Bearer-only wrapper expects a least-privilege API token.
Restrict its Cloudflare permissions/resources; local profile defaults do not narrow upstream grants.
Yes when the intended endpoints support that token type.
Set token_kind=account and an account ID for doctor verification.
Token kind changes only the diagnostic route; provider compatibility and permissions remain authoritative.
No. login prints private token instructions.
The package neither opens consent nor reads/renews official cf OAuth sessions or global CLI configuration.
Set CLOUDFLARE_READ_ONLY=1 and reconnect.
Eleven mutations disappear and direct calls still refuse.
CLOUDFLARE_ALLOW_DESTRUCTIVE=0 additionally refuses confirmed mutations.
No.
Every mutation needs --confirm or confirm:true for the actual requested operation.
The client/human still determine that it was approved; this flag is not a signed human consent.
The exact method, zone path, profile label and canonical native JSON body, preserving array order.
Any change requires a new local preview.
It does not bind remote state or a token grant and does not prevent concurrent edits.
The review/apply helper does.
Direct native batch_dns_records also exists, requires explicit confirmation and follows the native schema/provider limits, but does not require a digest.
No.
Cloudflare executes the request in a database transaction but distributed propagation is not atomic.
Inspect affected records after an unknown outcome and do not automatically repeat submissions.
No.
Ordinary commands fetch one response. query_pages supports three named reads with a one-to-five-page budget and explicit continuation/unknown reporting.
No request retries automatically.
Wait for current upstream reset policy, inspect possible mutation state and deliberately repeat only if appropriate.
No. list_workers is metadata only.
Use official cf, Code Mode or Wrangler for broader/deployment tasks.
There is no unrestricted raw request tool here.
One parsed GraphQL query at a time, with variables and provider-controlled dataset permissions, retention, sampling and limits.
It refuses mutations and partial-error responses; it is not an automatic analytics export.
That requires identical successful tasks and actual client/model usage.
No fresh matched Codex token result is published; character estimates, schema counts and borrowed metrics are not evidence.
Restart npx @latest, explicitly update global npm installs and reinstall new desktop archives separately.
Remove client entries and revoke the intended token through Cloudflare.
Uninstall does not undo provider changes.
Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.
More MCP servers & CLIs
Related free tools
Free AI newsletterThe most actionable AI newsletter for founders
Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.
No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.
P.S. Sign up now to get free access to my ultimate AI tools guide for creators.













