Skip to main content
Tools Reference

Cloudflare Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Cloudflare Tools

cf_ · 3453 tools · Free 1757 · Pro 1696The whole documented Cloudflare API across the accounts and zones one credential can see: DNS, R2, Workers and Pages, Zero Trust Access and Gateway, WAF and zone settings, Magic WAN, load balancing, certificates, email, Stream and Images, Radar and Cloudforce One. The credential is a scoped API token sent as a bearer against one fixed host, with no grant, no refresh and no renewal call; the legacy Global API Key pair is deliberately not offered. The token's own permission list and account/zone resource list are the real boundary, so a 403 usually means it is short one permission or one zone rather than broken, and the errors array says which. Every response is the vendor envelope {success, errors, messages, result, result_info}, passed through whole; a 200 saying success:false is a failure. Pagination has no single model. A few endpoints answer a file and return a short-lived link instead. The rate budget is the sharp edge: 1,200 requests per five minutes counted per USER.

All connector tools · Cloudflare setup guide

Cloudflare tool groups

MCP Analytics

ToolPlanAccessSummary
cf_get_mcp_portal_tool_callsFreeRead-onlyPer-portal MCP tool-call timeseries.
cf_get_mcp_server_tool_callsFreeRead-onlyPer-server MCP tool-call timeseries.
cf_get_mcp_tool_call_timeseriesFreeRead-onlyAccount-global MCP tool-call timeseries.

[Cloudflare] Per-portal MCP tool-call timeseries. GET /accounts//access/ai-controls/mcp/analytics/portals//tool-calls/timeseries. Path parameters: account_id, portal_id. Optional filters: granularity, aggregate, tz, days. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
aggregatestringnonullOptional. How the series values are aggregated.
daysintegernonullOptional. Daily trailing-window size; defaults to 7 and is ignored for monthly.
granularitystringnonullOptional. The time bucket for the series, for example hourly or daily.
portalIdstringyesRequired. The MCP Portal id, as returned by cf_list_mcp_portals.
tzstringnonullOptional. The IANA timezone the series is bucketed in, for example America/New_York.

[Cloudflare] Per-server MCP tool-call timeseries. GET /accounts//access/ai-controls/mcp/analytics/servers//tool-calls/timeseries. Path parameters: account_id, server_id. Optional filters: granularity, aggregate, tz, days. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
aggregatestringnonullOptional. How the series values are aggregated.
daysintegernonullOptional. Daily trailing-window size; defaults to 7 and is ignored for monthly.
granularitystringnonullOptional. The time bucket for the series, for example hourly or daily.
serverIdstringyesRequired. The MCP Server id, as returned by cf_list_mcp_servers.
tzstringnonullOptional. The IANA timezone the series is bucketed in, for example America/New_York.

[Cloudflare] Account-global MCP tool-call timeseries. Account-wide MCP tool-call volume over time — the read that answers whether anyone is actually using the portals, and when. GET /accounts//access/ai-controls/mcp/analytics/tool-calls/timeseries. Path parameters: account_id. Optional filters: granularity, aggregate, tz, days. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
aggregatestringnonullOptional. How the series values are aggregated.
daysintegernonullOptional. Daily trailing-window size; defaults to 7 and is ignored for monthly.
granularitystringnonullOptional. The time bucket for the series, for example hourly or daily.
tzstringnonullOptional. The IANA timezone the series is bucketed in, for example America/New_York.

MCP Portals

ToolPlanAccessSummary
cf_create_mcp_portalProWriteCreate a new MCP Portal.
cf_delete_mcp_portalProDestructiveDESTRUCTIVE: Delete an MCP Portal.
cf_get_mcp_portalFreeRead-onlyRead details of an MCP Portal.
cf_get_mcp_server_redirect_uriFreeRead-onlyResolve an MCP server OAuth redirect URI.
cf_list_mcp_portalsFreeRead-onlyList MCP Portals.
cf_update_mcp_portalProDestructiveDESTRUCTIVE: Update an MCP Portal.

[Cloudflare] Create a new MCP Portal. Additive: creates a new portal and changes no existing one. POST /accounts//access/ai-controls/mcp/portals. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: allow_code_mode, code_mode, description, hostname, id, name, secure_web_gateway, servers. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare documents these fields: allow_code_mode, code_mode, description, hostname, id, name, secure_web_gateway, servers.

[Cloudflare] DESTRUCTIVE: Delete an MCP Portal. Why this is destructive: Deletes the portal; every client pointed at its URL stops resolving. DELETE /accounts//access/ai-controls/mcp/portals/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. Unique identifier for the MCP portal.

[Cloudflare] Read details of an MCP Portal. Returns the portal with its bound servers and its hostname. Read it before an update: the update replaces the portal wholesale, so this is where you get the current binding list to send back. GET /accounts//access/ai-controls/mcp/portals/. Path parameters: id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. Unique identifier for the MCP portal.

[Cloudflare] Resolve an MCP server OAuth redirect URI. GET /accounts//access/ai-controls/mcp/portals//servers//effective-redirect-uri. Path parameters: portal_id, server_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
portalIdstringyesRequired. Unique identifier for the MCP portal.
serverIdstringyesRequired. Unique identifier for the MCP server.

[Cloudflare] List MCP Portals. An MCP Portal is the Zero Trust front door that publishes a set of MCP servers to users behind an Access policy. The portal id this returns is what the read, update and delete tools take, and it pairs with a server id on the redirect-URI tool. GET /accounts//access/ai-controls/mcp/portals. Path parameters: account_id. Optional filters: page, per_page, search. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Which page of results to return, starting at 1.
perPageintegernonullOptional. How many results to return per page.
searchstringnonullOptional. Search by id, name, hostname.

[Cloudflare] DESTRUCTIVE: Update an MCP Portal. Why this is destructive: Wholesale replace: the portal is rewritten from the body, so any server binding or Access policy you omit is removed. PUT /accounts//access/ai-controls/mcp/portals/. Path parameters: id, account_id. Send the request body as JSON; Cloudflare documents these fields: allow_code_mode, code_mode, description, hostname, name, secure_web_gateway, servers. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare documents these fields: allow_code_mode, code_mode, description, hostname, name, secure_web_gateway, servers.
idstringyesRequired. Unique identifier for the MCP portal.

MCP Servers

ToolPlanAccessSummary
cf_create_mcp_serverProWriteCreate a new MCP Server.
cf_delete_mcp_serverProDestructiveDESTRUCTIVE: Delete an MCP Server.
cf_get_mcp_serverFreeRead-onlyRead the details of an MCP Server.
cf_list_mcp_serversFreeRead-onlyList MCP Servers.
cf_sync_mcp_serverProWriteSync MCP Server Capabilities.
cf_update_mcp_serverProDestructiveDESTRUCTIVE: Update an MCP Server.

[Cloudflare] Create a new MCP Server. Additive: registers a new server and changes no existing one. POST /accounts//access/ai-controls/mcp/servers. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: auth_credentials, auth_type, client_secret, description, hostname, id, is_shared_oauth_callback_enabled, name, secure_web_gateway, updated_prompts, updated_tools. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare documents these fields: auth_credentials, auth_type, client_secret, description, hostname, id, is_shared_oauth_callback_enabled, name, secure_web_gateway, updated_prompts, updated_tools.

[Cloudflare] DESTRUCTIVE: Delete an MCP Server. Why this is destructive: Deletes the server and unbinds it from every portal that referenced it. DELETE /accounts//access/ai-controls/mcp/servers/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. Unique identifier for the MCP server.

[Cloudflare] Read the details of an MCP Server. Returns the server with its upstream URL and last-synced capabilities. Read it before an update, which replaces the record wholesale. GET /accounts//access/ai-controls/mcp/servers/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. Unique identifier for the MCP server.

[Cloudflare] List MCP Servers. The MCP servers registered on the account, each with the upstream URL and the capabilities Cloudflare last synced from it. If a portal is serving stale tools, sync the server rather than recreating it. GET /accounts//access/ai-controls/mcp/servers. Path parameters: account_id. Optional filters: page, per_page, search. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Which page of results to return, starting at 1.
perPageintegernonullOptional. How many results to return per page.
searchstringnonullOptional. Search by id, name.

[Cloudflare] Sync MCP Server Capabilities. Re-reads the upstream server capabilities; nothing the customer authored is replaced. POST /accounts//access/ai-controls/mcp/servers//sync. Path parameters: id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. Unique identifier for the MCP server.

[Cloudflare] DESTRUCTIVE: Update an MCP Server. Why this is destructive: Wholesale replace: the server record is rewritten from the body, so an omitted field reverts to its default. PUT /accounts//access/ai-controls/mcp/servers/. Path parameters: id, account_id. Send the request body as JSON; Cloudflare documents these fields: auth_credentials, client_secret, description, is_shared_oauth_callback_enabled, name, secure_web_gateway, updated_prompts, updated_tools. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare documents these fields: auth_credentials, client_secret, description, is_shared_oauth_callback_enabled, name, secure_web_gateway, updated_prompts, updated_tools.
idstringyesRequired. Unique identifier for the MCP server.

Zerotrust

ToolPlanAccessSummary
cf_create_zerotrust_routes_hostnameProWriteCreate hostname route.
cf_create_zerotrust_subnets_warpProWriteCreate WARP IP subnet.
cf_delete_zerotrust_routes_hostnameProDestructiveDESTRUCTIVE: Delete hostname route.
cf_delete_zerotrust_subnets_warpProDestructiveDESTRUCTIVE: Delete WARP IP subnet.
cf_get_zerotrust_connectivity_settingsFreeRead-onlyGet Zero Trust Connectivity Settings.
cf_get_zerotrust_routes_hostnameFreeRead-onlyGet hostname route.
cf_get_zerotrust_subnets_initial_resolved_ipFreeRead-onlyGet Initial Resolved IP Subnet.
cf_get_zerotrust_subnets_warpFreeRead-onlyGet WARP IP subnet.
cf_list_zerotrust_routes_hostnamesFreeRead-onlyList hostname routes.
cf_list_zerotrust_subnetsFreeRead-onlyList Subnets.
cf_set_zerotrust_subnets_initial_resolved_ipProDestructiveDESTRUCTIVE: Update Initial Resolved IP Subnet.
cf_update_zerotrust_connectivity_settingProWriteUpdates the Zero Trust Connectivity Settings.
cf_update_zerotrust_routes_hostnameProWriteUpdate hostname route.
cf_update_zerotrust_subnets_cloudflare_sourceProWriteUpdate Cloudflare Source Subnet.
cf_update_zerotrust_subnets_warpProWriteUpdate WARP IP subnet.

[Cloudflare] Create hostname route. Additive: creates a new record and changes no existing one. POST /accounts//zerotrust/routes/hostname. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: comment, hostname, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: comment, hostname, tunnel_id.

[Cloudflare] Create WARP IP subnet. Additive: creates a new record and changes no existing one. POST /accounts//zerotrust/subnets/warp. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: comment, is_default_network, name, network. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: comment, is_default_network, name, network. Cloudflare requires: name, network.

[Cloudflare] DESTRUCTIVE: Delete hostname route. Why this is destructive: Deletes the hostname route; traffic for that hostname stops going down the tunnel immediately and resolves wherever public DNS points it. DELETE /accounts//zerotrust/routes/hostname/. Path parameters: account_id, hostname_route_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
hostnameRouteIdstringyesRequired. The hostname route ID.

[Cloudflare] DESTRUCTIVE: Delete WARP IP subnet. Why this is destructive: Deletes the WARP IP subnet. Devices assigned addresses from it lose their tunnel addressing, so this disconnects users rather than only editing a record. DELETE /accounts//zerotrust/subnets/warp/. Path parameters: account_id, subnet_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
subnetIdstringyesRequired. The UUID of the subnet.

[Cloudflare] Get Zero Trust Connectivity Settings. The account-wide Zero Trust connectivity posture (ICMP proxy, WARP-to-WARP, default settings for new tunnels). Read it before changing a route or subnet: these settings decide whether a route is reachable at all. GET /accounts//zerotrust/connectivity_settings. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get hostname route. GET /accounts//zerotrust/routes/hostname/. Path parameters: account_id, hostname_route_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
hostnameRouteIdstringyesRequired. The hostname route ID.

[Cloudflare] Get Initial Resolved IP Subnet. GET /accounts//zerotrust/subnets/initial_resolved_ip/. Path parameters: account_id, address_family. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
addressFamilystringyesRequired. IP address family, either `v4` (IPv4) or `v6` (IPv6).

[Cloudflare] Get WARP IP subnet. GET /accounts//zerotrust/subnets/warp/. Path parameters: account_id, subnet_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
subnetIdstringyesRequired. The UUID of the subnet.

[Cloudflare] List hostname routes. Hostname routes send a named host down a tunnel instead of an IP range. The route id every other hostname-route tool takes comes from here. GET /accounts//zerotrust/routes/hostname. Path parameters: account_id. Optional filters: id, hostname, tunnel_id, comment, existed_at, is_deleted, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
commentstringnonullOptional. If set, only list hostname routes with the given comment.
existedAtstringnonullOptional. If provided, include only resources that were created (and not deleted) before this time.
hostnamestringnonullOptional. If set, only list hostname routes that contain a substring of the given value, the filter is case-insensitive.
idstringnonullOptional. The hostname route ID.
isDeletedbooleannonullOptional. If `true`, only return deleted hostname routes.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of results to display.
tunnelIdstringnonullOptional. If set, only list hostname routes that point to a specific tunnel.

[Cloudflare] List Subnets. GET /accounts//zerotrust/subnets. Path parameters: account_id. Optional filters: name, comment, network, existed_at, address_family, is_default_network, is_deleted, sort_order, subnet_types, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
addressFamilystringnonullOptional. If set, only include subnets in the given address family - `v4` or `v6`.
commentstringnonullOptional. If set, only list subnets with the given comment.
existedAtstringnonullOptional. If provided, include only resources that were created (and not deleted) before this time.
isDefaultNetworkbooleannonullOptional. If `true`, only include default subnets.
isDeletedbooleannonullOptional. If `true`, only include deleted subnets.
namestringnonullOptional. If set, only list subnets with the given name.
networkstringnonullOptional. If set, only list the subnet whose network exactly matches the given CIDR.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of results to display.
sortOrderstringnonullOptional. Sort order of the results.
subnetTypesstringnonullOptional. If set, the types of subnets to include, separated by comma.

[Cloudflare] DESTRUCTIVE: Update Initial Resolved IP Subnet. Why this is destructive: Wholesale replace of the initial resolved-IP subnet; the previous value is gone and in-flight sessions re-resolve. PUT /accounts//zerotrust/subnets/initial_resolved_ip/. Path parameters: account_id, address_family. Send the request body as JSON; Cloudflare documents these fields: comment, name, network. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
addressFamilystringyesRequired. IP address family, either `v4` (IPv4) or `v6` (IPv6).
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: comment, name, network.

[Cloudflare] Updates the Zero Trust Connectivity Settings. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//zerotrust/connectivity_settings. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: icmp_proxy_enabled, offramp_warp_enabled. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: icmp_proxy_enabled, offramp_warp_enabled.

[Cloudflare] Update hostname route. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//zerotrust/routes/hostname/. Path parameters: account_id, hostname_route_id. Send the request body as JSON; Cloudflare documents these fields: comment, hostname, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: comment, hostname, tunnel_id.
hostnameRouteIdstringyesRequired. The hostname route ID.

[Cloudflare] Update Cloudflare Source Subnet. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//zerotrust/subnets/cloudflare_source/. Path parameters: account_id, address_family. Send the request body as JSON; Cloudflare documents these fields: comment, name, network. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
addressFamilystringyesRequired. IP address family, either `v4` (IPv4) or `v6` (IPv6).
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: comment, name, network.

[Cloudflare] Update WARP IP subnet. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//zerotrust/subnets/warp/. Path parameters: account_id, subnet_id. Send the request body as JSON; Cloudflare documents these fields: comment, is_default_network, name, network. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: comment, is_default_network, name, network.
subnetIdstringyesRequired. The UUID of the subnet.

Custom Ns

ToolPlanAccessSummary
cf_create_custom_nsProWriteAdd Account Custom Nameserver.
cf_delete_custom_nsProDestructiveDESTRUCTIVE: Delete Account Custom Nameserver.
cf_list_custom_nsFreeRead-onlyList Account Custom Nameservers.
cf_list_zones_custom_nsFreeRead-onlyGet Account Custom Nameserver Related Zone Metadata.
cf_set_zones_custom_nsProDestructiveDESTRUCTIVE: Set Account Custom Nameserver Related Zone Metadata.

[Cloudflare] Add Account Custom Nameserver. Additive: it registers one more nameserver hostname on the account and changes no zone. A zone only begins answering from it once that zone is pointed at the matching nameserver set. Account custom nameservers need a Business or Enterprise account - Cloudflare's own plan table marks Free and Pro false - and the API token needs the Account Settings Write permission group. POST /accounts//custom_ns. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON. ns_name is required and is the FQDN of the name server, for example ns1.example.com. ns_set is optional and is the number of the set this name server belongs to; Cloudflare assigns one when it is omitted.

[Cloudflare] DESTRUCTIVE: Delete Account Custom Nameserver. Why this is destructive: The account stops offering that nameserver hostname to its zones. A zone still delegated to it at the registrar keeps sending the world to a name Cloudflare no longer serves for this account, so move the zones off the set and fix the registrar's NS records BEFORE deleting. Account custom nameservers need a Business or Enterprise account - Cloudflare's own plan table marks Free and Pro false - and the API token needs the Account Settings Write permission group. DELETE /accounts//custom_ns/. Path parameters: custom_ns_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
customNsIdstringyesRequired. The FQDN of the name server to remove, exactly as cf_list_custom_ns returned it in ns_name - for example ns1.example.com, not an opaque id.

[Cloudflare] List Account Custom Nameservers. Account custom nameservers are the vanity nameserver hostnames - ns1.example.com and friends - an account can delegate its zones to instead of Cloudflare's shared pair. Start here: each entry's ns_name is the FQDN cf_delete_custom_ns takes, and its ns_set number is the set a zone is pointed at through cf_update_zones_dns_setting's nameservers object. Cloudflare paginates nothing here: the whole collection comes back in one response. Account custom nameservers need a Business or Enterprise account - Cloudflare's own plan table marks Free and Pro false - and the API token needs the Account Settings Read permission group. GET /accounts//custom_ns. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get Account Custom Nameserver Related Zone Metadata. Reads whether this zone uses the account's custom nameservers and which nameserver set it is on. Cloudflare's own document deprecates it in favour of Show DNS Settings for a zone, which StackJack exposes as cf_get_zones_dns_settings - prefer that tool and read nameservers.type and nameservers.ns_set there. Account custom nameservers need a Business or Enterprise account - Cloudflare's own plan table marks Free and Pro false - and the API token needs the Account Settings Read permission group. GET /zones//custom_ns. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Set Account Custom Nameserver Related Zone Metadata. Why this is destructive: A PUT replaces this zone's whole account-custom-nameserver metadata from the body: leave enabled out and it is cleared, leave ns_set out and the zone's set assignment goes with it. Turning enabled off, or moving the zone to a different set, changes which nameservers answer for the zone, and the NS records at the registrar have to be changed to match or the zone stops resolving. Cloudflare deprecates this in favour of Update DNS Settings for a zone, which StackJack exposes as cf_update_zones_dns_setting - set nameservers.type and nameservers.ns_set there instead. Cloudflare also notes that making NEW zones in the account use account custom nameservers by default is an account setting (use_account_custom_ns_by_default), not a per-zone call. Account custom nameservers need a Business or Enterprise account - Cloudflare's own plan table marks Free and Pro false - and the API token needs the Account Settings Write permission group. PUT /zones//custom_ns. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesSend the request body as JSON. enabled decides whether the zone uses account-level custom nameservers at all. ns_set is the number of the name server set to assign to the zone, from cf_list_custom_ns.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

DNS Analytics

ToolPlanAccessSummary
cf_get_zones_dns_analytics_report_bytimesFreeRead-onlyDNS Analytics time series for a zone.
cf_get_zones_dns_analytics_reportsFreeRead-onlyDNS Analytics report table for a zone.

[Cloudflare] DNS Analytics time series for a zone. The same zone metrics as cf_get_zones_dns_analytics_reports, bucketed over time: time_delta picks the bucket size and the result carries one value per bucket. Cloudflare marks this deprecated and points at its API deprecation notice dated 2025-12-09, a date that has already passed - the endpoint still answers, and Cloudflare names no REST replacement for it, so there is no non-deprecated sibling to move to. GET /zones//dns_analytics/report/bytime. Path parameters: zone_id. Optional filters: metrics, dimensions, since, until, limit, sort, filters, time_delta. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
dimensionsstringnonullOptional. Comma-separated list of dimensions to group the rows by, for example queryName,queryType.
filtersstringnonullOptional. Segmentation filter in Cloudflare's own 'attribute operator value' form, for example responseCode==NOERROR.
limitintegernonullOptional. Caps how many metric rows Cloudflare returns. StackJack always sends a value: omit it and 100 is sent, and it accepts up to 1000.
metricsstringnonullOptional. Comma-separated list of metrics to query, for example queryCount,responseTimeAvg.
sincestringnonullOptional. Start of the window, ISO 8601.
sortstringnonullOptional. Comma-separated list of dimensions to sort by, each optionally prefixed with - for descending or + for ascending.
timeDeltastringnonullOptional. Bucket size the metrics are grouped into over the window.
untilstringnonullOptional. End of the window, ISO 8601.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DNS Analytics report table for a zone. One aggregated row per combination of the dimensions you group by, over the whole window - the table view rather than a time series; cf_get_zones_dns_analytics_report_bytimes is the series. The numbers are this zone's own authoritative query traffic. Cloudflare marks this deprecated and points at its API deprecation notice dated 2025-12-09, a date that has already passed - the endpoint still answers, and Cloudflare names no REST replacement for it, so there is no non-deprecated sibling to move to. GET /zones//dns_analytics/report. Path parameters: zone_id. Optional filters: metrics, dimensions, since, until, limit, sort, filters. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
dimensionsstringnonullOptional. Comma-separated list of dimensions to group the rows by, for example queryName,queryType.
filtersstringnonullOptional. Segmentation filter in Cloudflare's own 'attribute operator value' form, for example responseCode==NOERROR.
limitintegernonullOptional. Caps how many metric rows Cloudflare returns. StackJack always sends a value: omit it and 100 is sent, and it accepts up to 1000.
metricsstringnonullOptional. Comma-separated list of metrics to query, for example queryCount,responseTimeAvg.
sincestringnonullOptional. Start of the window, ISO 8601.
sortstringnonullOptional. Comma-separated list of dimensions to sort by, each optionally prefixed with - for descending or + for ascending.
untilstringnonullOptional. End of the window, ISO 8601.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

DNS Firewall

ToolPlanAccessSummary
cf_create_dns_firewallProWriteCreate DNS Firewall Cluster.
cf_delete_dns_firewallProDestructiveDESTRUCTIVE: Delete DNS Firewall Cluster.
cf_get_dns_firewallFreeRead-onlyDNS Firewall Cluster Details.
cf_get_dns_firewall_dns_analytics_report_bytimesFreeRead-onlyDNS Analytics time series for a DNS Firewall cluster.
cf_get_dns_firewall_dns_analytics_reportsFreeRead-onlyDNS Analytics report table for a DNS Firewall cluster.
cf_get_dns_firewall_reverse_dnsFreeRead-onlyShow DNS Firewall Cluster Reverse DNS.
cf_list_dns_firewallsFreeRead-onlyList DNS Firewall Clusters.
cf_update_dns_firewallProDestructiveDESTRUCTIVE: Update DNS Firewall Cluster.
cf_update_dns_firewall_reverse_dnsProWriteUpdate DNS Firewall Cluster Reverse DNS.

[Cloudflare] Create DNS Firewall Cluster. Additive: it stands up a new cluster and touches no existing one. Nothing resolves through it until the customer points resolvers at the addresses Cloudflare returns. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Write permission group. POST /accounts//dns_firewall. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON. name and upstream_ips are required, and upstream_ips is the list of the customer's own authoritative nameserver addresses this cluster forwards to - getting it wrong is what breaks resolution. dns_firewall_ip_count sets how many IPv4 addresses the cluster is given and CANNOT be changed afterwards. ratelimit is the per-second query ceiling forwarded upstream and retries the number of extra attempts; minimum_cache_ttl, maximum_cache_ttl and negative_cache_ttl bound how long answers are cached without changing the TTL Cloudflare returns to clients; attack_mitigation.enabled turns on random-prefix attack mitigation; deprecate_any_requests refuses ANY queries and ecs_fallback forwards the client subnet when no EDNS Client Subnet was sent.

[Cloudflare] DESTRUCTIVE: Delete DNS Firewall Cluster. Why this is destructive: The cluster goes and Cloudflare releases the addresses it answered on. Every resolver still pointed at those addresses stops getting answers the moment it does, so move them off first - a rebuilt cluster is given new addresses and the old ones are not held for you. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Write permission group. DELETE /accounts//dns_firewall/. Path parameters: dns_firewall_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
dnsFirewallIdstringyesRequired. The DNS Firewall cluster id from cf_list_dns_firewalls.

[Cloudflare] DNS Firewall Cluster Details. Reads one cluster's whole configuration - upstream_ips, the cache TTL bounds, the rate limit and the attack-mitigation settings. Worth doing before cf_update_dns_firewall, because upstream_ips is an array that the PATCH replaces wholesale. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Read or DNS Firewall Write permission group. GET /accounts//dns_firewall/. Path parameters: dns_firewall_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
dnsFirewallIdstringyesRequired. The DNS Firewall cluster id from cf_list_dns_firewalls.

[Cloudflare] DNS Analytics time series for a DNS Firewall cluster. The same cluster metrics as cf_get_dns_firewall_dns_analytics_reports, bucketed over time by time_delta. Cloudflare marks this deprecated and points at its API deprecation notice dated 2025-12-09, a date that has already passed - the endpoint still answers, and Cloudflare names no REST replacement for it, so there is no non-deprecated sibling to move to. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Read or DNS Firewall Write permission group. GET /accounts//dns_firewall//dns_analytics/report/bytime. Path parameters: dns_firewall_id, account_id. Optional filters: metrics, dimensions, since, until, limit, sort, filters, time_delta. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
dimensionsstringnonullOptional. Comma-separated list of dimensions to group the rows by, for example queryName,queryType.
dnsFirewallIdstringyesRequired. The DNS Firewall cluster id from cf_list_dns_firewalls.
filtersstringnonullOptional. Segmentation filter in Cloudflare's own 'attribute operator value' form, for example responseCode==NOERROR.
limitintegernonullOptional. Caps how many metric rows Cloudflare returns. StackJack always sends a value: omit it and 100 is sent, and it accepts up to 1000.
metricsstringnonullOptional. Comma-separated list of metrics to query, for example queryCount,responseTimeAvg.
sincestringnonullOptional. Start of the window, ISO 8601.
sortstringnonullOptional. Comma-separated list of dimensions to sort by, each optionally prefixed with - for descending or + for ascending.
timeDeltastringnonullOptional. Bucket size the metrics are grouped into over the window.
untilstringnonullOptional. End of the window, ISO 8601.

[Cloudflare] DNS Analytics report table for a DNS Firewall cluster. The aggregated table for ONE DNS Firewall cluster's own resolver traffic - queries that passed through the cluster, not a zone's authoritative traffic. Cloudflare marks this deprecated and points at its API deprecation notice dated 2025-12-09, a date that has already passed - the endpoint still answers, and Cloudflare names no REST replacement for it, so there is no non-deprecated sibling to move to. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Read or DNS Firewall Write permission group. GET /accounts//dns_firewall//dns_analytics/report. Path parameters: dns_firewall_id, account_id. Optional filters: metrics, dimensions, since, until, limit, sort, filters. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
dimensionsstringnonullOptional. Comma-separated list of dimensions to group the rows by, for example queryName,queryType.
dnsFirewallIdstringyesRequired. The DNS Firewall cluster id from cf_list_dns_firewalls.
filtersstringnonullOptional. Segmentation filter in Cloudflare's own 'attribute operator value' form, for example responseCode==NOERROR.
limitintegernonullOptional. Caps how many metric rows Cloudflare returns. StackJack always sends a value: omit it and 100 is sent, and it accepts up to 1000.
metricsstringnonullOptional. Comma-separated list of metrics to query, for example queryCount,responseTimeAvg.
sincestringnonullOptional. Start of the window, ISO 8601.
sortstringnonullOptional. Comma-separated list of dimensions to sort by, each optionally prefixed with - for descending or + for ascending.
untilstringnonullOptional. End of the window, ISO 8601.

[Cloudflare] Show DNS Firewall Cluster Reverse DNS. Reads the PTR records Cloudflare publishes for the cluster's own IP addresses - the reverse DNS an upstream nameserver sees when the cluster queries it. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Read or DNS Firewall Write permission group. GET /accounts//dns_firewall//reverse_dns. Path parameters: dns_firewall_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
dnsFirewallIdstringyesRequired. The DNS Firewall cluster id from cf_list_dns_firewalls.

[Cloudflare] List DNS Firewall Clusters. A DNS Firewall cluster is a Cloudflare-hosted resolver placed in front of a customer's own authoritative nameservers, caching, rate-limiting and mitigating attacks on the way through. Start here: each cluster's id is what every other DNS Firewall tool takes, and the addresses Cloudflare returns are the ones the customer points resolvers at. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Read or DNS Firewall Write permission group. GET /accounts//dns_firewall. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of clusters per page.

[Cloudflare] DESTRUCTIVE: Update DNS Firewall Cluster. Why this is destructive: Partial update: Cloudflare applies only the fields present in the body. upstream_ips is the exception that bites - it is an ARRAY, so sending it replaces the whole upstream list rather than adding to it, and a short or mistyped list stops the cluster resolving for everything behind it. Read cf_get_dns_firewall first and send the complete list. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Write permission group. PATCH /accounts//dns_firewall/. Path parameters: dns_firewall_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON with only the fields you are changing. upstream_ips is an ARRAY and REPLACES the whole upstream list when present. ratelimit is the per-second query ceiling forwarded upstream and retries the number of extra attempts; minimum_cache_ttl, maximum_cache_ttl and negative_cache_ttl bound how long answers are cached without changing the TTL Cloudflare returns to clients; attack_mitigation.enabled turns on random-prefix attack mitigation; deprecate_any_requests refuses ANY queries and ecs_fallback forwards the client subnet when no EDNS Client Subnet was sent. dns_firewall_ip_count is fixed at creation and is not accepted here.
dnsFirewallIdstringyesRequired. The DNS Firewall cluster id from cf_list_dns_firewalls.

[Cloudflare] Update DNS Firewall Cluster Reverse DNS. Partial update: Cloudflare applies only the fields present in the body. ptr is a MAP of cluster IP address to PTR content, and Cloudflare does not document whether an address left out of the map is kept or cleared - read cf_get_dns_firewall_reverse_dns first and send the complete map. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Write permission group. PATCH /accounts//dns_firewall//reverse_dns. Path parameters: dns_firewall_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON with a single ptr field: an object whose keys are the cluster's own IP addresses and whose values are the PTR record content to publish for each.
dnsFirewallIdstringyesRequired. The DNS Firewall cluster id from cf_list_dns_firewalls.

DNS Record Scans

ToolPlanAccessSummary
cf_list_scanned_dns_recordsFreeRead-onlyList Scanned DNS Records.
cf_review_scanned_dns_recordsProWriteReview Scanned DNS Records.
cf_scan_dns_recordsProWriteScan DNS Records.
cf_trigger_dns_record_scanProWriteTrigger DNS Record Scan.

[Cloudflare] List Scanned DNS Records. GET /zones//dns_records/scan/review. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Review Scanned DNS Records. Additive: accepts scanned records into the zone and removes none. POST /zones//dns_records/scan/review. Path parameters: zone_id. Send the request body as JSON; Cloudflare documents these fields: accepts, rejects. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: accepts, rejects.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Scan DNS Records. Additive: the scan adds records it discovers and removes none. POST /zones//dns_records/scan. Path parameters: zone_id. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON, per Cloudflare's documented sample for this endpoint.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Trigger DNS Record Scan. Starts a scan; nothing is written to the zone until the review call accepts it. POST /zones//dns_records/scan/trigger. Path parameters: zone_id. An optional JSON request body is accepted; Cloudflare publishes no sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Cloudflare publishes no sample for this endpoint; omit it unless you know the shape.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

DNS Records

ToolPlanAccessSummary
cf_batch_dns_recordsProDestructiveDESTRUCTIVE: Batch DNS Records.
cf_create_dns_recordProWriteCreate DNS Record.
cf_delete_dns_recordProDestructiveDESTRUCTIVE: Delete DNS Record.
cf_export_dns_recordsFreeRead-onlyExport DNS Records.
cf_get_dns_recordFreeRead-onlyDNS Record Details.
cf_import_dns_recordsProDestructiveDESTRUCTIVE: Import DNS Records.
cf_list_dns_recordsFreeRead-onlyList DNS Records.
cf_overwrite_dns_recordProDestructiveDESTRUCTIVE: Overwrite DNS Record.
cf_update_dns_recordProWriteUpdate DNS Record.

[Cloudflare] DESTRUCTIVE: Batch DNS Records. Why this is destructive: One batch carries deletes, patches and puts together and applies them atomically, so it can remove records. POST /zones//dns_records/batch. Path parameters: zone_id. Optional filters: include_shadow_metadata. Send the request body as JSON; Cloudflare documents these fields: deletes, patches, posts, puts. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: deletes, patches, posts, puts.
includeShadowMetadatabooleannonullOptional. Whether to include shadow metadata in the `meta` field of each record in the response.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Create DNS Record. Additive, and the plan task rules DNS record create false. Cloudflare requires type, name and content; ttl of 1 means automatic, and proxied only applies to record types Cloudflare can proxy. A duplicate name and type is refused rather than merged. POST /zones//dns_records. Path parameters: zone_id. Optional filters: include_shadow_metadata. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON, per Cloudflare's documented sample for this endpoint.
includeShadowMetadatabooleannonullOptional. Whether to include shadow metadata in the `meta` field of each record in the response.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete DNS Record. Why this is destructive: Deletes the record; resolution for that name stops immediately. DELETE /zones//dns_records/. Path parameters: dns_record_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
dnsRecordIdstringyesRequired. The DNS record id, as returned by cf_list_dns_records. It is not the record name.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Export DNS Records. Returns the whole zone as a BIND file, which is the quickest way to hand a customer or an auditor a complete picture of their DNS. This is the one Cloudflare response in this connector that is not JSON. GET /zones//dns_records/export. Path parameters: zone_id. Returns the zone file as plain text exactly as Cloudflare sent it, not JSON.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DNS Record Details. Reads one record by the id the list tool returned. Use it to confirm the current content, TTL and proxy state before an update, since the overwrite tool resets anything left out. GET /zones//dns_records/. Path parameters: dns_record_id, zone_id. Optional filters: include_shadow_metadata. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
dnsRecordIdstringyesRequired. The DNS record id, as returned by cf_list_dns_records. It is not the record name.
includeShadowMetadatabooleannonullOptional. Whether to include shadow metadata in the `meta` field of each record in the response.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Import DNS Records. Why this is destructive: A BIND file import writes every record it contains in one call and overwrites a record of the same name and type. Takes the BIND zone text itself, not a file path or an upload. Review the export of the target zone first: this writes every record the file contains in one call. POST /zones//dns_records/import. Path parameters: zone_id. Send the BIND zone file text itself as the file argument - this is not a file upload, it is the zone text. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
filestringyesRequired. The BIND zone file CONTENT as text, not a path or an upload - for example 'www.example.com. 300 IN A 127.0.0.1'.
proxiedstringnonullOptional. Whether proxiable records should be proxied through Cloudflare. Send the string 'true' or 'false'; Cloudflare defaults it to false.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List DNS Records. The first call for almost any DNS question. Narrow with type (A, AAAA, CNAME, MX, TXT) and name; match=all means every filter must hit, match=any means at least one. The record id it returns is what the get, update, overwrite and delete tools take. GET /zones//dns_records. Path parameters: zone_id. Optional filters: name, name.exact, name.contains, name.startswith, name.endswith, type, content, content.exact, content.contains, content.startswith, content.endswith, proxied, match, comment, comment.present, comment.absent, comment.exact, comment.contains, comment.startswith, comment.endswith, tag, tag.present, tag.absent, tag.exact, tag.contains, tag.startswith, tag.endswith, search, tag_match, page, per_page, order, direction, include_shadow_metadata, shadowed_by_name, shadowing_name. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional. Exact value of the DNS record comment.
commentAbsentstringnonullOptional. If this parameter is present, only records without a comment are returned.
commentContainsstringnonullOptional. Substring of the DNS record comment.
commentEndswithstringnonullOptional. Suffix of the DNS record comment.
commentExactstringnonullOptional. Exact value of the DNS record comment.
commentPresentstringnonullOptional. If this parameter is present, only records with a comment are returned.
commentStartswithstringnonullOptional. Prefix of the DNS record comment.
contentstringnonullOptional. Exact value of the DNS record content.
contentContainsstringnonullOptional. Substring of the DNS record content.
contentEndswithstringnonullOptional. Suffix of the DNS record content.
contentExactstringnonullOptional. Exact value of the DNS record content.
contentStartswithstringnonullOptional. Prefix of the DNS record content.
directionstringnonullOptional. Direction to order DNS records in.
includeShadowMetadatabooleannonullOptional. Whether to include shadow metadata in the `meta` field of each record in the response.
matchstringnonullOptional. Whether to match all search requirements or at least one (any).
namestringnonullOptional. Exact value of the DNS record name.
nameContainsstringnonullOptional. Substring of the DNS record name.
nameEndswithstringnonullOptional. Suffix of the DNS record name.
nameExactstringnonullOptional. Exact value of the DNS record name.
nameStartswithstringnonullOptional. Prefix of the DNS record name.
orderstringnonullOptional. Field to order DNS records by.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of DNS records per page.
proxiedbooleannonullOptional. Whether the record is receiving the performance and security benefits of Cloudflare.
searchstringnonullOptional. Allows searching in multiple properties of a DNS record simultaneously.
shadowedByNamestringnonullOptional. Filters to records at or below the given NS delegation name, excluding the NS records that form the delegation itself.
shadowingNamestringnonullOptional. Returns NS records that shadow the given name, searching at the name itself and each of its ancestor names within the zone, excluding the zone apex.
tagstringnonullOptional. Condition on the DNS record tag.
tagAbsentstringnonullOptional. Name of a tag which must not be present on the DNS record.
tagContainsstringnonullOptional. A tag and value, of the form `:`.
tagEndswithstringnonullOptional. A tag and value, of the form `:`.
tagExactstringnonullOptional. A tag and value, of the form `:`.
tagMatchstringnonullOptional. Whether to match all tag search requirements or at least one (any).
tagPresentstringnonullOptional. Name of a tag which must be present on the DNS record.
tagStartswithstringnonullOptional. A tag and value, of the form `:`.
typestringnonullOptional. Record type.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Overwrite DNS Record. Why this is destructive: Wholesale replace: Cloudflare calls this Overwrite, and every field you omit is reset to its default rather than kept. PUT /zones//dns_records/. Path parameters: dns_record_id, zone_id. Optional filters: include_shadow_metadata. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON, per Cloudflare's documented sample for this endpoint.
dnsRecordIdstringyesRequired. The DNS record id, as returned by cf_list_dns_records. It is not the record name.
includeShadowMetadatabooleannonullOptional. Whether to include shadow metadata in the `meta` field of each record in the response.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Update DNS Record. Partial update: omitted fields keep their value, and the plan task rules DNS record update false. The safe way to change one field of a record: anything you leave out keeps its current value. Prefer it over the overwrite tool unless you deliberately want the omitted fields reset. PATCH /zones//dns_records/. Path parameters: dns_record_id, zone_id. Optional filters: include_shadow_metadata. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON, per Cloudflare's documented sample for this endpoint.
dnsRecordIdstringyesRequired. The DNS record id, as returned by cf_list_dns_records. It is not the record name.
includeShadowMetadatabooleannonullOptional. Whether to include shadow metadata in the `meta` field of each record in the response.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

DNS Settings

ToolPlanAccessSummary
cf_create_dns_settings_viewProWriteCreate Internal DNS View.
cf_delete_dns_settings_viewProDestructiveDESTRUCTIVE: Delete Internal DNS View.
cf_get_dns_settingsFreeRead-onlyShow account DNS settings.
cf_get_dns_settings_viewFreeRead-onlyDNS Internal View Details.
cf_get_zones_dns_settingsFreeRead-onlyShow zone DNS settings.
cf_list_dns_settings_viewsFreeRead-onlyList Internal DNS Views.
cf_update_dns_settingProDestructiveDESTRUCTIVE: Update account DNS settings.
cf_update_dns_settings_viewProDestructiveDESTRUCTIVE: Update Internal DNS View.
cf_update_zones_dns_settingProDestructiveDESTRUCTIVE: Update zone DNS settings.

[Cloudflare] Create Internal DNS View. Additive: it creates a view and leaves every existing one alone. A zone named in zones starts being answered through this view immediately, so a zone bound to the wrong view answers the wrong clients. Internal DNS views are Enterprise-only, and the API token needs the DNS View Write permission group, which is separate from plain DNS Write. POST /accounts//dns_settings/views. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON. name and zones are both required, and zones is an ARRAY of zone ids to bind to the view. created_time and modified_time are Cloudflare's own timestamps rather than values to set.

[Cloudflare] DESTRUCTIVE: Delete Internal DNS View. Why this is destructive: The view goes and every zone bound to it loses that binding, so clients that were resolving those zones through the view stop getting the view's answers. The zones themselves survive; the binding does not, and it cannot be recovered from here. Internal DNS views are Enterprise-only, and the API token needs the DNS View Write permission group, which is separate from plain DNS Write. DELETE /accounts//dns_settings/views/. Path parameters: account_id, view_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
viewIdstringyesRequired. The internal DNS view id from cf_list_dns_settings_views.

[Cloudflare] Show account DNS settings. The ACCOUNT-level settings that sit above every zone: enforce_dns_only, and the zone_defaults block new zones inherit. cf_get_zones_dns_settings is the per-zone read - Cloudflare gives both operations the same summary, so check the path when choosing. The API token needs the Account DNS Settings Read permission group. GET /accounts//dns_settings. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DNS Internal View Details. Reads one view and the zone ids bound to it. Worth doing before cf_update_dns_settings_view, because zones is an array that the PATCH replaces. Internal DNS views are Enterprise-only, and the API token needs the DNS View Read or DNS View Write permission group, which is separate from plain DNS Read. GET /accounts//dns_settings/views/. Path parameters: account_id, view_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
viewIdstringyesRequired. The internal DNS view id from cf_list_dns_settings_views.

[Cloudflare] Show zone DNS settings. The per-ZONE settings: nameservers.type and nameservers.ns_set, which decide the nameservers the zone is delegated to, plus zone_mode, flatten_all_cnames, multi_provider, secondary_overrides, ns_ttl and the SOA components. cf_get_dns_settings is the account-level read - Cloudflare gives both operations the same summary, so check the path when choosing. The API token needs Zone DNS Settings Read or DNS Read. GET /zones//dns_settings. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List Internal DNS Views. An internal DNS view binds a set of zones together so they are answered only to clients resolving through that view - Cloudflare's split-horizon construct. Start here: each view's id is what the get, update and delete tools take, and zones is the list of zone ids bound to it. Narrow with name and the name.exact / name.contains / name.startswith / name.endswith forms, or by zone_id or zone_name; match=all requires every filter to hit and match=any at least one. Internal DNS views are Enterprise-only, and the API token needs the DNS View Read or DNS View Write permission group, which is separate from plain DNS Read. GET /accounts//dns_settings/views. Path parameters: account_id. Optional filters: name, name.exact, name.contains, name.startswith, name.endswith, zone_id, zone_name, match, page, per_page, order, direction. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
directionstringnonullOptional. Direction to order DNS views in.
matchstringnonullOptional. Whether to match all search requirements or at least one (any).
namestringnonullOptional. Exact value of the DNS view name.
nameContainsstringnonullOptional. Substring of the DNS view name.
nameEndswithstringnonullOptional. Suffix of the DNS view name.
nameExactstringnonullOptional. Exact value of the DNS view name.
nameStartswithstringnonullOptional. Prefix of the DNS view name.
orderstringnonullOptional. Field to order DNS views by.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of DNS views per page.
zoneIdstringnonullOptional. A zone ID that exists in the zones list for the view.
zoneNamestringnonullOptional. A zone name that exists in the zones list for the view.

[Cloudflare] DESTRUCTIVE: Update account DNS settings. Why this is destructive: This is the account-wide override. Cloudflare's own words for enforce_dns_only are that it 'forces all proxied DNS records in the account to behave as DNS-only at the edge, regardless of each record's individual proxy setting' - one call changes how every proxied record in every zone on the account is served, and each record's own proxy setting is ignored while it is on. The derived verdict read this as an ordinary partial update; the blast radius is the whole account. zone_defaults carries the settings a NEW zone starts with, so a change there is not retroactive, while enforce_dns_only takes effect for existing zones immediately. The API token needs the Account DNS Settings Write permission group. PATCH /accounts//dns_settings. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON with only the fields you are changing. enforce_dns_only is the account-wide DNS-only override described above. zone_defaults holds the DNS settings a newly created zone inherits.

[Cloudflare] DESTRUCTIVE: Update Internal DNS View. Why this is destructive: Partial update: Cloudflare applies only the fields present. zones is an ARRAY, so sending it replaces the whole binding list and a zone left out of it stops being answered through this view. Read cf_get_dns_settings_view first and send the complete list. Internal DNS views are Enterprise-only, and the API token needs the DNS View Write permission group, which is separate from plain DNS Write. PATCH /accounts//dns_settings/views/. Path parameters: account_id, view_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON with only the fields you are changing. name renames the view. zones is the COMPLETE array of zone ids bound to it and replaces the existing list. created_time and modified_time are Cloudflare's own timestamps.
viewIdstringyesRequired. The internal DNS view id from cf_list_dns_settings_views.

[Cloudflare] DESTRUCTIVE: Update zone DNS settings. Why this is destructive: nameservers.type and nameservers.ns_set decide which nameservers the WHOLE zone is delegated to - cloudflare.standard, cloudflare.advanced, custom.account, custom.tenant or custom.zone - and a zone whose delegation stops matching the NS records at its registrar stops resolving for everyone. zone_mode switches the entire zone between standard, cdn_only and dns_only, and flatten_all_cnames changes what every CNAME in the zone answers. Cloudflare deprecated PUT /zones//custom_ns in favour of THIS operation, and that one is destructive, so the replacement cannot be gentler than the call it replaces. The derived verdict read this as an ordinary partial update. The one tool here that changes zone-wide DNS behaviour rather than a single record; cf_update_dns_record is what you want for one name. foundation_dns is deprecated in Cloudflare's own schema - use nameservers.type to configure Advanced Nameservers. The API token needs Zone DNS Settings Write plus DNS Write. PATCH /zones//dns_settings. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesSend the request body as JSON with only the fields you are changing. nameservers is an object of type (cloudflare.standard, cloudflare.advanced, custom.account, custom.tenant, custom.zone) and ns_set. zone_mode is standard, cdn_only or dns_only. soa carries the zone's SOA components - mname, rname, refresh, retry, expire, min_ttl and ttl - and ns_ttl the TTL of the zone's NS records. multi_provider lets Cloudflare activate the zone even with non-Cloudflare NS records present; secondary_overrides lets a Secondary DNS zone use proxied override records and apex CNAME flattening; internal_dns.reference_zone_id names the zone an internal zone falls back to.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

DNS Usage

ToolPlanAccessSummary
cf_get_account_dns_record_usageFreeRead-onlyGet DNS Record Usage for Account.
cf_get_zone_dns_record_usageFreeRead-onlyGet DNS Record Usage.

[Cloudflare] Get DNS Record Usage for Account. GET /accounts//dns_records/usage. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get DNS Record Usage. GET /zones//dns_records/usage. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

DNSSEC

ToolPlanAccessSummary
cf_delete_zones_dnssecProDestructiveDESTRUCTIVE: Delete DNSSEC records.
cf_get_zones_dnssecsFreeRead-onlyDNSSEC Details.
cf_list_zones_dnssec_zsksFreeRead-onlyList DNSSEC ZSKs.
cf_update_zones_dnssecProDestructiveDESTRUCTIVE: Edit DNSSEC Status.

[Cloudflare] DESTRUCTIVE: Delete DNSSEC records. Why this is destructive: DNSSEC is turned off for the zone and Cloudflare discards the signing material. If the registrar still publishes the zone's DS record, every validating resolver refuses the whole domain from that moment - remove the DS record at the registrar FIRST. Enabling again later produces a new key and a new DS record, so the old one never becomes valid again. DELETE /zones//dnssec. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DNSSEC Details. The zone's DNSSEC state and the DS record the customer has to publish at their REGISTRAR: status, algorithm, digest, digest_type, key_tag, flags and public_key, plus a ready-made ds string. Read this first - DNSSEC only takes effect once that DS record is at the registrar, and removing it there is the first step of turning DNSSEC off safely. GET /zones//dnssec. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List DNSSEC ZSKs. The Zone Signing Keys DNSSEC uses for this zone: each entry carries its DNSKEY record, a lifecycle Tag (active, publish, external, retired, revoked or removed) and the storage Location Cloudflare keeps the key material in. The SigningKey member includes the key's encrypted PRIVATE key material, so treat the whole result as credential material and do not persist it. Cloudflare paginates nothing here: the whole collection comes back in one response. GET /zones//dnssec/zsk. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Edit DNSSEC Status. Why this is destructive: Cloudflare's own description of this operation is 'Enable or disable DNSSEC', and status takes active or disabled. Disabling DNSSEC while the registrar still publishes the zone's DS record makes every validating resolver refuse the WHOLE domain - the DS record has to be removed at the registrar first. dnssec_presigned and dnssec_multi_signer also change how the zone is signed for everyone who validates it. The summary-verb arm reads the vendor's summary, which here is the neutral 'Edit DNSSEC Status', so the derived verdict never saw the disable. Enabling returns the DS record to publish at the registrar; nothing validates until it is there. PATCH /zones//dnssec. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesSend the request body as JSON. status is active or disabled and is the enable/disable switch. dnssec_use_nsec3 turns on NSEC3. dnssec_presigned lets Cloudflare transfer in an already-signed zone with its signatures instead of signing on the fly, and dnssec_multi_signer lets more than one provider serve the signed zone at once, which is what allows non-Cloudflare DNSKEY records to be added to the zone.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

Secondary DNS

ToolPlanAccessSummary
cf_create_secondary_dns_aclProWriteCreate ACL.
cf_create_secondary_dns_peerProWriteCreate Peer.
cf_create_secondary_dns_tsigProWriteCreate TSIG.
cf_create_zones_secondary_dns_force_axfrProDestructiveDESTRUCTIVE: Force AXFR.
cf_create_zones_secondary_dns_incomingProWriteCreate Secondary Zone Configuration.
cf_create_zones_secondary_dns_outgoingProWriteCreate Primary Zone Configuration.
cf_create_zones_secondary_dns_outgoing_force_notifyProDestructiveDESTRUCTIVE: Force DNS NOTIFY.
cf_delete_secondary_dns_aclProDestructiveDESTRUCTIVE: Delete ACL.
cf_delete_secondary_dns_peerProDestructiveDESTRUCTIVE: Delete Peer.
cf_delete_secondary_dns_tsigProDestructiveDESTRUCTIVE: Delete TSIG.
cf_delete_zones_secondary_dns_incomingProDestructiveDESTRUCTIVE: Delete Secondary Zone Configuration.
cf_delete_zones_secondary_dns_outgoingProDestructiveDESTRUCTIVE: Delete Primary Zone Configuration.
cf_disable_zones_secondary_dns_outgoingProDestructiveDESTRUCTIVE: Disable Outgoing Zone Transfers.
cf_enable_zones_secondary_dns_outgoingProWriteEnable Outgoing Zone Transfers.
cf_get_secondary_dns_aclFreeRead-onlyACL Details.
cf_get_secondary_dns_peerFreeRead-onlyPeer Details.
cf_get_secondary_dns_tsigFreeRead-onlyTSIG Details.
cf_get_zones_secondary_dns_incomingsFreeRead-onlySecondary Zone Configuration Details.
cf_get_zones_secondary_dns_outgoing_configFreeRead-onlyPrimary Zone Configuration Details.
cf_get_zones_secondary_dns_outgoing_statusFreeRead-onlyGet Outgoing Zone Transfer Status.
cf_list_secondary_dns_aclsFreeRead-onlyList ACLs.
cf_list_secondary_dns_peersFreeRead-onlyList Peers.
cf_list_secondary_dns_tsigsFreeRead-onlyList TSIGs.
cf_set_secondary_dns_aclProDestructiveDESTRUCTIVE: Update ACL.
cf_set_secondary_dns_peerProDestructiveDESTRUCTIVE: Update Peer.
cf_set_secondary_dns_tsigProDestructiveDESTRUCTIVE: Update TSIG.
cf_set_zones_secondary_dns_incomingProDestructiveDESTRUCTIVE: Update Secondary Zone Configuration.
cf_set_zones_secondary_dns_outgoingProDestructiveDESTRUCTIVE: Update Primary Zone Configuration.

[Cloudflare] Create ACL. Additive: it widens what the account accepts transfer traffic from and narrows nothing. The range applies to the ENTIRE account, not to one zone. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. POST /accounts//secondary_dns/acls. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON. name and ip_range are both required. ip_range is the allowed IPv4/IPv6 range of the primary or secondary nameservers and applies across the whole account; Cloudflare caps it at /24 for IPv4 and /64 for IPv6.

[Cloudflare] Create Peer. Additive: it registers one more peer on the account. Only name is required, so the peer arrives without an address and transfers nothing until cf_set_secondary_dns_peer fills in ip, port and any tsig_id. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. POST /accounts//secondary_dns/peers. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON. Only name is required - the rest of the peer (ip, port, ixfr_enable, tsig_id) is filled in afterwards with cf_set_secondary_dns_peer.

[Cloudflare] Create TSIG. Additive: it stores one more TSIG key on the account and rebinds no peer - a transfer only starts using it once cf_set_secondary_dns_peer names its id as tsig_id. The secret you send IS the shared secret, and the response echoes it back. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. POST /accounts//secondary_dns/tsigs. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON. Cloudflare requires all four of id, name, secret and algo. name is the TSIG key name as BOTH sides of the transfer know it, algo is the TSIG algorithm, and secret is the shared secret itself - the identical value has to be configured on the peer nameserver or the transfer fails authentication.

[Cloudflare] DESTRUCTIVE: Force AXFR. Why this is destructive: It dispatches a full AXFR to the zone's primary nameservers right now, and Cloudflare replaces its copy of the zone with whatever the primary answers - every record in the zone, at once. A primary serving a truncated or wrong zone at that moment becomes what the internet sees within the TTL. It also bypasses the auto_refresh_seconds schedule, so it is the call that turns a primary-side mistake into a live one immediately. Cloudflare answers with the ordinary JSON envelope and performs the transfer asynchronously, so read the zone's records or cf_get_zones_secondary_dns_incomings afterwards to see what arrived. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/force_axfr. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Create Secondary Zone Configuration. Additive for this zone: it registers the incoming transfer configuration and names the peers Cloudflare will pull from. Once it exists the zone's contents come from the primary nameserver over AXFR/IXFR rather than from records edited at Cloudflare. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/incoming. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesSend the request body as JSON. Cloudflare's schema marks all four of id, name, peers and auto_refresh_seconds required, including on this create. name is the zone name, peers is an ARRAY of peer tags from cf_list_secondary_dns_peers, and auto_refresh_seconds is how often the zone refreshes regardless of DNS NOTIFY. Cloudflare documents no meaning for id on this endpoint.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Create Primary Zone Configuration. Additive for this zone: it registers the outgoing transfer configuration naming the secondaries Cloudflare will serve. Creating the configuration and switching transfers on are separate calls here - cf_enable_zones_secondary_dns_outgoing is the switch. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/outgoing. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesSend the request body as JSON. Cloudflare requires id, name and peers. name is the zone name and peers is an ARRAY of peer tags from cf_list_secondary_dns_peers - the secondary nameservers Cloudflare will NOTIFY and answer transfers for. Cloudflare documents no meaning for id on this endpoint.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Force DNS NOTIFY. Why this is destructive: Cloudflare's own description is 'Notifies the secondary nameserver(s) and clears IXFR backlog of primary zone'. Clearing the backlog is the destructive half: the incremental history the secondaries would have used is discarded, so each one has to pull the whole zone again, and a secondary that cannot complete a full AXFR keeps serving its old copy. The NOTIFY itself reaches the customer's own nameservers immediately. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/outgoing/force_notify. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete ACL. Why this is destructive: The account stops accepting zone-transfer traffic from that IP range. Every secondary zone relying on it for NOTIFY, and every primary zone relying on it to permit AXFR/IXFR, stops transferring - and because a stalled transfer keeps serving the last copy, the symptom is a zone that silently goes stale rather than an error. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. DELETE /accounts//secondary_dns/acls/. Path parameters: acl_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
aclIdstringyesRequired. The Secondary DNS ACL id from cf_list_secondary_dns_acls.

[Cloudflare] DESTRUCTIVE: Delete Peer. Why this is destructive: The peer is removed from the account and every zone whose peers array names it loses that transfer relationship: a secondary zone stops pulling from that primary, and a primary zone stops notifying that secondary. The zones keep serving the records they last had, so the failure shows up as stale data rather than an error. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. DELETE /accounts//secondary_dns/peers/. Path parameters: peer_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
peerIdstringyesRequired. The Secondary DNS peer id from cf_list_secondary_dns_peers - the same tag that appears in a zone's peers array.

[Cloudflare] DESTRUCTIVE: Delete TSIG. Why this is destructive: The shared secret is removed from the account. Any peer still naming this key as its tsig_id can no longer authenticate a transfer, so the zones behind it stop transferring and quietly go stale. Cloudflare never returns a deleted secret again, so a key removed by mistake has to be regenerated and reconfigured on BOTH sides. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. DELETE /accounts//secondary_dns/tsigs/. Path parameters: tsig_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tsigIdstringyesRequired. The TSIG key id from cf_list_secondary_dns_tsigs, and the same value a peer carries as tsig_id. It SELECTS the key; it is not the key's secret.

[Cloudflare] DESTRUCTIVE: Delete Secondary Zone Configuration. Why this is destructive: The zone stops being a secondary: Cloudflare no longer pulls from the primary, the peers list goes and the refresh schedule with it. The records already transferred stay, so the visible symptom is a zone frozen at its last transfer rather than a zone that disappears. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. DELETE /zones//secondary_dns/incoming. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete Primary Zone Configuration. Why this is destructive: The zone stops being a transfer source: every secondary loses its NOTIFY and its permission to pull, and each one keeps serving the copy it already holds. Because those secondaries usually answer for the domain alongside Cloudflare, the internet keeps getting the stale copy rather than an error. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. DELETE /zones//secondary_dns/outgoing. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Disable Outgoing Zone Transfers. Why this is destructive: Cloudflare's own description is 'Disable outgoing zone transfers for primary zone and clears IXFR backlog of primary zone'. Two things happen: the secondaries stop being served, and the IXFR backlog is discarded - so when transfers are enabled again the secondaries cannot pick up incrementally and need a full AXFR. Until they manage one, each keeps answering from the copy it already holds. cf_enable_zones_secondary_dns_outgoing turns it back on; the configuration and its peers are left alone by both. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/outgoing/disable. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Enable Outgoing Zone Transfers. Turns outgoing zone transfers back on for the zone. It is the reverse of cf_disable_zones_secondary_dns_outgoing and adds nothing to the configuration - the peers the zone already names start being notified and allowed to transfer again. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/outgoing/enable. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] ACL Details. Reads one ACL's name and ip_range. Worth doing before cf_set_secondary_dns_acl, which replaces the whole entry. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/acls/. Path parameters: acl_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
aclIdstringyesRequired. The Secondary DNS ACL id from cf_list_secondary_dns_acls.

[Cloudflare] Peer Details. Reads one peer's address, port, IXFR setting and the TSIG key id bound to it. Read it before cf_set_secondary_dns_peer, which replaces the peer wholesale. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/peers/. Path parameters: peer_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
peerIdstringyesRequired. The Secondary DNS peer id from cf_list_secondary_dns_peers - the same tag that appears in a zone's peers array.

[Cloudflare] TSIG Details. Reads one TSIG key. The response includes the secret in full, so treat the result as credential material and do not persist it. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/tsigs/. Path parameters: tsig_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tsigIdstringyesRequired. The TSIG key id from cf_list_secondary_dns_tsigs, and the same value a peer carries as tsig_id. It SELECTS the key; it is not the key's secret.

[Cloudflare] Secondary Zone Configuration Details. The INCOMING side: this zone as a SECONDARY that Cloudflare pulls from the customer's own primary nameservers. Returns the zone's auto_refresh_seconds and the peer tags it transfers from. cf_get_zones_secondary_dns_outgoing_config is the other direction. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Read or DNS Read on this zone. GET /zones//secondary_dns/incoming. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Primary Zone Configuration Details. The OUTGOING side: this zone as a PRIMARY that Cloudflare transfers out to the customer's own secondary nameservers. Returns the zone name and the peer tags Cloudflare NOTIFYs and answers AXFR/IXFR for. Mind the near-identical sibling - cf_get_zones_secondary_dns_outgoing_status, singular, reads the transfer STATUS at /outgoing/status, while this one reads the CONFIGURATION at /outgoing. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Read or DNS Read on this zone. GET /zones//secondary_dns/outgoing. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Get Outgoing Zone Transfer Status. The transfer STATUS for this zone as a primary - not its configuration. Cloudflare serves it at /outgoing/status, while cf_get_zones_secondary_dns_outgoing_config (plural) serves the configuration at /outgoing; the two tool names differ by one character, so check which one you want. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Read or DNS Read on this zone. GET /zones//secondary_dns/outgoing/status. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List ACLs. A Secondary DNS ACL is an account-wide IP range Cloudflare will accept zone-transfer traffic from: the extra NOTIFY sources allowed for secondary zones, and the addresses AXFR/IXFR requests may arrive from for primary zones. Start here - each entry's id is what the get, update and delete tools take. Cloudflare paginates nothing here: the whole collection comes back in one response. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/acls. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] List Peers. A Secondary DNS peer is the other nameserver in a transfer relationship: for a zone Cloudflare is SECONDARY for, the peer is the customer's primary that Cloudflare pulls AXFR/IXFR from; for a zone Cloudflare is PRIMARY for, it is the secondary Cloudflare NOTIFYs. Start here - each peer's id is the tag that goes into a zone's peers array. Cloudflare paginates nothing here: the whole collection comes back in one response. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/peers. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] List TSIGs. A TSIG key is the shared secret that authenticates a zone transfer between Cloudflare and a peer. Start here - each entry's id is what cf_set_secondary_dns_peer takes as tsig_id. Every entry includes its secret in full, so treat the result as credential material and do not persist it. Cloudflare paginates nothing here: the whole collection comes back in one response. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/tsigs. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DESTRUCTIVE: Update ACL. Why this is destructive: A PUT replaces the ACL outright and Cloudflare requires id, name and ip_range together, so every call rewrites the allowed range for the whole account. Narrowing or mistyping ip_range stops zone transfers from the addresses it used to permit, and those zones go stale rather than failing loudly. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. PUT /accounts//secondary_dns/acls/. Path parameters: acl_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
aclIdstringyesRequired. The Secondary DNS ACL id from cf_list_secondary_dns_acls.
bodyJsonstringyesSend the request body as JSON. Cloudflare requires all three of id (the ACL's own id, matching the path), name and ip_range. ip_range applies to the entire account and is capped at /24 for IPv4 and /64 for IPv6.

[Cloudflare] DESTRUCTIVE: Update Peer. Why this is destructive: A PUT replaces the peer from the body and Cloudflare requires only id and name, so leaving ip, port, ixfr_enable or tsig_id out CLEARS them. Dropping tsig_id is the one that bites: the transfer stops being TSIG-authenticated. Dropping ip leaves a peer that cannot transfer at all. Read cf_get_secondary_dns_peer first and send every field back. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. PUT /accounts//secondary_dns/peers/. Path parameters: peer_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON. id and name are required, and id is the peer's own id matching the path. ip is the peer nameserver's address - for a zone Cloudflare is secondary for it is the primary Cloudflare sends AXFR/IXFR to, and for a zone Cloudflare is primary for it is the secondary Cloudflare NOTIFYs. port is that nameserver's DNS port. ixfr_enable switches the transfer protocol from AXFR to IXFR and only applies to secondary zones. tsig_id binds a TSIG key from cf_list_secondary_dns_tsigs so the transfer is authenticated.
peerIdstringyesRequired. The Secondary DNS peer id from cf_list_secondary_dns_peers - the same tag that appears in a zone's peers array.

[Cloudflare] DESTRUCTIVE: Update TSIG. Why this is destructive: A PUT replaces the TSIG key and Cloudflare requires id, name, secret and algo together, so every call rewrites the shared secret. The moment it changes, every peer still configured with the old secret fails authentication and stops transferring - change it on the peer nameserver in the same maintenance window. The response echoes the new secret back. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. PUT /accounts//secondary_dns/tsigs/. Path parameters: tsig_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesSend the request body as JSON. Cloudflare requires all four of id, name, secret and algo. name is the TSIG key name as BOTH sides of the transfer know it, algo is the TSIG algorithm, and secret is the shared secret itself - the identical value has to be configured on the peer nameserver or the transfer fails authentication.
tsigIdstringyesRequired. The TSIG key id from cf_list_secondary_dns_tsigs, and the same value a peer carries as tsig_id. It SELECTS the key; it is not the key's secret.

[Cloudflare] DESTRUCTIVE: Update Secondary Zone Configuration. Why this is destructive: A PUT rewrites the zone's whole incoming transfer configuration, and peers is an ARRAY - a peer left out of it stops being a source for this zone. Drop them all and the zone stops refreshing entirely: it keeps serving the records it last pulled and silently goes stale rather than failing. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. PUT /zones//secondary_dns/incoming. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesSend the request body as JSON. Cloudflare requires id, name, peers and auto_refresh_seconds together, so every call rewrites all four. peers is the COMPLETE array of peer tags from cf_list_secondary_dns_peers, and auto_refresh_seconds is how often the zone refreshes regardless of DNS NOTIFY.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Update Primary Zone Configuration. Why this is destructive: A PUT rewrites the zone's whole outgoing transfer configuration, and peers is an ARRAY - a secondary left out of it stops being notified and stops being allowed to transfer, so it freezes at the copy it already holds while the zone keeps changing at Cloudflare. Since those secondaries usually answer for the domain alongside Cloudflare, the internet keeps getting the stale copy. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. PUT /zones//secondary_dns/outgoing. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesSend the request body as JSON. Cloudflare requires id, name and peers together, so every call rewrites all three. peers is the COMPLETE array of peer tags from cf_list_secondary_dns_peers.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

Account Analytics

ToolPlanAccessSummary
cf_get_user_analytics_dashboardsFreeRead-onlyGet user analytics dashboard.

[Cloudflare] Get user analytics dashboard. Cloudflare's named replacement is the GraphQL Analytics API (developers.cloudflare.com/analytics/graphql-api), which is where new work should go. Totals and time series aggregated across EVERY zone the token owner owns rather than one account, and only zones the user can read analytics for are counted. Omit since and until for the last seven days. GET /user/analytics/dashboard. Optional filters: since, until, continuous. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
continuousbooleannonullOptional. When set to true, the API will move the requested time window backward, until it finds a region with completely aggregated data.
sincestringnonullOptional. The (inclusive) beginning of the requested time frame.
untilstringnonullOptional. The (exclusive) end of the requested time frame.

Account Billable

ToolPlanAccessSummary
cf_get_account_billable_usageFreeRead-onlyGet Account Usage (Version 2, Alpha, Restricted).
cf_query_account_billable_usageFreeRead-onlyQuery Account Usage (Version 2, Alpha, Restricted).

[Cloudflare] Get Account Usage (Version 2, Alpha, Restricted). Cost and usage for ONE account in the FinOps FOCUS v1.3 shape: one record per billable metric per account per day, including metered usage that falls inside a free allowance and costs nothing. Cloudflare has NOT yet populated the cost and pricing fields, so they are absent from the response until its billing integration lands. Omit from and to for the current month to date; the widest range Cloudflare accepts is 31 days. The surface is Alpha and restricted, so an account that has not been enabled for it is refused. Use cf_query_account_billable_usage to filter or group the same data. GET /accounts//billable/usage. Path parameters: account_id. Optional filters: from, to. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Identifies the Cloudflare account.
fromstringnonullOptional. Start date for the usage query (ISO 8601).
tostringnonullOptional. End date for the usage query (ISO 8601).

[Cloudflare] Query Account Usage (Version 2, Alpha, Restricted). The filterable counterpart of cf_get_account_billable_usage on the same path. Cloudflare documents it as a READ-ONLY operation that needs only the billing:read permission - POST is used purely so the filter criteria can travel in a body - which is why StackJack ships it as a read. POST /accounts//billable/usage. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Identifies the Cloudflare account.
bodyJsonstringnonullOptional. A JSON request body with three members: TimePeriod (the date range to report on), FilterBy (narrow to accounts, services or tag keys) and GroupBy (the dimensions the totals are rolled up by). Omit the body for the current period, ungrouped.

Account Firewall

ToolPlanAccessSummary
cf_create_user_firewall_access_ruleProDestructiveDESTRUCTIVE: Create an IP Access rule.
cf_delete_user_firewall_access_ruleProDestructiveDESTRUCTIVE: Delete an IP Access rule.
cf_get_user_firewall_access_ruleFreeRead-onlyGet an IP Access rule.
cf_list_user_firewall_access_rulesFreeRead-onlyList IP Access rules.
cf_update_user_firewall_access_ruleProDestructiveDESTRUCTIVE: Update an IP Access rule.

[Cloudflare] DESTRUCTIVE: Create an IP Access rule. Why this is destructive: The rule takes effect on EVERY zone the token owner owns, immediately. A block or challenge rule aimed at the wrong address can shut real visitors - or the customer's own office - out of all of those domains at once, and a zone-level rule is the narrower tool when only one domain is meant. POST /user/firewall/access_rules/rules. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. configuration and mode are both required. configuration is {target, value}, where target is ip, ip6, ip_range, asn or country and value is the matching address, CIDR range, AS number or two-letter ISO-3166-1 alpha-2 country code - and Cloudflare accepts only /16 and /24 prefixes for an IPv4 range. mode is the action - block, challenge, js_challenge, managed_challenge or whitelist. notes is free text and is the only thing that will identify the rule later.

[Cloudflare] DESTRUCTIVE: Delete an IP Access rule. Why this is destructive: Removing a user-level rule lifts it from EVERY zone the token owner owns at once, so traffic the rule was blocking or challenging is served normally from the next request. Cloudflare keeps no copy - restoring it means creating it again. DELETE /user/firewall/access_rules/rules/. Path parameters: rule_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
ruleIdstringyesRequired. Unique identifier for a rule.

[Cloudflare] Get an IP Access rule. One user-level rule by id: the action it applies, what it matches and its notes. This is a USER-SCOPE endpoint: it answers for the token owner's own Cloudflare user, not for one account, and a token created under Manage Account cannot call it. GET /user/firewall/access_rules/rules/. Path parameters: rule_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
ruleIdstringyesRequired. Unique identifier for a rule.

[Cloudflare] List IP Access rules. USER-LEVEL IP Access rules, which is what makes this surface different from a zone's own firewall: one rule here applies to EVERY zone the token owner owns. Start here - the rule id the get, update and delete tools take comes from these rows. Each rule pairs a mode (the action) with a configuration (what it matches: an IP, a CIDR range, an AS number or a country code). This is a USER-SCOPE endpoint: it answers for the token owner's own Cloudflare user, not for one account, and a token created under Manage Account cannot call it. GET /user/firewall/access_rules/rules. Optional filters: mode, configuration.target, configuration.value, notes, match, page, per_page, order, direction. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
configurationTargetstringnonullOptional. Filter by what the rule matches on: ip, ip6, ip_range, asn or country.
configurationValuestringnonullOptional. Filter by the matched value itself - an IP address, a CIDR range, an AS number or a two-letter country code, matching the target you filtered on.
directionstringnonullOptional. Defines the direction used to sort returned rules.
matchstringnonullOptional. all requires every other filter to match; any accepts a rule matching at least one of them.
modestringnonullOptional. Filter by the action a rule applies: block, challenge, js_challenge, managed_challenge or whitelist.
notesstringnonullOptional. Defines the string to search for in the notes of existing IP Access rules.
orderstringnonullOptional. Defines the field used to sort returned rules.
pageintegernonullOptional. Defines the requested page within paginated list of results.
perPageintegernonullOptional. Defines the maximum number of results requested.

[Cloudflare] DESTRUCTIVE: Update an IP Access rule. Why this is destructive: Cloudflare accepts only two changes here - the action (mode) and the notes - and the new action applies to every zone the token owner owns from the next request. PATCH /user/firewall/access_rules/rules/. Path parameters: rule_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Only mode (block, challenge, js_challenge, managed_challenge, whitelist) and notes can be changed; what the rule MATCHES is fixed when it is created, so a wrong target means deleting the rule and creating a new one.
ruleIdstringyesRequired. Unique identifier for a rule.

Account Load Balancers

ToolPlanAccessSummary
cf_create_user_lb_monitorProWriteCreate Monitor.
cf_create_user_lb_poolProWriteCreate Pool.
cf_delete_user_lb_monitorProDestructiveDESTRUCTIVE: Delete Monitor.
cf_delete_user_lb_poolProDestructiveDESTRUCTIVE: Delete Pool.
cf_get_user_lb_monitorFreeRead-onlyMonitor Details.
cf_get_user_lb_poolFreeRead-onlyPool Details.
cf_get_user_lb_pool_healthFreeRead-onlyPool Health Details.
cf_get_user_lb_previewFreeRead-onlyPreview Result.
cf_get_user_lb_regionsFreeRead-onlyList Regions.
cf_list_user_lb_monitorsFreeRead-onlyList Monitors.
cf_list_user_lb_monitors_referencesFreeRead-onlyList Monitor References.
cf_list_user_lb_poolsFreeRead-onlyList Pools.
cf_list_user_lb_pools_referencesFreeRead-onlyList Pool References.
cf_preview_user_lb_monitorsFreeRead-onlyPreview Monitor.
cf_preview_user_lb_poolsFreeRead-onlyPreview Pool.
cf_set_user_lb_monitorProDestructiveDESTRUCTIVE: Update Monitor.
cf_set_user_lb_poolProDestructiveDESTRUCTIVE: Update Pool.
cf_update_user_lb_monitorProWritePatch Monitor.
cf_update_user_lb_pool_by_pool_idProDestructiveDESTRUCTIVE: Patch Pool.
cf_update_user_lb_poolsProWritePatch Pools.

[Cloudflare] Create Monitor. Additive: it creates one new health check and changes no pool. Nothing is probed until a pool references the monitor, but from that moment the check runs against that pool's origins on the interval you set. POST /user/load_balancers/monitors. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. The three fields that decide what is measured are type (http, https, tcp, udp_icmp, icmp_ping or smtp), the target (path plus expected_codes for an HTTP check, port for TCP) and interval with retries and timeout, which together set how fast an origin is declared down. expected_body, header, follow_redirects, allow_insecure and probe_zone refine the HTTP probe; description is free text.

[Cloudflare] Create Pool. Additive: it creates one new pool and changes no existing one. No traffic reaches it until a load balancer references the pool, but its health checks begin as soon as it exists. POST /user/load_balancers/pools. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. name and origins are required. origins is the field that matters most - each entry is {name, address, enabled, weight}, where address is the origin IP or hostname - and monitor names the health check that probes them. minimum_origins (default 1) decides when the whole pool is called unhealthy, notification_email is alerted when that happens, and check_regions, load_shedding, origin_steering and latitude/longitude shape which Cloudflare locations probe and steer to it.

[Cloudflare] DESTRUCTIVE: Delete Monitor. Why this is destructive: Any pool still pointing at this monitor loses its health check, so those origins stop being probed and stay at their last known state. Call cf_list_user_lb_monitors_references first to see what depends on it. DELETE /user/load_balancers/monitors/. Path parameters: monitor_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
monitorIdstringyesRequired. The monitor_id this call targets.

[Cloudflare] DESTRUCTIVE: Delete Pool. Why this is destructive: Any load balancer still steering to this pool loses those origins, so traffic fails over to its remaining pools - or to nothing, if this was the last one. Call cf_list_user_lb_pools_references first to see what depends on it. DELETE /user/load_balancers/pools/. Path parameters: pool_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
poolIdstringyesRequired. The pool_id this call targets.

[Cloudflare] Monitor Details. One user-scope monitor by id, with the probe type, target and timing that decide when an origin counts as down. These are USER-SCOPE load balancing objects, owned by the token owner rather than by one account; the account-scope equivalents are cf_list_lb_monitors and cf_list_lb_pools. GET /user/load_balancers/monitors/. Path parameters: monitor_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
monitorIdstringyesRequired. The monitor_id this call targets.

[Cloudflare] Pool Details. One user-scope pool by id, with its origins, the monitor that probes them and the address alerted when its health changes. These are USER-SCOPE load balancing objects, owned by the token owner rather than by one account; the account-scope equivalents are cf_list_lb_monitors and cf_list_lb_pools. GET /user/load_balancers/pools/. Path parameters: pool_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
poolIdstringyesRequired. The pool_id this call targets.

[Cloudflare] Pool Health Details. The latest health of ONE pool: the per-origin and per-region results of the pool's monitor. This is the read that answers "why is traffic failing over?". GET /user/load_balancers/pools//health. Path parameters: pool_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
poolIdstringyesRequired. The pool_id this call targets.

[Cloudflare] Preview Result. Collects the result of a preview started by cf_preview_user_lb_monitors or cf_preview_user_lb_pools, using the preview_id that call returned. The probes run asynchronously, so an immediate read can come back incomplete. GET /user/load_balancers/preview/. Path parameters: preview_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
previewIdstringyesRequired. The preview_id this call targets.

[Cloudflare] List Regions. The region map Cloudflare steers load balancing by - which countries and subdivisions sit in which region code (WNAM, ENAM, WEU, SEAS and the rest). It is reference data, the same for every customer, and it is what a pool's check_regions and a load balancer's region rules expect. Filter by country_code or subdivision_code to find the region one place belongs to. GET /user/load_balancers/regions. Optional filters: subdivision_code, country_code. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
countryCodestringnonullOptional. Two-letter alpha-2 country code as defined in ISO 3166-1.
subdivisionCodestringnonullOptional. Two-letter subdivision code followed in ISO 3166-2.

[Cloudflare] List Monitors. Start here for user-scope load balancing: a monitor is the health check a pool runs against its origins, and each row's id is the monitor_id every other monitor tool takes. These are USER-SCOPE load balancing objects, owned by the token owner rather than by one account; the account-scope equivalents are cf_list_lb_monitors and cf_list_lb_pools. This endpoint takes no paging parameters - the whole collection comes back in one response. GET /user/load_balancers/monitors. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

[Cloudflare] List Monitor References. Everything that points at this monitor - the pools whose health checking would change if you edited or deleted it. Call it before either. GET /user/load_balancers/monitors//references. Path parameters: monitor_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
monitorIdstringyesRequired. The monitor_id this call targets.

[Cloudflare] List Pools. Start here for user-scope pools: a pool is a named set of origins with a health check, and each row's id is the pool_id the other pool tools take. These are USER-SCOPE load balancing objects, owned by the token owner rather than by one account; the account-scope equivalents are cf_list_lb_monitors and cf_list_lb_pools. Filter by monitor to find the pools one health check governs. This endpoint takes no paging parameters - the whole collection comes back in one response. GET /user/load_balancers/pools. Optional filters: monitor. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
monitorstringnonullOptional. The ID of the Monitor to use for checking the health of origins within this pool.

[Cloudflare] List Pool References. Everything that points at this pool - the load balancers whose steering would change if you edited or deleted it. Call it before either. GET /user/load_balancers/pools//references. Path parameters: pool_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
poolIdstringyesRequired. The pool_id this call targets.

[Cloudflare] Preview Monitor. A simulation, not a change: Cloudflare runs the monitor settings in the body against the pools that use this monitor and hands back a preview_id. Nothing about the monitor or its pools is modified, which is why this POST ships as a read. Pass the preview_id to cf_get_user_lb_preview to collect the result. POST /user/load_balancers/monitors//preview. Path parameters: monitor_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON: the monitor settings to TRY, in the same shape as a monitor (type, path, expected_codes, interval, retries, timeout and the other probe fields). They are used for this preview only and are never saved.
monitorIdstringyesRequired. The monitor_id this call targets.

[Cloudflare] Preview Pool. A simulation, not a change: Cloudflare probes this pool's origins with the monitor settings in the body and hands back a preview_id, leaving the pool and its real monitor untouched - which is why this POST ships as a read. Pass the preview_id to cf_get_user_lb_preview. POST /user/load_balancers/pools//preview. Path parameters: pool_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON: the monitor settings to TRY against this pool's origins (type, path, expected_codes, interval, retries, timeout and the other probe fields). They are used for the preview only and nothing is saved.
poolIdstringyesRequired. The pool_id this call targets.

[Cloudflare] DESTRUCTIVE: Update Monitor. Why this is destructive: A PUT replaces the whole monitor from the body, so any field you leave out reverts to Cloudflare's default rather than keeping its current value - an omitted expected_codes or interval can silently change when the pools using this monitor call an origin down. Read cf_get_user_lb_monitor first and send the complete object, or use cf_update_user_lb_monitor to change one field. PUT /user/load_balancers/monitors/. Path parameters: monitor_id. Send the request body as JSON; Cloudflare documents these fields: allow_insecure, consecutive_down, consecutive_up, description, expected_body, expected_codes, follow_redirects, header, interval, method, path, port. Cloudflare documents 4 more fields; see its API docs. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: allow_insecure, consecutive_down, consecutive_up, description, expected_body, expected_codes, follow_redirects, header, interval, method, path, port, probe_zone, retries, timeout, type.
monitorIdstringyesRequired. The monitor_id this call targets.

[Cloudflare] DESTRUCTIVE: Update Pool. Why this is destructive: A PUT replaces the whole pool from the body: an origin you leave out of origins is REMOVED from the pool and stops receiving traffic, and every omitted setting reverts to its default. Read cf_get_user_lb_pool first and send the complete object, or use cf_update_user_lb_pool_by_pool_id for one field. PUT /user/load_balancers/pools/. Path parameters: pool_id. Send the request body as JSON; Cloudflare documents these fields: check_regions, description, disabled_at, enabled, health_sources, latitude, load_shedding, longitude, minimum_origins, monitor, monitor_group, name. Cloudflare documents 5 more fields; see its API docs. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: check_regions, description, disabled_at, enabled, health_sources, latitude, load_shedding, longitude, minimum_origins, monitor, monitor_group, name, networks, notification_email, notification_filter, origin_steering, origins. Cloudflare requires: name, origins.
poolIdstringyesRequired. The pool_id this call targets.

[Cloudflare] Patch Monitor. Partial update: Cloudflare applies only the fields you send and leaves the rest alone. The new probe settings are live on the next interval for every pool that references this monitor. PATCH /user/load_balancers/monitors/. Path parameters: monitor_id. Send the request body as JSON; Cloudflare documents these fields: allow_insecure, consecutive_down, consecutive_up, description, expected_body, expected_codes, follow_redirects, header, interval, method, path, port. Cloudflare documents 4 more fields; see its API docs. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: allow_insecure, consecutive_down, consecutive_up, description, expected_body, expected_codes, follow_redirects, header, interval, method, path, port, probe_zone, retries, timeout, type.
monitorIdstringyesRequired. The monitor_id this call targets.

[Cloudflare] DESTRUCTIVE: Patch Pool. Why this is destructive: Partial update of ONE pool, but origins is a list: sending it at all REPLACES the whole origin list rather than merging into it, so an origin you leave out stops receiving traffic immediately. Read cf_get_user_lb_pool first and send the complete list. PATCH /user/load_balancers/pools/. Path parameters: pool_id. Send the request body as JSON; Cloudflare documents these fields: check_regions, description, disabled_at, enabled, health_sources, latitude, load_shedding, longitude, minimum_origins, monitor, monitor_group, name. Cloudflare documents 4 more fields; see its API docs. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: check_regions, description, disabled_at, enabled, health_sources, latitude, load_shedding, longitude, minimum_origins, monitor, monitor_group, name, notification_email, notification_filter, origin_steering, origins.
poolIdstringyesRequired. The pool_id this call targets.

[Cloudflare] Patch Pools. This is the BATCH form and it carries no pool id: Cloudflare applies the body to EVERY pool the token owner owns and answers with the list it changed. Sending notification_email here rewrites who is alerted for all of them; cf_update_user_lb_pool_by_pool_id is the one-pool tool. PATCH /user/load_balancers/pools. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents one changeable field for the batch form - notification_email, the address alerted when a pool's health changes - and applies it to every pool the token owner owns.

Account Members

ToolPlanAccessSummary
cf_add_account_memberProDestructiveDESTRUCTIVE: Add Member.
cf_get_account_memberFreeRead-onlyMember Details.
cf_list_account_membersFreeRead-onlyList Members.
cf_remove_account_memberProDestructiveDESTRUCTIVE: Remove Member.
cf_update_account_memberProDestructiveDESTRUCTIVE: Update Member.

[Cloudflare] DESTRUCTIVE: Add Member. Why this is destructive: Grants a person access to the account with the roles you name. Cloudflare accepts one of TWO body shapes here and refuses a body that satisfies both: send email plus roles (a list of role ids from cf_list_account_roles), or email plus policies. Pick one and omit the other. status is optional and defaults to pending, which sends the invitation. POST /accounts//members. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: email, roles, status, policies. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: email, roles, status, policies.

[Cloudflare] Member Details. GET /accounts//members/. Path parameters: member_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
memberIdstringyesRequired. The account MEMBER id, as returned by cf_list_account_members. It is not the user id.

[Cloudflare] List Members. Who can reach this Cloudflare account and with which roles. The member id this returns is what the update and remove tools take, and it is NOT the user id. GET /accounts//members. Path parameters: account_id. Optional filters: order, status, page, per_page, direction. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
directionstringnonullOptional. Direction to order results.
orderstringnonullOptional. Field to order results by.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Maximum number of results per page.
statusstringnonullOptional. A member's status in the account.

[Cloudflare] DESTRUCTIVE: Remove Member. Why this is destructive: Removes the person from the account. DELETE /accounts//members/. Path parameters: member_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
memberIdstringyesRequired. The account MEMBER id, as returned by cf_list_account_members. It is not the user id.

[Cloudflare] DESTRUCTIVE: Update Member. Why this is destructive: Replaces the member role list wholesale, so this both grants and revokes privilege. Two body shapes, as on the add: send roles for a role-based member, or policies for a policy-based one, never both. This is a wholesale replace either way - whatever you send becomes the complete list, so read cf_get_account_member first and send the full set you want the member to end up with. PUT /accounts//members/. Path parameters: member_id, account_id. Send the request body as JSON; Cloudflare documents these fields: id, roles, status, user, policies. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: id, roles, status, user, policies.
memberIdstringyesRequired. The account MEMBER id, as returned by cf_list_account_members. It is not the user id.

Account Memberships

ToolPlanAccessSummary
cf_get_user_membershipFreeRead-onlyGet User Membership.

[Cloudflare] Get User Membership. One membership of the token owner - the link between this user and an account, with the roles it carries and whether the invitation is accepted or still pending. This is a USER-SCOPE endpoint: it answers for the token owner's own Cloudflare user, not for one account, and a token created under Manage Account cannot call it. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Memberships Write or Memberships Read permission rather than that the call is unsupported. GET /user/memberships/. Path parameters: membership_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
membershipIdstringyesRequired. The membership_id this call targets.

Account Organizations

ToolPlanAccessSummary
cf_delete_user_organizationProDestructiveDESTRUCTIVE: Leave Organization.
cf_get_user_organizationFreeRead-onlyOrganization Details.
cf_list_user_organizationsFreeRead-onlyList Organizations.

[Cloudflare] DESTRUCTIVE: Leave Organization. Why this is destructive: This is LEAVE ORGANIZATION: the token owner's own membership is removed, so that user loses everything the organization granted them and only an administrator who is still a member can invite them back. It does not delete the organization itself. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. DELETE /user/organizations/. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
organizationIdstringyesRequired. The organization_id this call targets.

[Cloudflare] Organization Details. One organization the token owner belongs to, with the membership status and permissions it carries. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /user/organizations/. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
organizationIdstringyesRequired. The organization_id this call targets.

[Cloudflare] List Organizations. Organizations are Cloudflare's older Enterprise-only account grouping; accounts are the current model, so cf_list_accounts is almost always the read you want. Cloudflare caps per_page at 50 here and StackJack clamps to that ceiling. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Memberships Write or Memberships Read permission rather than that the call is unsupported. GET /user/organizations. Optional filters: name, page, per_page, order, direction, match, status. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
directionstringnonullOptional. Direction to order organizations.
matchstringnonullOptional. Whether to match all search requirements or at least one (any).
namestringnonullOptional. Organization name.
orderstringnonullOptional. Field to order organizations by.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of organizations per page.
statusstringnonullOptional. Whether the user is a member of the organization or has an inivitation pending.

Account Profile

ToolPlanAccessSummary
cf_get_profilesFreeRead-onlyGet account profile.
cf_set_profileProDestructiveDESTRUCTIVE: Modify account profile.

[Cloudflare] Get account profile. The account's business profile - legal name, business address, business email and phone, plus the organization metadata Cloudflare holds against the account. It is also the cheapest read for confirming the token really reaches the account you think it does. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Trust and Safety Write or Trust and Safety Read or DNS View Write or DNS View Read or SCIM Provisioning or Load Balancers Account Write or Load Balancers Account Read or Zero Trust: PII Read or DDoS Botnet Feed Write or DDoS Botnet Feed Read or Workers R2 Storage Write or Workers R2 Storage Read or DDoS Protection Write or DDoS Protection Read or Workers Tail Read or Workers KV Storage Write or Workers KV Storage Read or Workers Scripts Write or Workers Scripts Read or Load Balancing: Monitors and Pools Write or Load Balancing: Monitors and Pools Read or Account Firewall Access Rules Write or Account Firewall Access Rules Read or DNS Firewall Write or DNS Firewall Read or Billing Write or Billing Read or Account Settings Write or Account Settings Read permission rather than that the call is unsupported. GET /accounts//profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DESTRUCTIVE: Modify account profile. Why this is destructive: A PUT replaces the whole profile and Cloudflare requires ALL of business_address, business_email, business_name, business_phone and external_metadata in the body, so anything you omit is not kept. The business email is where Cloudflare sends this account's correspondence, so a wrong value here sends the customer's account mail somewhere else. Read cf_get_profiles first and send every value back. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Account Settings Write permission rather than that the call is unsupported. PUT /accounts//profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON, and Cloudflare requires every member: business_address, business_email, business_name, business_phone and external_metadata. Read the current values with cf_get_profiles and send them back unchanged except for what you mean to change.

Account Settings

ToolPlanAccessSummary
cf_get_settings_ut_billingsFreeRead-onlyGet Unique Transformations billing setting.
cf_list_settings_transformationsFreeRead-onlyList Image Resizing configurations for account.
cf_update_settings_ut_billingProDestructiveDESTRUCTIVE: Change Unique Transformations billing setting.

[Cloudflare] Get Unique Transformations billing setting. Whether this account's image transformations are billed through the Unique Transformations pipeline. Read it before cf_update_settings_ut_billing, because that switch is one-way. GET /accounts//settings/ut-billing. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] List Image Resizing configurations for account. The Image Resizing (transformations) state of EVERY zone in the account in one response, which is the quick way to find the zones where it is switched on. Changing it for one zone is a zone-settings call, not this one. GET /accounts//settings/transformations. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DESTRUCTIVE: Change Unique Transformations billing setting. Why this is destructive: It changes how Cloudflare BILLS this account for image transformations, and Cloudflare does not permit the value to be set back to off once it has been enabled - so switching it on is a one-way change to the customer's invoice. Confirm the customer wants the Unique Transformations pricing model before sending it. PATCH /accounts//settings/ut-billing. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON with one required member, value, which switches the Unique Transformations billing pipeline on. Cloudflare's schema accepts exactly one value for it - on - and its own note says off is not permitted once the setting has been enabled, so there is no way back through this API.

Account Tokens

ToolPlanAccessSummary
cf_create_user_tokenProDestructiveDESTRUCTIVE: Create Token.
cf_delete_user_tokenProDestructiveDESTRUCTIVE: Delete Token.
cf_get_user_tokenFreeRead-onlyToken Details.
cf_list_user_tokensFreeRead-onlyList Tokens.
cf_list_user_tokens_permission_groupsFreeRead-onlyList Token Permission Groups.
cf_roll_user_tokenProDestructiveDESTRUCTIVE: Roll Token.
cf_set_user_tokenProDestructiveDESTRUCTIVE: Update Token.

[Cloudflare] DESTRUCTIVE: Create Token. Why this is destructive: It mints a live Cloudflare API credential that can act on everything its policies allow, from the moment it is created until it expires or is deleted. The value comes back exactly once - treat the response as a secret and keep it out of anything durable. The response carries the new token VALUE once and Cloudflare never shows it again, so capture it at that moment or roll the token later. Build policies from the permission group ids cf_list_user_tokens_permission_groups returns. POST /user/tokens. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. name and policies are both required. policies is what the token can DO: each entry pairs effect (allow or deny) with a permission_groups array of taken from cf_list_user_tokens_permission_groups and a resources map naming the accounts or zones it reaches. expires_on and not_before bound its lifetime, and condition carries the optional request.ip allow-list.

[Cloudflare] DESTRUCTIVE: Delete Token. Why this is destructive: The token stops authenticating immediately, so anything still using it - a script, a CI job, another integration - starts failing with 401 at once. Cloudflare cannot restore a deleted token; a replacement is a new token with a new value. DELETE /user/tokens/. Path parameters: token_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
tokenIdstringyesRequired. Token identifier tag.

[Cloudflare] Token Details. One token's policies, status, expiry and last-used time by id. It never returns the token value - Cloudflare shows that only when the token is created or rolled. GET /user/tokens/. Path parameters: token_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
tokenIdstringyesRequired. Token identifier tag.

[Cloudflare] List Tokens. The API tokens the token owner created, with their policies, status and expiry but never the token value itself. Each row's id is the token_id the get, update, roll and delete tools take. Set include_expired to include recently-expired tokens. Cloudflare caps per_page at 50 here and StackJack clamps to that ceiling. This is a USER-SCOPE endpoint: it answers for the token owner's own Cloudflare user, not for one account, and a token created under Manage Account cannot call it. GET /user/tokens. Optional filters: page, per_page, direction, include_expired. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
directionstringnonullOptional. Direction to order results.
includeExpiredbooleannonullOptional. When true, includes recently-expired tokens in the response.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Maximum number of results per page.

[Cloudflare] List Token Permission Groups. The catalog of permission groups a token policy can name - the id, name and scope of each. This is the read you make BEFORE cf_create_user_token, because a policy has to carry these ids. It returns names and identifiers only, never key material. GET /user/tokens/permission_groups. Optional filters: name, scope. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
namestringnonullOptional. Filter by the name of the permission group.
scopestringnonullOptional. Filter by the scope of the permission group.

[Cloudflare] DESTRUCTIVE: Roll Token. Why this is destructive: Rolling replaces the token's secret: the OLD value stops authenticating the moment Cloudflare answers, so every script, pipeline or integration still holding it fails with 401 until it is given the new value. That new value appears only in this response. The response body IS the new secret: result is the token string itself, and Cloudflare will never show it again. Capture it, store it, and update whatever was using the old value. PUT /user/tokens//value. Path parameters: token_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
tokenIdstringyesRequired. Token identifier tag.

[Cloudflare] DESTRUCTIVE: Update Token. Why this is destructive: A PUT replaces the token's whole definition, and policies is the part that bites: the array you send BECOMES what the token may do, so a policy left out is revoked the moment Cloudflare accepts the call and anything relying on it starts failing. Read cf_get_user_token first and send the complete set. Setting status to disabled switches the credential off without deleting it. PUT /user/tokens/. Path parameters: token_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. name and policies are required and the call is a wholesale replace: policies is the COMPLETE list of what the token may do (effect plus permission_groups and resources), status switches it between active and disabled, and expires_on / not_before bound its lifetime. Read the current token with cf_get_user_token and send it back with only your change applied.
tokenIdstringyesRequired. Token identifier tag.

Account Zones

ToolPlanAccessSummary
cf_get_zones_v1_images_flowsFreeRead-onlyGet transformation flows.
cf_set_zones_v1_images_flowProDestructiveDESTRUCTIVE: Update transformation flows.

[Cloudflare] Get transformation flows. The zone's image transformation flows - the named pipelines that decide which resizing and format transformations are allowed. Read it before writing: the write is a whole-document replace and it needs the version and etag this returns. GET /accounts//zones//v1/images/flows. Path parameters: accountId, zoneId. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Account identifier.
zoneIdstringyesRequired. Zone identifier.

[Cloudflare] DESTRUCTIVE: Update transformation flows. Why this is destructive: It replaces the zone's ENTIRE transformation flow configuration: a flow you leave out of the body is deleted, and image URLs that relied on it stop transforming. Read cf_get_zones_v1_images_flows first and send the full document back with your change, using the etag it returned so a concurrent edit by someone else is refused rather than overwritten. PUT /accounts//zones//v1/images/flows. Path parameters: accountId, zoneId. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Account identifier.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare requires flows and version inside it: flows is the COMPLETE set of transformation flows the zone should end up with - anything omitted is removed - and version is the document version. Send the etag from cf_get_zones_v1_images_flows to make the write conditional on nobody else having changed it.
zoneIdstringyesRequired. Zone identifier.

Accounts

ToolPlanAccessSummary
cf_create_accountProDestructiveDESTRUCTIVE: Create an account.
cf_delete_accountProDestructiveDESTRUCTIVE: Delete a specific account.
cf_get_accountFreeRead-onlyAccount Details.
cf_list_accountsFreeRead-onlyList Accounts.
cf_update_accountProDestructiveDESTRUCTIVE: Update Account.

[Cloudflare] DESTRUCTIVE: Create an account. Why this is destructive: Provisions a new billable Cloudflare account under the partner tenant. POST /accounts. Send the request body as JSON; Cloudflare documents these fields: name, type, unit. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: name, type, unit. Cloudflare requires: name.

[Cloudflare] DESTRUCTIVE: Delete a specific account. Why this is destructive: Deletes the whole account and everything in it. DELETE /accounts/. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The account ID of the account to be deleted.

[Cloudflare] Account Details. GET /accounts/. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] List Accounts. Start here: this is how an agent learns which Cloudflare accounts the stored API token can see, and the id each of the account-scoped tools needs. A token scoped to one account returns exactly that one. GET /accounts. Optional filters: name, page, per_page, direction. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
directionstringnonullOptional. Direction to order results.
namestringnonullOptional. Name of the account.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Maximum number of results per page.

[Cloudflare] DESTRUCTIVE: Update Account. Why this is destructive: Wholesale replace: the account settings block is rewritten from the body, so an omitted setting reverts to its default. PUT /accounts/. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: created_on, id, managed_by, name, settings, type. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: created_on, id, managed_by, name, settings, type. Cloudflare requires: id, name, type.

Activation Check

ToolPlanAccessSummary
cf_set_zones_activation_checkProDestructiveDESTRUCTIVE: Rerun the Activation Check.

[Cloudflare] DESTRUCTIVE: Rerun the Activation Check. Why this is destructive: It re-runs Cloudflare's own nameserver check against a PENDING zone, and a zone that passes goes active - which is the moment Cloudflare starts serving the domain, with whatever configuration is on the zone at that time. It changes nothing you authored and can be repeated, but Cloudflare rate-limits it to once every five minutes on paid zones and once an hour on Free ones. Only useful on a zone whose status is still pending: read cf_get_zone first. If the customer's registrar has not yet been pointed at the Cloudflare nameservers the check simply fails again. PUT /zones//activation_check. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. Zone ID.

Address Validation

ToolPlanAccessSummary
cf_create_address_validationFreeRead-onlyValidate Billing Address.

[Cloudflare] Validate Billing Address. A validation lookup, not a change: Cloudflare checks the address in the body against its address provider and answers with corrected suggestions, storing nothing - which is why this POST ships as a read. Cloudflare does not enforce authentication on it, so it also works before an account exists. Use it to clean an address before sending it to cf_create_billing_profile. POST /billing/address-validation. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON: address, address2, city, state, zipcode and country - the postal address to check. Cloudflare answers with the normalized form and any suggestions; nothing is saved.

API Tokens

ToolPlanAccessSummary
cf_verify_account_tokenFreeRead-onlyVerify Token.
cf_verify_user_tokenFreeRead-onlyVerify Token.

[Cloudflare] Verify Token. The account-owned equivalent of the personal token check. Use it when the token was created under Manage Account rather than My Profile; a personal token is refused here. GET /accounts//tokens/verify. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Verify Token. The cheapest way to answer "is this credential alive?" for a personal token. It reports the token status and, when one was set, its expiry. An ACCOUNT-OWNED token is refused here: use the account-scoped verify instead. GET /user/tokens/verify. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

Audit Logs

ToolPlanAccessSummary
cf_list_audit_logsFreeRead-onlyGet account audit logs.
cf_list_user_audit_logsFreeRead-onlyGet user audit logs.

[Cloudflare] Get account audit logs. Who changed what on this account and when - the first read for "why did this break?". Filter by actor.email or actor.ip for one person, by action.type for one kind of change, by zone.name for one domain, and by since/before for the window. hide_user_logs drops user-level entries. Cloudflare accepts up to 1000 entries a page here. GET /accounts//audit_logs. Path parameters: account_id. Optional filters: id, export, action.type, actor.ip, actor.email, since, before, zone.name, direction, per_page, page, hide_user_logs. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
actionTypestringnonullOptional. Filters by the action type.
actorEmailstringnonullOptional. Filters by the email address of the actor that made the change.
actorIpstringnonullOptional. Filters by the IP address of the request that made the change by specific IP address or valid CIDR Range.
beforestringnonullOptional. The before filter.
directionstringnonullOptional. Changes the direction of the chronological sorting.
exportbooleannonullOptional. True asks Cloudflare for a CSV export of the same query instead of the JSON page. The body comes back as the raw export, so prefer the default JSON unless a file is what you want.
hideUserLogsbooleannonullOptional. Indicates whether or not to hide user level audit logs.
idstringnonullOptional. Return the single audit entry with this id, ignoring the other filters.
pageintegernonullOptional. Defines which page of results to return.
perPageintegernonullOptional. Sets the number of results to return per page.
sincestringnonullOptional. The since filter.
zoneNamestringnonullOptional. Filters by the name of the zone associated to the change.

[Cloudflare] Get user audit logs. The same audit feed as cf_list_audit_logs, but for the TOKEN OWNER's own user rather than an account: it covers the user's actions across every account they belong to. Use the account-scoped tool when you are investigating one customer account. GET /user/audit_logs. Optional filters: id, export, action.type, actor.ip, actor.email, since, before, zone.name, direction, per_page, page, hide_user_logs. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
actionTypestringnonullOptional. Filters by the action type.
actorEmailstringnonullOptional. Filters by the email address of the actor that made the change.
actorIpstringnonullOptional. Filters by the IP address of the request that made the change by specific IP address or valid CIDR Range.
beforestringnonullOptional. The before filter.
directionstringnonullOptional. Changes the direction of the chronological sorting.
exportbooleannonullOptional. True asks Cloudflare for a CSV export of the same query instead of the JSON page. The body comes back as the raw export, so prefer the default JSON unless a file is what you want.
hideUserLogsbooleannonullOptional. Indicates whether or not to hide user level audit logs.
idstringnonullOptional. Return the single audit entry with this id, ignoring the other filters.
pageintegernonullOptional. Defines which page of results to return.
perPageintegernonullOptional. Sets the number of results to return per page.
sincestringnonullOptional. The since filter.
zoneNamestringnonullOptional. Filters by the name of the zone associated to the change.

Billable Usage

ToolPlanAccessSummary
cf_get_billable_usage_infoFreeRead-onlyGet Account Billable Usage Info (Version 1, Alpha).
cf_list_billable_usagesFreeRead-onlyGet Account Billable Usage (Version 1, Alpha).

[Cloudflare] Get Account Billable Usage Info (Version 1, Alpha). The header facts behind the usage feed: which period is covered, how complete the data is and the subscription metadata it is measured against. Read it first to learn whether cf_list_billable_usages will answer for the window you care about. GET /accounts//billable-usage/info. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Identifies the Cloudflare account.

[Cloudflare] Get Account Billable Usage (Version 1, Alpha). Version 1 of the billable-usage feed, which Cloudflare marks Alpha. With no from/to it returns the CURRENT billing period. cf_get_account_billable_usage is the newer FOCUS v1.3 dataset on a different path; read both before trusting either for an invoice reconciliation. GET /accounts//billable-usage. Path parameters: account_id. Optional filters: from, to. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Identifies the Cloudflare account.
fromstringnonullOptional. Start date for the usage query (ISO 8601).
tostringnonullOptional. End date for the usage query (ISO 8601).

Billing

ToolPlanAccessSummary
cf_create_billing_profileProWriteCreate Billing Profile.
cf_create_billing_profile_payment_methodProWriteCreate Payment Intent for Billing Profile.
cf_delete_billing_profileProDestructiveDESTRUCTIVE: Delete Billing Profile.
cf_get_account_billing_historyFreeRead-onlyGet Account Billing History.
cf_get_account_billing_usageFreeRead-onlyGet account billing usage.
cf_get_billing_bad_debtsFreeRead-onlyGet Account Bad Debt.
cf_get_billing_creditsFreeRead-onlyGet Account Credits.
cf_get_billing_profilesFreeRead-onlyGet Billing Profile.
cf_get_billing_unpaid_invoicesFreeRead-onlyGet Unpaid Invoices.
cf_get_user_billing_historyFreeRead-onlyBilling History Details.
cf_get_user_billing_profilesFreeRead-onlyBilling Profile Details.
cf_set_billing_profileProDestructiveDESTRUCTIVE: Update Billing Profile.
cf_update_billing_profileProWriteUpdate Billing Email.

[Cloudflare] Create Billing Profile. Additive: it gives an account that has none a billing identity. The fields decide who is invoiced and at what tax treatment, so an error here reaches the customer's invoice rather than their configuration. POST /accounts//billing/profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. The fields that matter are billing_email (who is invoiced), first_name/last_name plus company, the postal address (address, address2, city, state, zipcode, country) and the tax identity (vat with tax_id_type) - Cloudflare uses the country and tax id to decide the tax treatment. buying_rate_plan names the plan being bought. The captcha members (h_captcha_response, cf_turnstile_response, captcha_challenge_jwt) exist for Cloudflare's own signup form and are not needed on an API-token call.

[Cloudflare] Create Payment Intent for Billing Profile. Additive: it mints a Stripe payment intent and attaches no payment method on its own. The client_secret in the response can complete a card attachment in a browser, so treat it as short-lived secret material and do not put it anywhere durable. It starts Stripe's payment-method flow: Cloudflare creates a Stripe payment intent and answers with intent_type and a client_secret that a browser checkout page needs to confirm the card. Nothing is charged and no payment method is attached until that flow finishes somewhere else, so an agent calling this alone achieves nothing - and the client_secret it hands back is live Stripe material, not a Cloudflare credential. POST /accounts//billing/profile/payment-method. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DESTRUCTIVE: Delete Billing Profile. Why this is destructive: The account's billing identity goes with it - the billing email Cloudflare invoices, the business address and the tax details - so invoicing and any renewal that needs them start failing. Read cf_get_billing_profiles first and keep the values; re-creating the profile means entering them all again. DELETE /accounts//billing/profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get Account Billing History. The account's billing history - the charges and payments Cloudflare has recorded, newest first, filterable by status. This is the account-scope history; cf_get_user_billing_history is the deprecated user-scope one. GET /accounts//billing/history. Path parameters: account_id. Optional filters: page, per_page, status. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of items per page.
statusstringnonullOptional. Filter billing history by status.

[Cloudflare] Get account billing usage. DEPRECATED by Cloudflare in its API document: billing usage analytics as a time series across the billable products (Stream, Images, Rate Limiting, Load Balancing, Argo, Workers, Workers KV, Image Resizing and Spectrum). Cloudflare accepts limit up to 10000 data points but StackJack clamps it to 1000 per call; narrow the window with since/until instead. Needs an API token with Billing Read. GET /accounts//billing/usage. Path parameters: account_id. Optional filters: metrics, since, until, time_delta, limit, filters. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Standard Cloudflare hex account identifier.
filtersstringnonullOptional. Filter expressions to apply to the query.
limitintegernonullOptional. Maximum number of data points to return.
metricsstringnonullOptional. Comma-separated list of metrics to include in the response.
sincestringnonullOptional. Start of the time range for the query (inclusive).
timeDeltastringnonullOptional. Time unit to aggregate usage observations into.
untilstringnonullOptional. End of the time range for the query (inclusive).

[Cloudflare] Get Account Bad Debt. What the account owes that Cloudflare has written to bad debt: the outstanding invoices and the total. An account in bad debt can have services suspended, so this is worth reading before debugging "why did this stop working". GET /accounts//billing/bad-debt. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get Account Credits. The account's credit balance and whether it is eligible for credit. Credits are applied before a payment method is charged. GET /accounts//billing/credits. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get Billing Profile. The account's billing profile: who is invoiced (billing_email plus secondary_billing_email), the business name and address behind the invoice, the tax id and the preferred locale. Read it before any billing write - both the PUT and the profile creates want these values back. GET /accounts//billing/profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get Unpaid Invoices. The invoices Cloudflare is still waiting to be paid for this account, with the amounts. Pair it with cf_create_pay_invoice, which takes an invoice_id from here. GET /accounts//billing/unpaid-invoice. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Billing History Details. The TOKEN OWNER's own billing history rather than an account's. Cloudflare caps per_page at 50 here and StackJack clamps to that ceiling; cf_get_account_billing_history is the account-scope read that replaces it. GET /user/billing/history. Optional filters: page, per_page, order, occurred_at, type, action. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
actionstringnonullOptional. The billing item action.
occurredAtstringnonullOptional. When the billing item was created.
orderstringnonullOptional. Field to order billing history by.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of items per page.
typestringnonullOptional. The billing item type.

[Cloudflare] Billing Profile Details. The TOKEN OWNER's own billing profile rather than an account's. cf_get_billing_profiles is the account-scope read that replaces it. GET /user/billing/profile. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

[Cloudflare] DESTRUCTIVE: Update Billing Profile. Why this is destructive: A PUT replaces the WHOLE billing profile: an omitted billing_email, address or tax id is cleared rather than kept, which lands directly on the customer's next invoice. Read cf_get_billing_profiles first and send the full object back, or use cf_update_billing_profile when the change is only the billing email or locale. PUT /accounts//billing/profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON and it REPLACES the profile. Send the whole object back from cf_get_billing_profiles with your change applied: billing_email and secondary_billing_email, first_name/last_name and company, the postal address (address, address2, city, state, zipcode, country), the tax identity (vat, tax_id_type), preferred_locale and buying_rate_plan. The captcha members belong to Cloudflare's own signup form and are not needed here.

[Cloudflare] Update Billing Email. This is the narrow, safe billing write: Cloudflare changes only the billing email addresses and the preferred locale, and leaves the rest of the profile alone. It does change WHERE the customer's invoices are sent, so confirm the address. PATCH /accounts//billing/profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON with up to three members: billing_email (the address Cloudflare invoices), secondary_billing_email (a copy recipient) and preferred_locale. Anything else in the profile is changed through cf_set_billing_profile.

Communication Preferences

ToolPlanAccessSummary
cf_get_user_communication_preferencesFreeRead-onlyGet communication preferences.
cf_set_user_communication_preferenceProDestructiveDESTRUCTIVE: Update communication preferences.

[Cloudflare] Get communication preferences. What the token owner has agreed to receive from Cloudflare: whether the email address is verified, the marketing opt-in state and the language locale. Read it before writing - the write is a replace. GET /user/communication_preferences. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

[Cloudflare] DESTRUCTIVE: Update communication preferences. Why this is destructive: A PUT replaces the preference set from the body, so a preference you leave out reverts to Cloudflare's default rather than keeping the person's current choice - and these are a person's marketing and language consents. Read cf_get_user_communication_preferences first and send the full set back. PUT /user/communication_preferences. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON with two members: preferences, the COMPLETE set of communication opt-ins the user should end up with, and language-locale, one of Cloudflare's ten supported locales (en-US, es-ES, de-DE, fr-FR, it-IT, ja-JP, ko-KR, pt-BR, zh-CN, zh-TW). Anything omitted from preferences reverts to Cloudflare's default.

Diagnostics

ToolPlanAccessSummary
cf_create_diagnostics_endpoint_healthcheckProWriteEndpoint Health Check.
cf_create_diagnostics_tracerouteProWriteTraceroute.
cf_delete_diagnostics_endpoint_healthcheckProDestructiveDESTRUCTIVE: Delete Endpoint Health Check.
cf_get_diagnostics_endpoint_healthcheckFreeRead-onlyGet Endpoint Health Check.
cf_get_diagnostics_endpoint_healthchecksFreeRead-onlyList Endpoint Health Checks.
cf_set_diagnostics_endpoint_healthcheckProDestructiveDESTRUCTIVE: Update Endpoint Health Check.

[Cloudflare] Endpoint Health Check. Additive: it creates one new probe and changes no existing check. Cloudflare begins probing the endpoint you name as soon as it exists, so point it at an address the customer owns. POST /accounts//diagnostics/endpoint-healthchecks. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. check_type and endpoint are required: check_type is the probe (icmp, tcp or udp) and endpoint is the address to probe. name is free text and is what will identify the check later.

[Cloudflare] Traceroute. It dispatches live traceroutes from the Cloudflare data centres you name toward the targets in the body and answers with the hops. Nothing in the customer's configuration changes, but real probe packets leave Cloudflare's network toward whatever you put in targets - so only name hosts the customer owns or is entitled to probe. Cloudflare gates this endpoint to Enterprise accounts and asks for an API token with Magic Transit Write; on any other plan it is refused. POST /accounts//diagnostics/traceroute. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. targets is required and is the list of hostnames or IP addresses to trace to. colos names the Cloudflare data centres the traceroute runs FROM (omit for Cloudflare's default set), and options carries the packet settings - packets_per_ttl, max_ttl, packet_type, wait_time and port.

[Cloudflare] DESTRUCTIVE: Delete Endpoint Health Check. Why this is destructive: Cloudflare stops probing that endpoint, so the health signal anything downstream was reading simply stops. There is no undo; re-create the check to restore it. DELETE /accounts//diagnostics/endpoint-healthchecks/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. UUID.

[Cloudflare] Get Endpoint Health Check. One endpoint health check by id, with the probe type and the address it targets. Cloudflare gates this endpoint to Enterprise accounts and asks for an API token with Magic Transit Write; on any other plan it is refused. GET /accounts//diagnostics/endpoint-healthchecks/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. UUID.

[Cloudflare] List Endpoint Health Checks. The account's endpoint health checks - Cloudflare-run probes of a customer endpoint, used with Magic Transit and Magic WAN. Each row's id is what the get, update and delete tools take. Cloudflare gates this endpoint to Enterprise accounts and asks for an API token with Magic Transit Write; on any other plan it is refused. This endpoint takes no paging parameters - the whole collection comes back in one response. GET /accounts//diagnostics/endpoint-healthchecks. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DESTRUCTIVE: Update Endpoint Health Check. Why this is destructive: A PUT replaces the whole check from the body, so an omitted name is cleared and an omitted check_type or endpoint is refused. Read the check first and send it back complete. PUT /accounts//diagnostics/endpoint-healthchecks/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON and it REPLACES the check: check_type (icmp, tcp or udp) and endpoint are required, name is optional and is dropped if you leave it out.
idstringyesRequired. UUID.

Entitlements

ToolPlanAccessSummary
cf_list_entitlementsFreeRead-onlyGet Account Entitlements.
cf_list_zones_entitlementsFreeRead-onlyGet Zone Entitlements.

[Cloudflare] Get Account Entitlements. What this account is actually entitled to use: one row per product feature with the allocation that governs it (a boolean, a count, a range, an enum or a string). It is the read that explains a 403 on some other tool - if the feature is not entitled here, the call will not work whatever the token allows. GET /accounts//entitlements. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Identifier of the account.

[Cloudflare] Get Zone Entitlements. The same entitlement list as cf_list_entitlements, resolved for ONE zone: the features and allocations that zone may use. Read it when a zone-scoped call is refused and you want to know whether it is the plan rather than the token. GET /zones//entitlements. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. Identifier of the zone.

Flagship

ToolPlanAccessSummary
cf_create_flagship_appProWriteCreate app.
cf_create_flagship_apps_evaluateFreeRead-onlyEvaluate flag (POST).
cf_create_flagship_apps_flagProWriteCreate flag.
cf_delete_flagship_appProDestructiveDESTRUCTIVE: Delete app.
cf_delete_flagship_apps_flagProDestructiveDESTRUCTIVE: Delete flag.
cf_get_flagship_appFreeRead-onlyGet app.
cf_get_flagship_apps_flagFreeRead-onlyGet flag.
cf_list_flagship_appsFreeRead-onlyList apps.
cf_list_flagship_apps_definitionsFreeRead-onlyGet flag definitions.
cf_list_flagship_apps_evaluatesFreeRead-onlyEvaluate flag.
cf_list_flagship_apps_flagsFreeRead-onlyList flags.
cf_list_flagship_apps_flags_changelogsFreeRead-onlyGet flag changelog.
cf_set_flagship_appProDestructiveDESTRUCTIVE: Update app.
cf_set_flagship_apps_flagProDestructiveDESTRUCTIVE: Update flag.

[Cloudflare] Create app. Additive: it creates one new flag container and changes nothing that exists. The id it returns is what every other Flagship tool takes. POST /accounts//flagship/apps. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON with one required member, name, the app's display name. The id Cloudflare assigns is what later calls use.

[Cloudflare] Evaluate flag (POST). The POST form of the flag evaluation: same answer as cf_list_flagship_apps_evaluates, but the context travels as an OFREP-shaped JSON body, so its values keep their types instead of being flattened to strings. It evaluates and returns - no flag, app or rollout is changed - which is why it ships as a read. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. POST /accounts//flagship/apps//evaluate. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.
bodyJsonstringyesRequired. The request body as JSON, OFREP-shaped. flagKey is required and names the flag; context carries the evaluation attributes (including targetingKey, the identity a percentage rollout buckets on) with their real JSON types.

[Cloudflare] Create flag. Additive: it adds one flag to the app and changes no existing flag. The flag is live for evaluation as soon as Cloudflare stores it, so an enabled flag with a rollout rule starts serving its variations immediately. Cloudflare answers 409 if the key already exists. POST /accounts//flagship/apps//flags. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare requires default_variation, enabled, key, rules and variations. variations is the set of values the flag can serve (boolean, string, number or json) and default_variation names the one served when no rule matches; rules is the ORDERED list of targeting and percentage-rollout conditions, each condition an attribute with an operator (equals, not_equals, greater_than, less_than, contains, starts_with, ends_with, in, not_in and their variants) joined by AND or OR; enabled switches the whole flag on. type is inferred from the variation values - Cloudflare ignores a type you send.

[Cloudflare] DESTRUCTIVE: Delete app. Why this is destructive: It deletes the app AND every flag in it AND the whole changelog history, and Cloudflare refuses with 409 only while a Worker still binds to the app - so once the binding is gone the flags go with it and SDKs fall back to their caller-supplied defaults. There is no undo. DELETE /accounts//flagship/apps/. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.

[Cloudflare] DESTRUCTIVE: Delete flag. Why this is destructive: Cloudflare deletes the flag permanently and says so: every later evaluation falls back to the default the CALLING code supplies, which is usually the off state, so any behaviour behind the flag changes at once. It cannot be undone. DELETE /accounts//flagship/apps//flags/. Path parameters: account_id, app_id, flag_key. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.
flagKeystringyesRequired. Flag key (slug).

[Cloudflare] Get app. One app's name and audit fields by id. Flag definitions are not included. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps/. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.

[Cloudflare] Get flag. The full definition of one flag - variations, default_variation, the ordered rules and the audit fields. Read it before cf_set_flagship_apps_flag, which replaces the lot. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps//flags/. Path parameters: account_id, app_id, flag_key. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.
flagKeystringyesRequired. Flag key (slug).

[Cloudflare] List apps. Start here for Flagship: an app is the container a set of feature flags live in, and each row's id is the app_id every flag, changelog and evaluation tool takes. Identity and audit fields only - the flags themselves come from cf_list_flagship_apps_flags. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get flag definitions. The evaluation-only copy of the app's flag definitions, the shape an SDK that evaluates locally consumes. Send the ETag from a previous response in ifNoneMatch and Cloudflare answers 304 when nothing has changed instead of re-sending the document. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps//definitions. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.
ifNoneMatchstringnonullOptional. Previously returned ETag, or `*`. Sent as the If-None-Match request header.

[Cloudflare] Evaluate flag. Evaluates ONE flag for one context and answers with the variation that flag would serve. flagKey is REQUIRED even though the argument is optional in this tool's signature, and targetingKey is the identity a percentage rollout buckets on. Cloudflare forwards every context value as a string here; cf_create_flagship_apps_evaluate takes a typed JSON context instead. For in-Worker evaluation Cloudflare recommends the Flagship binding over either. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps//evaluate. Path parameters: account_id, app_id. Cloudflare REQUIRES this query parameter and answers 400 without it: flagKey. Optional filters: targetingKey. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.
flagKeystringnonullRequired by Cloudflare - the call fails without it. REQUIRED by Cloudflare even though this argument is optional in the signature - the call is refused without it. The key of the flag to evaluate, as returned by cf_list_flagship_apps_flags.
targetingKeystringnonullOptional. The OpenFeature targeting key: the stable identity (a user or account id) a percentage rollout buckets on. The same key always lands in the same bucket.

[Cloudflare] List flags. The app's flags, ordered by key, with their variations and rules. Paging is CURSOR-based: take cursor from result_info and pass it back for the next page; a null cursor means the last page. limit is a string Cloudflare accepts from 1 to 200 and StackJack passes it through unchanged, so the generic page-size sentence below does not apply here. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps//flags. Path parameters: account_id, app_id. Optional filters: limit, cursor. Cloudflare declares this endpoint's page size as a string, so StackJack sends the value verbatim and applies no ceiling of its own. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.
cursorstringnonullOptional. The cursor from the previous response's result_info. Omit it for the first page; a null cursor in the response means there are no more.
limitstringnonullOptional. How many flags to return, 1 to 200, sent verbatim as Cloudflare declares it (a string).

[Cloudflare] Get flag changelog. Who changed this flag and how, newest first: each entry carries the event type and the full flag state after the change, and an update entry also carries a field-level diff. Cloudflare keeps at most 200 entries per flag. Paging is CURSOR-based - pass cursor from result_info - and limit is a string from 1 to 200 that StackJack passes through unchanged, so the generic page-size sentence below does not apply. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps//flags//changelog. Path parameters: account_id, app_id, flag_key. Optional filters: limit, cursor. Cloudflare declares this endpoint's page size as a string, so StackJack sends the value verbatim and applies no ceiling of its own. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.
cursorstringnonullOptional. The cursor from the previous response's result_info. Omit it for the first page; a null cursor in the response means there are no more.
flagKeystringyesRequired. Flag key (slug).
limitstringnonullOptional. How many changelog entries to return, 1 to 200, sent verbatim as Cloudflare declares it (a string).

[Cloudflare] DESTRUCTIVE: Update app. Why this is destructive: Cloudflare treats only name as mutable here, so this is a rename - the flags in the app are not touched. It is still a PUT, so send the object rather than a fragment. PUT /accounts//flagship/apps/. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.
bodyJsonstringyesRequired. The request body as JSON. Only name is mutable; Cloudflare ignores anything else you send.

[Cloudflare] DESTRUCTIVE: Update flag. Why this is destructive: It replaces the ENTIRE flag definition and Cloudflare is explicit that omitted fields are dropped rather than preserved: a rule or a variation you leave out disappears, and the next evaluation serves something else. Read cf_get_flagship_apps_flag first and send the complete object back. Each write appends a changelog entry. PUT /accounts//flagship/apps//flags/. Path parameters: account_id, app_id, flag_key. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. App identifier.
bodyJsonstringyesRequired. The request body as JSON and it REPLACES the flag: Cloudflare requires default_variation, enabled, key, rules and variations, and drops anything you omit - a targeting rule or a variation left out of the body disappears. Read the current definition with cf_get_flagship_apps_flag and send it back with only your change applied.
flagKeystringyesRequired. Flag key (slug).

Hold

ToolPlanAccessSummary
cf_create_zones_holdProWriteCreate Zone Hold.
cf_delete_zones_holdProDestructiveDESTRUCTIVE: Remove Zone Hold.
cf_get_zones_holdFreeRead-onlyGet Zone Hold by Zone Name.
cf_get_zones_holdsFreeRead-onlyGet Zone Hold.
cf_update_zones_holdProWriteUpdate Zone Hold.

[Cloudflare] Create Zone Hold. Additive and reversible: it turns the hold on, blocking the creation or activation of any zone with this hostname anywhere in Cloudflare - including in the customer's own other accounts, which is the usual surprise. Cloudflare refuses a hold on a CDN-only zone. cf_delete_zones_hold lifts it. POST /zones//hold. Path parameters: zone_id. Optional filters: include_subdomains. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
includeSubdomainsbooleannonullOptional. True extends the hold to every subdomain of this zone and to SSL for SaaS custom hostnames under it, so none of them can be added as a zone elsewhere either.
zoneIdstringyesRequired. Zone ID.

[Cloudflare] DESTRUCTIVE: Remove Zone Hold. Why this is destructive: It stops enforcing the hold, so from that moment ANY Cloudflare account can add or activate a zone with this hostname - including someone outside the customer's organization. Pass hold_after to suspend it until a time instead, which is the safer form when you only need a window to move the domain. DELETE /zones//hold. Path parameters: zone_id. Optional filters: hold_after. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
holdAfterstringnonullOptional. An RFC3339 time at which Cloudflare re-enables the hold automatically. With it the hold is only SUSPENDED until then; without it the hold is removed for good.
zoneIdstringyesRequired. Zone ID.

[Cloudflare] Get Zone Hold by Zone Name. Whether a given HOSTNAME is blocked by a hold, including a hold on an ancestor domain that was created with include_subdomains - which is what makes it different from cf_get_zones_holds, the read for the zone itself. Cloudflare uses this call internally during zone activation, so it is the read that explains "this domain cannot be added". GET /zones//hold/. Path parameters: zone_id, zone_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. Zone identifier.
zoneNamestringyesRequired. The hostname to check for a zone hold.

[Cloudflare] Get Zone Hold. Whether THIS zone is held, and the hold's metadata (when it was created and whether it covers subdomains). A zone hold is the lock that stops anyone else adding this hostname to Cloudflare - the protection against a domain being claimed in another account. cf_get_zones_hold is the other read: it answers for a HOSTNAME, following ancestor domains. GET /zones//hold. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. Zone ID.

[Cloudflare] Update Zone Hold. Partial update of an existing hold: hold_after schedules when enforcement resumes and include_subdomains widens or narrows what it covers. Setting hold_after to a time in the PAST means the hold is enforced now, and setting it to null on a CDN-only zone removes the hold entirely. PATCH /zones//hold. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. hold_after is an RFC3339 time: the hold stays suspended until then, and a value in the past means it is enforced immediately. include_subdomains extends the hold to every subdomain and to SSL for SaaS custom hostnames under this zone.
zoneIdstringyesRequired. Zone ID.

Invites

ToolPlanAccessSummary
cf_get_user_inviteFreeRead-onlyInvitation Details.
cf_list_user_invitesFreeRead-onlyList Invitations.
cf_update_user_inviteProDestructiveDESTRUCTIVE: Respond to Invitation.

[Cloudflare] Invitation Details. One invitation by id: which account and organization sent it, the roles it carries and whether it is still pending. Account invitations are Enterprise-gated in Cloudflare's own plan availability and need an API token with a Memberships permission group. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Memberships Write or Memberships Read permission rather than that the call is unsupported. GET /user/invites/. Path parameters: invite_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
inviteIdstringyesRequired. Invite identifier tag.

[Cloudflare] List Invitations. The account invitations waiting for the TOKEN OWNER - the accounts this user has been asked to join, with each invitation's id and status. It is the token owner's own inbox, not an account's outgoing invitation list; cf_list_account_members shows an account's members and their pending state. Account invitations are Enterprise-gated in Cloudflare's own plan availability and need an API token with a Memberships permission group. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Memberships Write or Memberships Read permission rather than that the call is unsupported. GET /user/invites. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

[Cloudflare] DESTRUCTIVE: Respond to Invitation. Why this is destructive: This is how an invitation is ACCEPTED or REJECTED, and it decides account access: accepting makes the token owner a member of that account with the roles the invitation carries, rejecting closes it and only a new invitation from an administrator can reopen it. It acts for the token owner, not for a person you name. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Memberships Write permission rather than that the call is unsupported. PATCH /user/invites/. Path parameters: invite_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON with one required member, status: accepted joins the account with the roles the invitation carries, rejected declines it for good.
inviteIdstringyesRequired. Invite identifier tag.

Invoices

ToolPlanAccessSummary
cf_update_invoiceProWriteToggle PDF Invoices.

[Cloudflare] Toggle PDF Invoices. A reversible account preference: it switches PDF invoice generation on or off for this account. It changes what Cloudflare sends the customer, not what they are charged. PATCH /accounts//invoices. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON with one member, toggle, which turns PDF invoice generation on or off for the account.

IPs

ToolPlanAccessSummary
cf_get_ipsFreeRead-onlyCloudflare/JD Cloud IP Details.

[Cloudflare] Cloudflare/JD Cloud IP Details. Cloudflare's own published edge IP ranges - the addresses customer origins should allow. Public reference data, identical for every customer and not tied to the account the token belongs to. Pass networks=jdcloud for the JD Cloud ranges used by the China network. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /ips. Optional filters: networks. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
networksstringnonullOptional. Specified as `jdcloud` to list IPs used by JD Cloud data centers.

Live

ToolPlanAccessSummary
cf_check_livenessFreeRead-onlyRun liveness checks.

[Cloudflare] Run liveness checks. Cloudflare's own liveness probe for the API: it answers a success message and says nothing about the customer's account, so it is only useful for telling an API outage apart from a permissions problem. cf_verify_account_token is the right read for "is our credential alive?". GET /live. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

Load Balancing Analytics

ToolPlanAccessSummary
cf_list_user_lb_analytics_eventsFreeRead-onlyList Healthcheck Events.

[Cloudflare] List Healthcheck Events. Origin and pool health CHANGES over a window - when an origin went down, when a pool recovered - for the token owner's user-scope load balancing. This is the history behind cf_get_user_lb_pool_health, which only shows the latest state. Filter by pool_id or pool_name, by origin_name, and by origin_healthy / pool_healthy to see only the failures. GET /user/load_balancing_analytics/events. Optional filters: until, pool_name, origin_healthy, pool_id, since, origin_name, pool_healthy. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
originHealthybooleannonullOptional. True returns only events where the origin ended HEALTHY, false only those where it ended unhealthy. Omit it to see both.
originNamestringnonullOptional. The name for the origin to filter.
poolHealthybooleannonullOptional. True returns only events where the pool ended HEALTHY, false only those where it ended unhealthy. Omit it to see both.
poolIdstringnonullOptional. The pool_id filter.
poolNamestringnonullOptional. The name for the pool to filter.
sincestringnonullOptional. Start date and time of requesting data period in the ISO8601 format.
untilstringnonullOptional. End date and time of requesting data period in the ISO8601 format.

Move

ToolPlanAccessSummary
cf_move_accountProDestructiveDESTRUCTIVE: Move account.
cf_move_accounts_batchProDestructiveDESTRUCTIVE: Batch move accounts.

[Cloudflare] DESTRUCTIVE: Move account. Why this is destructive: It re-parents ONE account under a different organization, and the account takes its zones, its members' access and its billing with it - so the customer's live domains end up administered somewhere else. Moving it back is another call with the original organization id, which you should read and keep before sending this. Cloudflare marks this operation BETA. The same call moves an account OUT of an organization hierarchy as well as within one. cf_move_accounts_batch is the batch form. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. POST /accounts//move. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON with one required member, destination_organization_id - the organization this account should end up under.

[Cloudflare] DESTRUCTIVE: Batch move accounts. Why this is destructive: It re-parents a whole COLLECTION of accounts under a different organization in one call, and an account carries its zones, its members' access and its billing with it - so a wrong destination_organization_id moves the customer's live domains under administration they did not choose. There is no batch undo: each account has to be moved back individually. Cloudflare marks this operation ALPHA and its own API document says "Not implemented", so expect it to be refused; cf_move_account is the one-account form that does work. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. POST /accounts/move. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Both members are required: account_ids, the list of accounts to move, and destination_organization_id, the organization they all end up under.

One

ToolPlanAccessSummary
cf_create_one_integrationProWriteCreate integration.
cf_delete_one_integrationProDestructiveDESTRUCTIVE: Delete integration.
cf_get_one_applicationFreeRead-onlyGet application details.
cf_get_one_integrationFreeRead-onlyGet integration details.
cf_list_one_applicationsFreeRead-onlyList applications.
cf_list_one_applications_auth_methodsFreeRead-onlyGet auth methods.
cf_list_one_applications_setup_flowsFreeRead-onlyGet application setup flows.
cf_list_one_integrationsFreeRead-onlyList integrations.
cf_pause_one_integrationsProWritePause integration.
cf_resume_one_integrationsProWriteResume integration.
cf_update_one_integrationProWriteUpdate integration.

[Cloudflare] Create integration. Additive: it adds one new SaaS connection and changes no existing one. Cloudflare begins crawling the customer's tenant with the credentials you supply as soon as it is created, so the permissions those credentials carry decide what Cloudflare can see. Cloudflare does not support creating an OAuth-based integration through the API - the other auth methods work. POST /accounts//one/integrations. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Cloudflare account identifier.
bodyJsonstringyesRequired. The request body as JSON. application, credentials and name are required. application is the vendor - Cloudflare's enum is ANTHROPIC, AWS, BITBUCKET, BOX, CONFLUENCE, DROPBOX, GITHUB, GOOGLE_CLOUD_PLATFORM, GOOGLE_WORKSPACE, JIRA, MICROSOFT_INTERNAL, OPENAI, SALESFORCE, SERVICENOW and SLACK; credentials is the vendor's own secret material in the SHAPE that vendor's auth method documents - read cf_list_one_applications_auth_methods first; name is what the integration is called. use_cases (casb, ces) and dlp_profiles decide what is scanned, and permissions narrows what the integration may read.

[Cloudflare] DESTRUCTIVE: Delete integration. Why this is destructive: Cloudflare soft-deletes the integration: crawling stops and the connection disappears from the customer's Cloudflare One posture, so CASB findings and any DLP scanning that depended on it stop being produced. The API offers no undo here - re-connecting means creating the integration again with fresh credentials. DELETE /accounts//one/integrations/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Cloudflare account identifier.
idstringyesRequired. Integration ID.

[Cloudflare] Get application details. One catalog application in full: the auth methods it supports, its use cases and the permissions an integration will ask for. Cloudflare One integrations are the SaaS connections CASB and the email/data scanners read through - a customer's Google Workspace or Microsoft 365 tenant, for example. GET /accounts//one/applications/. Path parameters: account_id, application_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Cloudflare account identifier.
applicationIdstringyesRequired. Application/vendor identifier.

[Cloudflare] Get integration details. One integration in full: its application, status, use cases, DLP profiles and permissions, plus credentials_expiry - the date the stored credential stops working, which is the usual cause of an integration that has quietly stopped crawling. GET /accounts//one/integrations/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Cloudflare account identifier.
idstringyesRequired. Integration ID.

[Cloudflare] List applications. The CATALOG of applications Cloudflare One can integrate with - vendors, their use cases and the permissions each needs - not the customer's own connections. Each row's id is the application_id the auth-method and setup-flow reads take, and the value you put in a new integration's application field. Cloudflare One integrations are the SaaS connections CASB and the email/data scanners read through - a customer's Google Workspace or Microsoft 365 tenant, for example. Use cf_list_one_integrations for what the customer has actually connected. GET /accounts//one/applications. Path parameters: account_id. Optional filters: environment, page, page_size. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Cloudflare account identifier.
environmentstringnonullOptional. Narrow the catalog to applications supported in one environment: standard or fedramp.
pageintegernonullOptional. A page number within the paginated result set.
pageSizeintegernonullOptional. Number of results to return per page.

[Cloudflare] Get auth methods. How this vendor can be authenticated: each auth method with its CREDENTIAL SCHEMA, setup instructions and an example payload. Read it before cf_create_one_integration - the credentials object that call needs has the shape described here. It returns the schema and the field names, never a customer's own secret. GET /accounts//one/applications//auth-methods. Path parameters: account_id, application_id. Optional filters: page, page_size. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Cloudflare account identifier.
applicationIdstringyesRequired. Application/vendor identifier.
pageintegernonullOptional. A page number within the paginated result set.
pageSizeintegernonullOptional. Number of results to return per page.

[Cloudflare] Get application setup flows. The setup flows Cloudflare publishes for this application, one per auth method: the ordered steps a person follows in the vendor's console before the integration can be created. Filter by auth_method or environment. GET /accounts//one/applications//setup-flows. Path parameters: account_id, application_id. Optional filters: auth_method, environment, page, page_size. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Cloudflare account identifier.
applicationIdstringyesRequired. Application/vendor identifier.
authMethodstringnonullOptional. Filter by auth method id.
environmentstringnonullOptional. Filter by environment.
pageintegernonullOptional. A page number within the paginated result set.
pageSizeintegernonullOptional. Number of results to return per page.

[Cloudflare] List integrations. Start here for what the customer has actually CONNECTED: one row per Cloudflare One integration, with its application, status, use cases and whether DLP is on. Each row's id is what the get, update, pause, resume and delete tools take. Cloudflare One integrations are the SaaS connections CASB and the email/data scanners read through - a customer's Google Workspace or Microsoft 365 tenant, for example. Filter by application (GOOGLE_WORKSPACE, MICROSOFT_INTERNAL and so on), by status, or by use_cases such as casb or ces. GET /accounts//one/integrations. Path parameters: account_id. Optional filters: application, direction, dlp_enabled, order, page, page_size, search, status, use_cases. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Cloudflare account identifier.
applicationstringnonullOptional. Filter by application/vendor (e.g., GOOGLE_WORKSPACE, MICROSOFT_INTERNAL).
directionstringnonullOptional. Direction to order results.
dlpEnabledbooleannonullOptional. Filter by DLP enabled status (true/false).
orderstringnonullOptional. Field to order results by.
pageintegernonullOptional. Page number within the paginated result set.
pageSizeintegernonullOptional. Number of results per page.
searchstringnonullOptional. Search integrations by name or application.
statusstringnonullOptional. Filter by integration status.
useCasesstringnonullOptional. Filter by enabled use cases (e.g., casb, ces).

[Cloudflare] Pause integration. Reversible: it pauses the integration and stops every crawler on it, so Cloudflare stops discovering new findings for that tenant until cf_resume_one_integrations is called. Nothing already discovered is deleted. POST /accounts//one/integrations//pause. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Cloudflare account identifier.
idstringyesRequired. Integration ID.

[Cloudflare] Resume integration. Reversible: it resumes a paused integration and restarts its crawlers, so Cloudflare begins reading the customer's tenant again with the stored credentials. POST /accounts//one/integrations//resume. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Cloudflare account identifier.
idstringyesRequired. Integration ID.

[Cloudflare] Update integration. Partial update: Cloudflare applies only the members you send. Sending credentials REPLACES the stored secret for the vendor tenant, which is how an expired credential is rotated - and how a wrong value silently stops the crawl. Changing use_cases or dlp_profiles changes what Cloudflare scans from the next crawl. PATCH /accounts//one/integrations/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. Cloudflare account identifier.
bodyJsonstringnonullOptional. A JSON request body carrying only what you want changed: name, permissions, use_cases, dlp_profiles, or credentials to rotate the stored secret for the vendor tenant (same shape as on create - see cf_list_one_applications_auth_methods).
idstringyesRequired. Integration ID.

Pay Bad Debt

ToolPlanAccessSummary
cf_create_pay_bad_debtProDestructiveDESTRUCTIVE: Pay Bad Debt.

[Cloudflare] DESTRUCTIVE: Pay Bad Debt. Why this is destructive: It CHARGES the customer: Cloudflare discovers every outstanding bad debt on the account and takes payment for it from the payment method you name, or the default one. Money moves as soon as Cloudflare accepts the call and the API offers no reversal - a refund is a support matter. Read cf_get_billing_bad_debts first so you know the amount. POST /accounts//pay-bad-debt. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. payment_method_id names which stored payment method to charge (from cf_list_payment_methods); omit it to use the account's default. Cloudflare discovers the debt itself and de-duplicates the invoices.

Pay Invoice

ToolPlanAccessSummary
cf_create_pay_invoiceProDestructiveDESTRUCTIVE: Pay Invoice.

[Cloudflare] DESTRUCTIVE: Pay Invoice. Why this is destructive: It CHARGES the customer: Cloudflare takes payment for the invoice you name from the payment method you name, or the default one. Money moves as soon as Cloudflare accepts the call and the API offers no reversal. Read cf_get_billing_unpaid_invoices first and confirm the invoice_id and the amount. When the card issuer demands Strong Customer Authentication, Cloudflare answers with a Stripe client secret instead of a completed payment: the charge is NOT done, and a person has to finish the challenge in a browser. POST /accounts//pay-invoice. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. invoice_id names the invoice to pay (from cf_get_billing_unpaid_invoices) and payment_method_id which stored method to charge (from cf_list_payment_methods); omit the latter for the account default. validate_payment_method asks Cloudflare to check the method before charging.

Payment Methods

ToolPlanAccessSummary
cf_create_payment_methodProWriteCreate Payment Method.
cf_create_payment_method_set_as_defaultProWriteSet Default Payment Method.
cf_delete_payment_methodProDestructiveDESTRUCTIVE: Delete Payment Method.
cf_get_payment_methodFreeRead-onlyGet Payment Method.
cf_list_payment_methodsFreeRead-onlyList Payment Methods.
cf_set_payment_methodProDestructiveDESTRUCTIVE: Update Payment Method.

[Cloudflare] Create Payment Method. Additive: it stores one new payment method on the account and does not make it the default - cf_create_payment_method_set_as_default does that. Nothing is charged by this call, but the method becomes chargeable by the pay tools and by renewals. POST /accounts//payment-methods. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. type says what is being stored - CREDIT_CARD, PAYPAL, CASHAPP, SEPA_DEBIT, LINK or ACH_DIRECT_DEBIT - and payment_gateway which processor holds it; for a tokenized card Cloudflare expects payment_nonce (the single-use token the gateway's own collection form produced) rather than a card number, and for a bank account bank_code, bank_country, bank_name, bank_routing_number and bank_account_type. The billing name and postal address (first_name, last_name, address, address2, city, state, zipcode, country) travel with it, nick_name labels it and default asks for it to become the account default.

[Cloudflare] Set Default Payment Method. It changes WHICH stored method Cloudflare charges for this account's renewals and invoices. Reversible - set another method as default to move it back - but until you do, every automatic charge lands on the method you just named. POST /accounts//payment-methods//set-as-default. Path parameters: account_id, payment_method_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
paymentMethodIdstringyesRequired. Payment method identifier.

[Cloudflare] DESTRUCTIVE: Delete Payment Method. Why this is destructive: The stored method is removed, so any renewal or invoice that would have been charged to it fails from then on - and if it was the account default, Cloudflare has nothing to charge until another method is made default. Check cf_list_payment_methods for a second method first. DELETE /accounts//payment-methods/. Path parameters: account_id, payment_method_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
paymentMethodIdstringyesRequired. Payment method identifier.

[Cloudflare] Get Payment Method. One stored payment method by id: its type, last_four, gateway and whether it is the account default. Cloudflare never returns a full card number. GET /accounts//payment-methods/. Path parameters: account_id, payment_method_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
paymentMethodIdstringyesRequired. Payment method identifier.

[Cloudflare] List Payment Methods. The payment methods stored on the account - type, last_four, the gateway and which one is the default. Each row's id is the payment_method_id the get, update, delete, set-as-default and the two pay tools take. Cloudflare returns the card's last four digits, never a full card number. GET /accounts//payment-methods. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of items per page.

[Cloudflare] DESTRUCTIVE: Update Payment Method. Why this is destructive: A PUT replaces the stored payment method from the body, so an omitted billing name, address or bank detail is cleared rather than kept - and the method is what Cloudflare charges for renewals and invoices. Read cf_get_payment_method first and send the complete object back. PUT /accounts//payment-methods/. Path parameters: account_id, payment_method_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON and it REPLACES the stored method. Send the object back complete: type (CREDIT_CARD, PAYPAL, CASHAPP, SEPA_DEBIT, LINK or ACH_DIRECT_DEBIT) and payment_gateway, the tokenized payment_nonce for a card or the bank fields (bank_code, bank_country, bank_name, bank_routing_number, bank_account_type) for a bank account, plus the billing name and postal address, nick_name and default.
paymentMethodIdstringyesRequired. Payment method identifier.

Rate Plans

ToolPlanAccessSummary
cf_get_rate_planFreeRead-onlyGet Rate Plan by Public Key.

[Cloudflare] Get Rate Plan by Public Key. A public price-catalog read: the details of one Cloudflare rate plan by its public key, such as teams_free or cf_pro_20_20. Cloudflare does not enforce authentication on it and the answer is the same for every customer - it is the plan definition, not what this account is on. Use cf_list_subscriptions for the account's own plans. GET /billing/rate_plans/. Path parameters: public_key. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
publicKeystringyesRequired. The public key identifier for the rate plan.

Ready

ToolPlanAccessSummary
cf_check_readinessFreeRead-onlyRun readiness checks.

[Cloudflare] Run readiness checks. Cloudflare's own readiness probe for the API - the sibling of the liveness probe on /live. It reports the API's own state, never the customer's account. GET /ready. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

Receipts

ToolPlanAccessSummary
cf_download_receipt_pdfProRead-onlyGet Receipt PDF.

[Cloudflare] Get Receipt PDF. The customer-facing PDF for one receipt. StackJack uploads the bytes and answers with a short-lived download link rather than the file itself, which is why this read is Pro tier rather than Free: it spends blob storage and mints a bearer URL. Fetch the link promptly - it expires in about fifteen minutes and nothing keeps a copy afterwards. GET /accounts//receipts//pdf. Path parameters: account_id, receipt_id. Optional filters: doctype. This Cloudflare endpoint answers a file rather than JSON, so instead of the bytes you get a JSON envelope with sasUrl (a short-lived read-only download link, valid for about 15 minutes), contentType, suggestedFileName, sizeBytes and expiresAt. Fetch the link before it expires; nothing else in StackJack keeps a copy.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
doctypestringnonullOptional. Which document Cloudflare should render for this receipt id - the receipt itself or the matching invoice. Omit it for Cloudflare's default.
receiptIdstringyesRequired. Receipt identifier.

Signed URL

ToolPlanAccessSummary
cf_list_signed_urlsFreeRead-onlyInternal route for testing signed URLs.

[Cloudflare] Internal route for testing signed URLs. Cloudflare's own internal route for TESTING signed URLs, published in the API document but not a customer feature: it returns nothing about the account and is only useful for probing the API itself. GET /signed-url. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

Spectrum Analytics

ToolPlanAccessSummary
cf_list_user_spectrum_analytics_zones_reportsFreeRead-onlyGet zones bandwidth report.

[Cloudflare] Get zones bandwidth report. Total bandwidth by zone over a window for the TOKEN OWNER's zones, the Spectrum (TCP/UDP proxy) view. cdn_traffic defaults to true and folds ordinary CDN traffic into the totals - set it false for Spectrum bandwidth alone. GET /user/spectrum_analytics/zones/report. Optional filters: since, until, cdn_traffic. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
cdnTrafficbooleannonullOptional. True (the default) includes ordinary CDN traffic in the bandwidth totals; false reports Spectrum traffic only.
sincestringnonullOptional. The since filter.
untilstringnonullOptional. The until filter.

Submit

ToolPlanAccessSummary
cf_submit_rootProWriteInternal route for testing URL submissions.

[Cloudflare] Internal route for testing URL submissions. Cloudflare's own internal route for TESTING URL submissions. It takes no body and no parameters, changes nothing in the customer's account, and is published in the API document without a documented effect - there is no customer reason to call it. POST /internal/submit. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

Subscription

ToolPlanAccessSummary
cf_create_zones_subscriptionProDestructiveDESTRUCTIVE: Create Zone Subscription.
cf_delete_zones_subscriptionProDestructiveDESTRUCTIVE: Delete Zone Subscription.
cf_get_zones_subscriptionsFreeRead-onlyZone Subscription Details.
cf_set_zones_subscriptionProDestructiveDESTRUCTIVE: Update Zone Subscription.

[Cloudflare] DESTRUCTIVE: Create Zone Subscription. Why this is destructive: It puts the zone onto a paid plan or adds a paid add-on, so Cloudflare starts billing for it and keeps billing at the renewal frequency you set. It changes what this customer is CHARGED: the subscription renews on its own at the frequency and rate plan it carries, so the next invoice reflects whatever you send. Read cf_get_zones_subscriptions and cf_get_rate_plan first, and confirm the plan and the amount with whoever pays the invoice. POST /zones//subscription. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON: the subscription to create. rate_plan is the field that decides the money: rate_plan.id names the plan being bought (the public keys cf_get_rate_plan describes, such as cf_pro_20_20) and frequency is how often it renews - weekly, monthly, quarterly or yearly. component_values carries the metered add-on quantities for plans that have them, and zone names the zone for a zone-scoped subscription. currency, price, state and the current_period fields are Cloudflare's own bookkeeping and are normally read back rather than sent. app is a sunset Apps Marketplace field kept only for grandfathered subscriptions.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete Zone Subscription. Why this is destructive: It cancels the zone's paid plan: the domain drops to what its account's free entitlement covers, so paid features stop applying to live traffic. Billing changes with it. Read cf_get_zones_subscriptions first and keep the rate_plan id - re-subscribing is a new subscription at whatever the plan costs today. DELETE /zones//subscription. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Zone Subscription Details. The subscription attached to ONE zone - the plan the domain is on, its rate plan, price, renewal frequency and current period. Read it before any subscription write so you know what the customer is paying today. Cloudflare exposes the same zone subscription on two paths: this singular /subscription one, which its own document prefers, and the plural /subscriptions alias. GET /zones//subscription. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Update Zone Subscription. Why this is destructive: A PUT replaces the zone's whole subscription from the body, so an omitted rate_plan or frequency does not keep its current value - and this is the customer's bill. Upgrading, downgrading or changing the renewal frequency all land on the next invoice, and a downgrade takes features away from a live domain. Read cf_get_zones_subscriptions first and send the complete object back. PUT /zones//subscription. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON and it REPLACES the zone's subscription. rate_plan is the field that decides the money: rate_plan.id names the plan being bought (the public keys cf_get_rate_plan describes, such as cf_pro_20_20) and frequency is how often it renews - weekly, monthly, quarterly or yearly. component_values carries the metered add-on quantities for plans that have them, and zone names the zone for a zone-scoped subscription. currency, price, state and the current_period fields are Cloudflare's own bookkeeping and are normally read back rather than sent. app is a sunset Apps Marketplace field kept only for grandfathered subscriptions.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

Subscriptions

ToolPlanAccessSummary
cf_create_subscriptionProDestructiveDESTRUCTIVE: Create Subscription.
cf_create_subscriptions_action_appendProDestructiveDESTRUCTIVE: Append Subscription Action.
cf_create_subscriptions_cancel_downgradeProDestructiveDESTRUCTIVE: Cancel Delayed Downgrade.
cf_create_subscriptions_cancel_reasonProDestructiveDESTRUCTIVE: Create Cancel Reason.
cf_create_user_subscriptionProDestructiveDESTRUCTIVE: Create User Subscription.
cf_create_zones_subscription_by_zone_idProDestructiveDESTRUCTIVE: Create Zone Subscription.
cf_delete_subscriptionProDestructiveDESTRUCTIVE: Delete Subscription.
cf_delete_user_subscriptionProDestructiveDESTRUCTIVE: Delete User Subscription.
cf_delete_zones_subscriptionsProDestructiveDESTRUCTIVE: Delete Zone Subscription.
cf_get_subscriptionFreeRead-onlyGet Subscription.
cf_get_subscriptions_cancel_reasonsFreeRead-onlyGet Cancel Reason.
cf_list_subscriptionsFreeRead-onlyList Subscriptions.
cf_list_user_subscriptionsFreeRead-onlyGet User Subscriptions.
cf_set_subscriptionProDestructiveDESTRUCTIVE: Update Subscription.
cf_set_user_subscriptionProDestructiveDESTRUCTIVE: Update User Subscription.
cf_set_zones_subscription_by_zone_idProDestructiveDESTRUCTIVE: Update Zone Subscription.

[Cloudflare] DESTRUCTIVE: Create Subscription. Why this is destructive: It starts a new PAID subscription on the account, so Cloudflare bills for it and keeps billing at the renewal frequency you set. It changes what this customer is CHARGED: the subscription renews on its own at the frequency and rate plan it carries, so the next invoice reflects whatever you send. Read cf_list_subscriptions and cf_get_rate_plan first, and confirm the plan and the amount with whoever pays the invoice. POST /accounts//subscriptions. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON: the subscription to create. rate_plan is the field that decides the money: rate_plan.id names the plan being bought (the public keys cf_get_rate_plan describes, such as cf_pro_20_20) and frequency is how often it renews - weekly, monthly, quarterly or yearly. component_values carries the metered add-on quantities for plans that have them, and zone names the zone for a zone-scoped subscription. currency, price, state and the current_period fields are Cloudflare's own bookkeeping and are normally read back rather than sent. app is a sunset Apps Marketplace field kept only for grandfathered subscriptions.

[Cloudflare] DESTRUCTIVE: Append Subscription Action. Why this is destructive: Cloudflare calls this "smartly applies the incoming subscription into the lifecycle of the subscription": it folds the subscription in the body into the existing one, which can change the rate plan, the component quantities or the renewal, so the customer's next invoice changes and the exact outcome is decided by Cloudflare rather than stated by you. Read cf_get_subscription before and after. POST /accounts//subscriptions//action/append. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON: the subscription to fold into the existing one. rate_plan is the field that decides the money: rate_plan.id names the plan being bought (the public keys cf_get_rate_plan describes, such as cf_pro_20_20) and frequency is how often it renews - weekly, monthly, quarterly or yearly. component_values carries the metered add-on quantities for plans that have them, and zone names the zone for a zone-scoped subscription. currency, price, state and the current_period fields are Cloudflare's own bookkeeping and are normally read back rather than sent. app is a sunset Apps Marketplace field kept only for grandfathered subscriptions.
subscriptionIdentifierstringyesRequired. Subscription identifier tag.

[Cloudflare] DESTRUCTIVE: Cancel Delayed Downgrade. Why this is destructive: It CANCELS pending downgrades, which means the subscriptions you name stay on their current (higher) plan and keep being billed at that price instead of dropping at the period end. That is the opposite of what "cancel" reads like at a glance, so confirm which outcome the customer wants before sending it. POST /accounts//subscriptions/cancel-downgrade. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON with one member, subscription_ids: the subscriptions whose pending delayed downgrade should be called off. Take the ids from cf_list_subscriptions.

[Cloudflare] DESTRUCTIVE: Create Cancel Reason. Why this is destructive: It records WHY a subscription was cancelled against the subscription's own record, where Cloudflare's billing and account teams read it. It does not cancel anything itself - cf_delete_subscription does that - but the note it leaves is on the customer's account permanently. POST /accounts//subscriptions//cancel-reason. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. reason_code is Cloudflare's own cancellation reason code and other is the free-text explanation to record with it.
subscriptionIdentifierstringyesRequired. Subscription identifier tag.

[Cloudflare] DESTRUCTIVE: Create User Subscription. Why this is destructive: It starts a new PAID subscription billed to the token owner's own user, so Cloudflare bills that user and keeps billing at the renewal frequency you set. It changes what this customer is CHARGED: the subscription renews on its own at the frequency and rate plan it carries, so the next invoice reflects whatever you send. Most customers want the account-scope cf_create_subscription instead. POST /user/subscriptions. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON: the subscription to create. rate_plan is the field that decides the money: rate_plan.id names the plan being bought (the public keys cf_get_rate_plan describes, such as cf_pro_20_20) and frequency is how often it renews - weekly, monthly, quarterly or yearly. component_values carries the metered add-on quantities for plans that have them, and zone names the zone for a zone-scoped subscription. currency, price, state and the current_period fields are Cloudflare's own bookkeeping and are normally read back rather than sent. app is a sunset Apps Marketplace field kept only for grandfathered subscriptions.

[Cloudflare] DESTRUCTIVE: Create Zone Subscription. Why this is destructive: It puts the zone onto a paid plan or adds a paid add-on, so Cloudflare starts billing for it and keeps billing at the renewal frequency you set. It changes what this customer is CHARGED: the subscription renews on its own at the frequency and rate plan it carries, so the next invoice reflects whatever you send. This is Cloudflare's PLURAL /subscriptions alias, retained for audit-log coverage; its own document says to use the singular path instead, which is cf_create_zones_subscription. POST /zones//subscriptions. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON: the subscription to create. rate_plan is the field that decides the money: rate_plan.id names the plan being bought (the public keys cf_get_rate_plan describes, such as cf_pro_20_20) and frequency is how often it renews - weekly, monthly, quarterly or yearly. component_values carries the metered add-on quantities for plans that have them, and zone names the zone for a zone-scoped subscription. currency, price, state and the current_period fields are Cloudflare's own bookkeeping and are normally read back rather than sent. app is a sunset Apps Marketplace field kept only for grandfathered subscriptions.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete Subscription. Why this is destructive: It cancels a paid subscription on the account: the products it covered drop to the free entitlement, which can switch off protections or features on live traffic, and the billing stops with them. Read cf_get_subscription first and keep the rate_plan id - re-subscribing is a new subscription at today's price. DELETE /accounts//subscriptions/. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
subscriptionIdentifierstringyesRequired. Subscription identifier tag.

[Cloudflare] DESTRUCTIVE: Delete User Subscription. Why this is destructive: It cancels a subscription billed to the token owner's own user: whatever it paid for drops to the free entitlement and the billing stops. Read cf_list_user_subscriptions first and keep the rate_plan id - re-subscribing is a new subscription at today's price. DELETE /user/subscriptions/. Path parameters: identifier. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
identifierstringyesRequired. Subscription identifier tag.

[Cloudflare] DESTRUCTIVE: Delete Zone Subscription. Why this is destructive: It cancels the zone's paid plan: the domain drops to what its account's free entitlement covers, so paid features stop applying to live traffic, and the billing stops with them. This is Cloudflare's PLURAL /subscriptions alias, retained for audit-log coverage; its own document says to use the singular path instead, which is cf_delete_zones_subscription. DELETE /zones//subscriptions. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Get Subscription. One account subscription by its identifier: rate plan, price, renewal frequency, state and the current billing period. Read it before any write to this subscription. GET /accounts//subscriptions/. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
subscriptionIdentifierstringyesRequired. Subscription identifier tag.

[Cloudflare] Get Cancel Reason. The cancellation reason recorded against one subscription, if any - what the customer said when they cancelled. It reads the record; cf_create_subscriptions_cancel_reason writes one. GET /accounts//subscriptions//cancel-reason. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
subscriptionIdentifierstringyesRequired. Subscription identifier tag.

[Cloudflare] List Subscriptions. Start here for what the customer is PAYING FOR: every subscription on the account, each with its rate plan, price, renewal frequency, state and current period. The id on each row is the subscription_identifier the get, update, delete and cancel tools take. This endpoint takes no paging parameters - the whole collection comes back in one response. GET /accounts//subscriptions. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get User Subscriptions. The subscriptions billed to the TOKEN OWNER's own user rather than to an account - the older user-scope billing model. cf_list_subscriptions is the account-scope read most customers need. This endpoint takes no paging parameters - the whole collection comes back. GET /user/subscriptions. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

[Cloudflare] DESTRUCTIVE: Update Subscription. Why this is destructive: A PUT replaces the account subscription from the body, so an omitted rate_plan or frequency does not keep its current value - and this is the customer's bill. An upgrade, a downgrade or a change of renewal frequency all reach the next invoice, and a downgrade removes whatever the higher plan was providing. Read cf_get_subscription first and send the complete object back. PUT /accounts//subscriptions/. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON and it REPLACES the subscription. rate_plan is the field that decides the money: rate_plan.id names the plan being bought (the public keys cf_get_rate_plan describes, such as cf_pro_20_20) and frequency is how often it renews - weekly, monthly, quarterly or yearly. component_values carries the metered add-on quantities for plans that have them, and zone names the zone for a zone-scoped subscription. currency, price, state and the current_period fields are Cloudflare's own bookkeeping and are normally read back rather than sent. app is a sunset Apps Marketplace field kept only for grandfathered subscriptions.
subscriptionIdentifierstringyesRequired. Subscription identifier tag.

[Cloudflare] DESTRUCTIVE: Update User Subscription. Why this is destructive: A PUT replaces a user-scope subscription from the body, so an omitted rate_plan or frequency does not keep its current value and the change lands on the token owner's next invoice. Read cf_list_user_subscriptions first and send the complete object back. PUT /user/subscriptions/. Path parameters: identifier. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON and it REPLACES the subscription. rate_plan is the field that decides the money: rate_plan.id names the plan being bought (the public keys cf_get_rate_plan describes, such as cf_pro_20_20) and frequency is how often it renews - weekly, monthly, quarterly or yearly. component_values carries the metered add-on quantities for plans that have them, and zone names the zone for a zone-scoped subscription. currency, price, state and the current_period fields are Cloudflare's own bookkeeping and are normally read back rather than sent. app is a sunset Apps Marketplace field kept only for grandfathered subscriptions.
identifierstringyesRequired. Subscription identifier tag.

[Cloudflare] DESTRUCTIVE: Update Zone Subscription. Why this is destructive: A PUT replaces the zone's whole subscription from the body, so an omitted rate_plan or frequency does not keep its current value and the change reaches the customer's next invoice; a downgrade also takes features away from a live domain. This is Cloudflare's PLURAL /subscriptions alias, retained for audit-log coverage; its own document says to use the singular path instead, which is cf_set_zones_subscription. PUT /zones//subscriptions. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON and it REPLACES the zone's subscription. rate_plan is the field that decides the money: rate_plan.id names the plan being bought (the public keys cf_get_rate_plan describes, such as cf_pro_20_20) and frequency is how often it renews - weekly, monthly, quarterly or yearly. component_values carries the metered add-on quantities for plans that have them, and zone names the zone for a zone-scoped subscription. currency, price, state and the current_period fields are Cloudflare's own bookkeeping and are normally read back rather than sent. app is a sunset Apps Marketplace field kept only for grandfathered subscriptions.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

Tags

ToolPlanAccessSummary
cf_delete_tagsProDestructiveDESTRUCTIVE: Delete tags from an account-level resource.
cf_delete_zones_tagsProDestructiveDESTRUCTIVE: Delete tags from a zone-level resource.
cf_get_tagsFreeRead-onlyGet tags for an account-level resource.
cf_get_tags_summaryFreeRead-onlyList tag key summary.
cf_get_zones_tagsFreeRead-onlyGet tags for a zone-level resource.
cf_list_tag_valuesFreeRead-onlyList tag values.
cf_list_tags_keysFreeRead-onlyList tag keys.
cf_list_tags_resourcesFreeRead-onlyList tagged resources.
cf_set_tagProDestructiveDESTRUCTIVE: Set tags for an account-level resource.
cf_set_zones_tagProDestructiveDESTRUCTIVE: Set tags for a zone-level resource.

[Cloudflare] DESTRUCTIVE: Delete tags from an account-level resource. Why this is destructive: It removes ALL tags from the resource in one call, not the one tag you might have in mind: cost allocation, saved filters and any automation keyed off those tags stop matching it. Read cf_get_tags first if you want to put them back, and use cf_set_tag with the reduced set when you only mean to drop one. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. DELETE /accounts//tags. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON naming the resource whose tags are to be cleared. Cloudflare requires resource_id and resource_type - resource_type is a discriminator whose value picks the body shape, and the Worker-scoped shapes additionally require worker_id. Every tag on that resource is removed.
ifMatchstringnonullOptional. ETag value for optimistic concurrency control. Sent as the If-Match request header.

[Cloudflare] DESTRUCTIVE: Delete tags from a zone-level resource. Why this is destructive: It removes ALL tags from that zone-level resource in one call, not one tag: cost allocation, saved filters and any automation keyed off them stop matching. Use cf_set_zones_tag with the reduced set when you only mean to drop one. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. DELETE /zones//tags. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON naming the resource whose tags are to be cleared. Cloudflare requires resource_id and resource_type - resource_type is a discriminator whose value picks the body shape, and the access_application_policy shape additionally requires access_application_id. Every tag on that resource is removed.
ifMatchstringnonullOptional. ETag value for optimistic concurrency control. Sent as the If-Match request header.
zoneIdstringyesRequired. Zone ID is required only for zone-level resources.

[Cloudflare] Get tags for an account-level resource. The tags on ONE account-level resource. resource_id and resource_type are REQUIRED by Cloudflare even though both arguments are optional in this tool's signature - the call is refused without them. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. Use cf_list_tags_resources to find tagged resources and cf_get_zones_tags for a zone-level one. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /accounts//tags. Path parameters: account_id. Cloudflare REQUIRES these query parameters and answers 400 without it: resource_id, resource_type. Optional filters: worker_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
resourceIdstringnonullRequired by Cloudflare - the call fails without it. REQUIRED by Cloudflare even though this argument is optional in the signature - the call is refused without it. The id of the account-level resource whose tags you want.
resourceTypestringnonullRequired by Cloudflare - the call fails without it. REQUIRED by Cloudflare even though this argument is optional in the signature - the call is refused without it. What kind of resource resource_id names, in Cloudflare's own resource-type vocabulary.
workerIdstringnonullOptional. Only for Worker-scoped resources: the Worker the resource belongs to.

[Cloudflare] List tag key summary. Tag keys AND their distinct values across the account in one response - the summary view of the whole tagging vocabulary, where cf_list_tags_keys returns only the keys. Paging is cursor-based. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /accounts//tags/summary. Path parameters: account_id. Optional filters: cursor. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
cursorstringnonullOptional. Cursor for pagination.

[Cloudflare] Get tags for a zone-level resource. The tags on ONE zone-level resource. resource_id and resource_type are REQUIRED by Cloudflare even though both arguments are optional in this tool's signature - the call is refused without them. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. cf_get_tags is the account-level equivalent. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /zones//tags. Path parameters: zone_id. Cloudflare REQUIRES these query parameters and answers 400 without it: resource_id, resource_type. Optional filters: access_application_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accessApplicationIdstringnonullOptional. Only for Access-scoped resources: the Access application the resource belongs to.
resourceIdstringnonullRequired by Cloudflare - the call fails without it. REQUIRED by Cloudflare even though this argument is optional in the signature - the call is refused without it. The id of the zone-level resource whose tags you want.
resourceTypestringnonullRequired by Cloudflare - the call fails without it. REQUIRED by Cloudflare even though this argument is optional in the signature - the call is refused without it. What kind of resource resource_id names, in Cloudflare's own resource-type vocabulary.
zoneIdstringyesRequired. Zone ID is required only for zone-level resources.

[Cloudflare] List tag values. Every distinct value in use for ONE tag key, optionally narrowed to a resource type. Use it to discover what a key's values actually are before filtering cf_list_tags_resources by them. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /accounts//tags/values/. Path parameters: account_id, tag_key. Optional filters: type, cursor. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
cursorstringnonullOptional. Cursor for pagination.
tagKeystringyesRequired. The tag key to retrieve values for.
typestringnonullOptional. Filter by resource type.

[Cloudflare] List tag keys. Every distinct tag KEY in use across the account's resources - the vocabulary someone has actually applied. Start here, then cf_list_tag_values for one key's values or cf_get_tags_summary for keys and values together. Paging is cursor-based. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /accounts//tags/keys. Path parameters: account_id. Optional filters: cursor. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
cursorstringnonullOptional. Cursor for pagination.

[Cloudflare] List tagged resources. The account's TAGGED resources, filterable by tag criteria, resource type, name or id - the read that answers "what belongs to this project or cost centre?". case_insensitive matches keys and values without regard to case. Paging is cursor-based. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /accounts//tags/resources. Path parameters: account_id. Optional filters: type, name, id, case_insensitive, tag, cursor. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
caseInsensitivebooleannonullOptional. Match `tag` keys and values case-insensitively.
cursorstringnonullOptional. Cursor for pagination.
idstringnonullOptional. Filter by resource ID.
namestringnonullOptional. Filter by resource name.
tagstringnonullOptional. Filter to resources carrying particular tags, in Cloudflare's tag criteria syntax (key and value pairs).
typestringnonullOptional. Filter to one kind of resource, in Cloudflare's own resource-type vocabulary.

[Cloudflare] DESTRUCTIVE: Set tags for an account-level resource. Why this is destructive: It REPLACES the full tag set on that resource: a tag missing from the body is removed, so anything keyed off it - cost allocation, a saved filter, another team's automation - stops matching. Read cf_get_tags first and send the complete set. Pass the ETag in ifMatch so a concurrent edit is refused instead of silently overwritten. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. PUT /accounts//tags. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare requires resource_id and resource_type: resource_type is a discriminator whose value (account, kv_namespace, d1_database, cloudflared_tunnel, image, pages_project and the rest of its enum) picks the body shape, and the Worker-scoped shapes additionally require worker_id. tags is the COMPLETE key/value set that resource should end up with - anything you leave out is removed.
ifMatchstringnonullOptional. ETag value for optimistic concurrency control. Sent as the If-Match request header.

[Cloudflare] DESTRUCTIVE: Set tags for a zone-level resource. Why this is destructive: Cloudflare replaces ALL existing tags on that zone-level resource with the set you send, so a tag missing from the body is removed and anything keyed off it stops matching. Read cf_get_zones_tags first and send the complete set, and pass the ETag in ifMatch so a concurrent edit is refused rather than overwritten. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. PUT /zones//tags. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare requires resource_id and resource_type: resource_type is a discriminator whose value (zone, dns_record, custom_hostname, load_balancer, worker_route and the rest of its enum) picks the body shape, and the access_application_policy shape additionally requires access_application_id. tags is the COMPLETE key/value set that resource should end up with - anything you leave out is removed.
ifMatchstringnonullOptional. ETag value for optimistic concurrency control. Sent as the If-Match request header.
zoneIdstringyesRequired. Zone ID is required only for zone-level resources.

User

ToolPlanAccessSummary
cf_get_usersFreeRead-onlyUser Details.
cf_update_userProWriteEdit User.

[Cloudflare] User Details. The identity behind the credential: the token owner's email, name, country and two-factor state, plus the accounts they belong to. It is the read that answers "whose token is this?" when a call is refused. The path is /user - one user, the authenticated one. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the User Details Write or User Details Read permission rather than that the call is unsupported. GET /user. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

[Cloudflare] Edit User. It edits the real person's own Cloudflare profile - first_name, last_name, telephone, country and zipcode - for the user the token belongs to, not for a member you name. Partial: omitted fields keep their value. The email address cannot be changed here. PATCH /user. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON with the parts of the token owner's profile you want changed: first_name, last_name, telephone, country and zipcode. Anything omitted keeps its current value; the email address is not editable through this call.

v4

ToolPlanAccessSummary
cf_check_api_healthFreeRead-onlyAPI health check.

[Cloudflare] API health check. Cloudflare describes this as an INTERNAL infrastructure health check for its API monolith, not intended for customer use and excluded from its own SDKs and public docs. It tells you nothing about the customer's account; prefer cf_verify_account_token or the /live probe. GET /api/v4/health. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

Zones

ToolPlanAccessSummary
cf_create_zoneProWriteCreate Zone.
cf_delete_zoneProDestructiveDESTRUCTIVE: Delete Zone.
cf_get_zoneFreeRead-onlyZone Details.
cf_list_zonesFreeRead-onlyList Zones.
cf_update_zoneProWriteEdit Zone.

[Cloudflare] Create Zone. Additive: adds a zone and changes no existing one. POST /zones. Send the request body as JSON; Cloudflare documents these fields: account, name, type. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: account, name, type. Cloudflare requires: account, name.

[Cloudflare] DESTRUCTIVE: Delete Zone. Why this is destructive: Deletes the zone; Cloudflare stops answering for the domain. DELETE /zones/. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Zone Details. Returns the zone record, including its status (active, pending, moved), its plan, its nameservers and the account it belongs to. A pending zone means the domain is not yet delegated to Cloudflare, which explains most "the change had no effect" reports. GET /zones/. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List Zones. Start here for anything zone-scoped: it returns every zone the token can see, with the zone id the DNS, firewall and cache tools take. Filter by name for one domain, or by account.id to list the zones of one account. GET /zones. Optional filters: name, status, type, account.id, account.name, page, per_page, order, direction, match. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringnonullOptional. Filter by an account ID.
accountNamestringnonullOptional. An account Name.
directionstringnonullOptional. Direction to order zones.
matchstringnonullOptional. Whether to match all search requirements or at least one (any).
namestringnonullOptional. A domain name.
orderstringnonullOptional. Field to order zones by.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of zones per page.
statusstringnonullOptional. Specify a zone status to filter by.
typestringnonullOptional. Zone types to filter by.

[Cloudflare] Edit Zone. Partial update: omitted fields keep their value. PATCH /zones/. Path parameters: zone_id. Send the request body as JSON; Cloudflare documents these fields: paused, plan, type, vanity_name_servers. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: paused, plan, type, vanity_name_servers.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

R2

ToolPlanAccessSummary
cf_get_r2_objectProRead-onlyGet Object.
cf_upload_r2_objectProDestructiveDESTRUCTIVE: Upload Object.

[Cloudflare] Get Object. The object's BYTES, handed back as a short-lived download link rather than inline: R2 objects are arbitrary files and base64 in a tool result would spend the whole result budget on one of them. Use cf_get_r2_object_metadata when you only need the size, etag or content type. GET /accounts//r2/buckets//objects/. Path parameters: account_id, bucket_name, object_key. This Cloudflare endpoint answers a file rather than JSON, so instead of the bytes you get a JSON envelope with sasUrl (a short-lived read-only download link, valid for about 15 minutes), contentType, suggestedFileName, sizeBytes and expiresAt. Fetch the link before it expires; nothing else in StackJack keeps a copy.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
ifModifiedSincestringnonullOptional. Returns the object only if it has been modified since the specified time. Sent as the If-Modified-Since request header.
ifNoneMatchstringnonullOptional. Returns the object only if its ETag does not match the given value. Sent as the If-None-Match request header.
objectKeystringyesRequired. The key (name) of the object to retrieve.

[Cloudflare] DESTRUCTIVE: Upload Object. Why this is destructive: The whole request body is the file, so this writes the object at this path in full - anything already stored there is replaced. Supply the file EITHER as base64 in contentBase64 OR as a public https URL in sourceUrl, never both. StackJack fetches an https URL server-side, refuses plain http, refuses a redirect to a different host and caps the transfer at 25 MB. PUT /accounts//r2/buckets//objects/. Path parameters: account_id, bucket_name, object_key. The whole request body is the file's bytes. Supply it EITHER as base64 in contentBase64 OR as a public https URL in sourceUrl - exactly one of the two. StackJack downloads an https URL server-side and refuses a non-https URL, a redirect to a different host, or anything over 25 MB. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
cfR2StorageClassstringnonullOptional. Storage class for this object. Sent as the cf-r2-storage-class request header.
contentBase64stringnonullOptional. The file's bytes as base64. Give this OR sourceUrl, never both. Maximum 25 MB decoded.
contentTypestringnonullOptional. The media type R2 stores with the object and serves it back as - image/png, application/pdf, text/csv. Left out, the object is stored as application/octet-stream, which a browser downloads instead of displaying. Sent as the Content-Type request header.
fileNamestringnonullOptional. A file name for the upload. Cloudflare stores the bytes at the path, so this only labels the transfer.
objectKeystringyesRequired. The key (name) to assign to the object.
sourceUrlstringnonullOptional. A public https URL StackJack downloads the file from. Give this OR contentBase64, never both. Maximum 25 MB.

R2 Bucket Settings

ToolPlanAccessSummary
cf_delete_r2_bucket_corsProDestructiveDESTRUCTIVE: Delete Bucket CORS Policy.
cf_disable_r2_bucket_sippyProDestructiveDESTRUCTIVE: Disable Sippy.
cf_enable_r2_bucket_sippyProWriteEnable Sippy.
cf_get_r2_bucket_corsFreeRead-onlyGet Bucket CORS Policy.
cf_get_r2_bucket_lifecycleFreeRead-onlyGet Object Lifecycle Rules.
cf_get_r2_bucket_local_uploadsFreeRead-onlyGet Local Uploads Configuration.
cf_get_r2_bucket_lockFreeRead-onlyGet Bucket Lock Rules.
cf_get_r2_bucket_sippyFreeRead-onlyGet Sippy Configuration.
cf_set_r2_bucket_corsProDestructiveDESTRUCTIVE: Put Bucket CORS Policy.
cf_set_r2_bucket_lifecycleProDestructiveDESTRUCTIVE: Put Object Lifecycle Rules.
cf_set_r2_bucket_local_uploadsProWritePut Local Uploads Configuration.
cf_set_r2_bucket_lockProDestructiveDESTRUCTIVE: Put Bucket Lock Rules.

[Cloudflare] DESTRUCTIVE: Delete Bucket CORS Policy. Why this is destructive: Removes the CORS policy; browser callers start failing pre-flight. DELETE /accounts//r2/buckets//cors. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] DESTRUCTIVE: Disable Sippy. Why this is destructive: Turns migration off and discards the stored source credentials. DELETE /accounts//r2/buckets//sippy. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] Enable Sippy. Turns on incremental migration from the source bucket; it copies in and deletes nothing. PUT /accounts//r2/buckets//sippy. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: destination, source. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: destination, source.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] Get Bucket CORS Policy. GET /accounts//r2/buckets//cors. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] Get Object Lifecycle Rules. GET /accounts//r2/buckets//lifecycle. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] Get Local Uploads Configuration. GET /accounts//r2/buckets//local-uploads. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.

[Cloudflare] Get Bucket Lock Rules. GET /accounts//r2/buckets//lock. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] Get Sippy Configuration. GET /accounts//r2/buckets//sippy. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] DESTRUCTIVE: Put Bucket CORS Policy. Why this is destructive: Wholesale replace: the whole CORS rule list is rewritten, so a rule you omit is removed. PUT /accounts//r2/buckets//cors. Path parameters: bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: rules. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: rules.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] DESTRUCTIVE: Put Object Lifecycle Rules. Why this is destructive: Wholesale replace, and lifecycle rules delete stored objects on the schedule they name. PUT /accounts//r2/buckets//lifecycle. Path parameters: bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: rules. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: rules.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] Put Local Uploads Configuration. A single reversible on/off toggle; nothing stored is changed. PUT /accounts//r2/buckets//local-uploads. Path parameters: bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: enabled. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: enabled. Cloudflare requires: enabled.
bucketNamestringyesRequired. Name of the bucket.

[Cloudflare] DESTRUCTIVE: Put Bucket Lock Rules. Why this is destructive: Wholesale replace of the retention rule list, and a lock rule cannot be shortened once it applies. PUT /accounts//r2/buckets//lock. Path parameters: bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: rules. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: rules.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

R2 Buckets

ToolPlanAccessSummary
cf_create_r2_bucketProWriteCreate Bucket.
cf_create_r2_bucket_by_nameProWriteCreate Bucket (by name).
cf_delete_r2_bucketProDestructiveDESTRUCTIVE: Delete Bucket.
cf_get_r2_bucketFreeRead-onlyGet Bucket.
cf_get_r2_metricsFreeRead-onlyGet Account-Level Metrics.
cf_list_r2_bucketsFreeRead-onlyList Buckets.
cf_update_r2_bucket_storage_classProWritePatch Bucket.

[Cloudflare] Create Bucket. Additive, and the plan task rules R2 bucket create false. POST /accounts//r2/buckets. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: locationHint, name, storageClass. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: locationHint, name, storageClass. Cloudflare requires: name.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] Create Bucket (by name). Creates the bucket at the name in the path; it creates and never replaces, so the plan task R2 bucket create false applies. PUT /accounts//r2/buckets/. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
cfR2StorageClassstringnonullOptional. The R2 storage class: Standard or InfrequentAccess. Sent as the cf-r2-storage-class request header.

[Cloudflare] DESTRUCTIVE: Delete Bucket. Why this is destructive: Deletes the bucket. DELETE /accounts//r2/buckets/. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] Get Bucket. Reads one bucket by name — R2 addresses buckets by name, not by an id. Returns its creation date, location hint and default storage class. GET /accounts//r2/buckets/. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] Get Account-Level Metrics. Account-level R2 storage and object counts, split by standard and infrequent-access class — the read behind a storage-cost question. GET /accounts//r2/metrics. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] List Buckets. The first call for anything R2. Returns every bucket in the account with its location and storage class. Paging here is cursor-based rather than page-numbered. GET /accounts//r2/buckets. Path parameters: account_id. Optional filters: name_contains, start_after, per_page, order, direction, cursor. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
cursorstringnonullOptional. Pagination cursor received during the last List Buckets call.
directionstringnonullOptional. Direction to order buckets.
nameContainsstringnonullOptional. Bucket names to filter by.
orderstringnonullOptional. Field to order buckets by.
perPageintegernonullOptional. Maximum number of buckets to return in a single call.
startAfterstringnonullOptional. Bucket name to start searching after.

[Cloudflare] Patch Bucket. Changes the default storage class for objects written from now on; existing objects are untouched. PATCH /accounts//r2/buckets/. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
cfR2StorageClassstringyesRequired. The R2 storage class: Standard or InfrequentAccess. Sent as the cf-r2-storage-class request header.

R2 Data Catalog

ToolPlanAccessSummary
cf_delete_r2_catalog_metadataProDestructiveDESTRUCTIVE: Delete R2 catalog metadata.
cf_disable_r2_catalogProDestructiveDESTRUCTIVE: Disable R2 catalog.
cf_enable_r2_catalogProWriteEnable R2 bucket as a catalog.
cf_get_r2_catalogFreeRead-onlyGet R2 catalog details.
cf_get_r2_catalog_maintenance_configFreeRead-onlyGet catalog maintenance configuration.
cf_get_r2_catalog_tableFreeRead-onlyGet table details.
cf_get_r2_catalog_table_maintenanceFreeRead-onlyGet table maintenance configuration.
cf_list_r2_catalog_maintenance_runsFreeRead-onlyList table maintenance runs.
cf_list_r2_catalog_namespacesFreeRead-onlyList namespaces in catalog.
cf_list_r2_catalog_tablesFreeRead-onlyList tables in namespace.
cf_list_r2_catalogsFreeRead-onlyList R2 catalogs.
cf_queue_r2_catalog_table_maintenanceProDestructiveDESTRUCTIVE: Queue table maintenance.
cf_store_r2_catalog_credentialProDestructiveDESTRUCTIVE: Store catalog credentials.
cf_update_r2_catalog_maintenanceProWriteUpdate catalog maintenance configuration.
cf_update_r2_catalog_table_maintenanceProWriteUpdate table maintenance configuration.

[Cloudflare] DESTRUCTIVE: Delete R2 catalog metadata. Why this is destructive: Deletes the catalog metadata for the bucket. POST /accounts//r2-catalog//delete. Path parameters: account_id, bucket_name. Optional filters: force. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Specifies the R2 bucket name.
forcebooleannonullOptional. Remove child metadata before deleting the catalog.

[Cloudflare] DESTRUCTIVE: Disable R2 catalog. Why this is destructive: Turns the catalog off; every Iceberg client reading it loses access. POST /accounts//r2-catalog//disable. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Specifies the R2 bucket name to disable as catalog.

[Cloudflare] Enable R2 bucket as a catalog. Additive: turns the catalog on for the bucket. POST /accounts//r2-catalog//enable. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Specifies the R2 bucket name to enable as catalog.

[Cloudflare] Get R2 catalog details. GET /accounts//r2-catalog/. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Specifies the R2 bucket name.

[Cloudflare] Get catalog maintenance configuration. GET /accounts//r2-catalog//maintenance-configs. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Specifies the R2 bucket name.

[Cloudflare] Get table details. GET /accounts//r2-catalog//namespaces//tables/. Path parameters: account_id, bucket_name, namespace, table_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Specifies the R2 bucket name.
namespacestringyesRequired. The namespace identifier.
tableNamestringyesRequired. The table name within the given namespace.

[Cloudflare] Get table maintenance configuration. GET /accounts//r2-catalog//namespaces//tables//maintenance-configs. Path parameters: account_id, bucket_name, namespace, table_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Specifies the R2 bucket name.
namespacestringyesRequired. The namespace identifier (use %1F as separator for nested namespaces).
tableNamestringyesRequired. The table name.

[Cloudflare] List table maintenance runs. GET /accounts//r2-catalog//namespaces//tables//maintenance-runs. Path parameters: account_id, bucket_name, namespace, table_name. Optional filters: page_size, page_token. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Specifies the R2 bucket name.
namespacestringyesRequired. The R2 Data Catalog namespace, as returned by cf_list_r2_catalog_namespaces.
pageSizeintegernonullOptional. How many results to return per page.
pageTokenstringnonullOptional. The opaque paging token from the previous response. Omit it for the first page.
tableNamestringyesRequired. The Iceberg table name inside the namespace.

[Cloudflare] List namespaces in catalog. GET /accounts//r2-catalog//namespaces. Path parameters: account_id, bucket_name. Optional filters: page_token, page_size, parent, return_uuids, return_details. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Specifies the R2 bucket name.
pageSizeintegernonullOptional. Maximum number of namespaces to return per page.
pageTokenstringnonullOptional. Opaque pagination token from a previous response.
parentstringnonullOptional. Parent namespace to filter by.
returnDetailsbooleannonullOptional. Whether to include additional metadata (timestamps).
returnUuidsbooleannonullOptional. Whether to include namespace UUIDs in the response.

[Cloudflare] List tables in namespace. GET /accounts//r2-catalog//namespaces//tables. Path parameters: account_id, bucket_name, namespace. Optional filters: page_token, page_size, return_uuids, return_details. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Specifies the R2 bucket name.
namespacestringyesRequired. The namespace identifier.
pageSizeintegernonullOptional. Maximum number of tables to return per page.
pageTokenstringnonullOptional. Opaque pagination token from a previous response.
returnDetailsbooleannonullOptional. Whether to include additional metadata (timestamps, locations).
returnUuidsbooleannonullOptional. Whether to include table UUIDs in the response.

[Cloudflare] List R2 catalogs. R2 Data Catalog turns a bucket into an Apache Iceberg catalog. This lists the buckets on which it is enabled; the namespace and table tools walk what is inside one. GET /accounts//r2-catalog. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DESTRUCTIVE: Queue table maintenance. Why this is destructive: Runs compaction or snapshot expiration against the table; expiring a snapshot drops the history it held. POST /accounts//r2-catalog//namespaces//tables//maintenance-configs//queue. Path parameters: account_id, bucket_name, namespace, table_name, configuration_type. Send the request body as JSON; Cloudflare documents these fields: request_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: request_id.
bucketNamestringyesRequired. Specifies the R2 bucket name.
configurationTypestringyesRequired. The configuration_type this call targets.
namespacestringyesRequired. The R2 Data Catalog namespace, as returned by cf_list_r2_catalog_namespaces.
tableNamestringyesRequired. The Iceberg table name inside the namespace.

[Cloudflare] DESTRUCTIVE: Store catalog credentials. Why this is destructive: Stores an API token on the catalog for it to act with; it replaces whatever token was stored before. POST /accounts//r2-catalog//credential. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: token. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: token. Cloudflare requires: token.
bucketNamestringyesRequired. Specifies the R2 bucket name.

[Cloudflare] Update catalog maintenance configuration. Changes the maintenance schedule only; no maintenance is run by this call. POST /accounts//r2-catalog//maintenance-configs. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: compaction, snapshot_expiration. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: compaction, snapshot_expiration.
bucketNamestringyesRequired. Specifies the R2 bucket name.

[Cloudflare] Update table maintenance configuration. Changes the table maintenance schedule only; no maintenance is run by this call. POST /accounts//r2-catalog//namespaces//tables//maintenance-configs. Path parameters: account_id, bucket_name, namespace, table_name. Send the request body as JSON; Cloudflare documents these fields: compaction, snapshot_expiration. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: compaction, snapshot_expiration.
bucketNamestringyesRequired. Specifies the R2 bucket name.
namespacestringyesRequired. The namespace identifier (use %1F as separator for nested namespaces).
tableNamestringyesRequired. The table name.

R2 Domains

ToolPlanAccessSummary
cf_attach_r2_bucket_custom_domainProWriteAttach Custom Domain To Bucket.
cf_get_r2_bucket_custom_domainFreeRead-onlyGet Custom Domain Settings.
cf_get_r2_bucket_managed_domainFreeRead-onlyGet r2.dev Domain of Bucket.
cf_list_r2_bucket_custom_domainsFreeRead-onlyList Custom Domains of Bucket.
cf_remove_r2_bucket_custom_domainProDestructiveDESTRUCTIVE: Remove Custom Domain From Bucket.
cf_set_r2_bucket_custom_domainProDestructiveDESTRUCTIVE: Configure Custom Domain Settings.
cf_set_r2_bucket_managed_domainProWriteUpdate r2.dev Domain of Bucket.

[Cloudflare] Attach Custom Domain To Bucket. Additive: attaches a domain and changes no existing one. POST /accounts//r2/buckets//domains/custom. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: ciphers, domain, enabled, minTLS, zoneId. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: ciphers, domain, enabled, minTLS, zoneId. Cloudflare requires: domain, enabled, zoneId.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] Get Custom Domain Settings. GET /accounts//r2/buckets//domains/custom/. Path parameters: account_id, bucket_name, domain. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
domainstringyesRequired. Name of the custom domain.

[Cloudflare] Get r2.dev Domain of Bucket. GET /accounts//r2/buckets//domains/managed. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] List Custom Domains of Bucket. GET /accounts//r2/buckets//domains/custom. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] DESTRUCTIVE: Remove Custom Domain From Bucket. Why this is destructive: Detaches the domain; anything served from that hostname stops resolving. DELETE /accounts//r2/buckets//domains/custom/. Path parameters: bucket_name, account_id, domain. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
domainstringyesRequired. Name of the custom domain.

[Cloudflare] DESTRUCTIVE: Configure Custom Domain Settings. Why this is destructive: Wholesale replace of the domain settings; an omitted field reverts to its default and can take the domain offline. PUT /accounts//r2/buckets//domains/custom/. Path parameters: account_id, bucket_name, domain. Send the request body as JSON; Cloudflare documents these fields: ciphers, enabled, minTLS. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: ciphers, enabled, minTLS.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
domainstringyesRequired. Name of the custom domain.

[Cloudflare] Update r2.dev Domain of Bucket. A single reversible on/off toggle for the r2.dev domain. PUT /accounts//r2/buckets//domains/managed. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: enabled. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: enabled. Cloudflare requires: enabled.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

R2 Event Notifications

ToolPlanAccessSummary
cf_delete_r2_event_notification_rulesProDestructiveDESTRUCTIVE: Delete Event Notification Rules.
cf_get_r2_event_notification_ruleFreeRead-onlyGet Event Notification Rule.
cf_list_r2_event_notification_rulesFreeRead-onlyList Event Notification Rules.
cf_set_r2_event_notification_ruleProDestructiveDESTRUCTIVE: Create Event Notification Rule.

[Cloudflare] DESTRUCTIVE: Delete Event Notification Rules. Why this is destructive: Deletes notification rules; downstream consumers stop receiving events. DELETE /accounts//event_notifications/r2//configuration/queues/. Path parameters: queue_id, bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: ruleIds. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare documents these fields: ruleIds.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
queueIdstringyesRequired. Queue ID.

[Cloudflare] Get Event Notification Rule. GET /accounts//event_notifications/r2//configuration/queues/. Path parameters: queue_id, bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
queueIdstringyesRequired. Queue ID.

[Cloudflare] List Event Notification Rules. GET /accounts//event_notifications/r2//configuration. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] DESTRUCTIVE: Create Event Notification Rule. Why this is destructive: Wholesale replace: the queue rule list is rewritten, so a rule you omit stops firing. PUT /accounts//event_notifications/r2//configuration/queues/. Path parameters: queue_id, bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: rules. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: rules. Cloudflare requires: rules.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
queueIdstringyesRequired. Queue ID.

R2 Migration Jobs

ToolPlanAccessSummary
cf_create_r2_migration_jobProDestructiveDESTRUCTIVE: Create a Storage Class Migration Job.
cf_get_r2_bucket_jobFreeRead-onlyGet Bucket Job.
cf_get_r2_migration_jobFreeRead-onlyGet Storage Class Migration Job.
cf_list_r2_bucket_jobsFreeRead-onlyList Bucket Jobs.
cf_list_r2_migration_jobsFreeRead-onlyList Storage Class Migration Jobs.

[Cloudflare] DESTRUCTIVE: Create a Storage Class Migration Job. Why this is destructive: Rewrites the storage class of every matching object in the bucket and changes what the customer is billed for storage. POST /accounts//r2/buckets//storage-class-migration-jobs. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: destinationStorageClass, jobType, sourceStorageClass. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: destinationStorageClass, jobType, sourceStorageClass. Cloudflare requires: jobType.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.

[Cloudflare] Get Bucket Job. GET /accounts//r2/buckets//jobs/. Path parameters: account_id, bucket_name, job_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
jobIdstringyesRequired. Identifier returned when the background job was submitted.

[Cloudflare] Get Storage Class Migration Job. GET /accounts//r2/buckets//storage-class-migration-jobs/. Path parameters: account_id, bucket_name, job_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
jobIdstringyesRequired. Identifier returned when the migration job was submitted.

[Cloudflare] List Bucket Jobs. GET /accounts//r2/buckets//jobs. Path parameters: account_id, bucket_name. Optional filters: jobType, status, maxKeys, continuationToken. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
continuationTokenstringnonullOptional. Pagination token received as `nextContinuationToken` in the previous response.
jobTypestringnonullOptional. Restricts results to jobs of the specified type.
maxKeysintegernonullOptional. Maximum number of jobs to return.
statusstringnonullOptional. Restricts results to jobs with the specified status.

[Cloudflare] List Storage Class Migration Jobs. GET /accounts//r2/buckets//storage-class-migration-jobs. Path parameters: account_id, bucket_name. Optional filters: status, maxKeys, continuationToken. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
continuationTokenstringnonullOptional. Pagination token received as `nextContinuationToken` in the previous response.
maxKeysintegernonullOptional. Maximum number of jobs to return.
statusstringnonullOptional. Restricts results to jobs with the specified status.

R2 Objects

ToolPlanAccessSummary
cf_create_r2_temp_credentialsProDestructiveDESTRUCTIVE: Create Temporary Access Credentials.
cf_delete_r2_objectProDestructiveDESTRUCTIVE: Delete Object.
cf_delete_r2_objectsProDestructiveDESTRUCTIVE: Delete Objects or Empty a Bucket.
cf_list_r2_objectsFreeRead-onlyList Objects.

[Cloudflare] DESTRUCTIVE: Create Temporary Access Credentials. Why this is destructive: Mints an S3 access key pair for the bucket: a credential mint, which the wiring manifest rules destructive. POST /accounts//r2/temp-access-credentials. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: bucket, objects, parentAccessKeyId, permission, prefixes, ttlSeconds. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: bucket, objects, parentAccessKeyId, permission, prefixes, ttlSeconds. Cloudflare requires: bucket, parentAccessKeyId, permission, ttlSeconds.

[Cloudflare] DESTRUCTIVE: Delete Object. Why this is destructive: Deletes one object. Deleted R2 objects are not recoverable. DELETE /accounts//r2/buckets//objects/. Path parameters: account_id, bucket_name, object_key. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
objectKeystringyesRequired. The key (name) of the object to delete.

[Cloudflare] DESTRUCTIVE: Delete Objects or Empty a Bucket. Why this is destructive: Deletes many objects in one call - every key in the list you send, every key under the prefix you name, or EVERY object in the bucket when the prefix is sent as an empty string. Deleted R2 objects are not recoverable. Three modes, chosen by the prefix argument alone, and they are exclusive. OMIT prefix and send a JSON array of object keys as the body: exactly those objects are deleted. Send a NON-EMPTY prefix and no body: every key beginning with it goes. Send prefix as an EMPTY STRING: the whole bucket is emptied - so never pass an empty string meaning "no prefix". Both prefix modes answer with a job descriptor that cf_get_r2_bucket_job polls, and a bucket that still has event notification rules configured refuses with a 409 until they are removed. DELETE /accounts//r2/buckets//objects. Path parameters: account_id, bucket_name. Optional filters: prefix. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. Delete-by-list mode: a JSON ARRAY of object keys to delete, for example ["path/to/object-a.txt","path/to/object-b.txt"]. Send this OR a prefix, never both - Cloudflare ignores the body whenever the prefix argument is present, including when it is the empty string.
bucketNamestringyesRequired. Name of the bucket.
cfR2DataCatalogCheckstringnonullOptional. Set this header to reject the operation when R2 Data Catalog is enabled for the bucket. Sent as the cf-r2-data-catalog-check request header.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
prefixstringnonullOptional. Chooses the mode, and an EMPTY STRING is not the same as omitting it. Omit this argument entirely to delete the object keys you send in the body. Give a non-empty prefix (Cloudflare expects it to end in /) to delete every key beginning with it. Send it as an empty string to EMPTY THE WHOLE BUCKET - do not pass an empty string to mean "no prefix".

[Cloudflare] List Objects. Lists object keys and sizes, filtered by prefix and walked with a cursor. It returns metadata only: the object bytes themselves are not available through this connector. GET /accounts//r2/buckets//objects. Path parameters: account_id, bucket_name. Optional filters: per_page, prefix, delimiter, cursor, start_after. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bucketNamestringyesRequired. Name of the bucket.
cfR2JurisdictionstringnonullOptional. Jurisdiction where objects in this bucket are guaranteed to be stored. Sent as the cf-r2-jurisdiction request header.
cursorstringnonullOptional. Pagination cursor received from a previous List Objects call.
delimiterstringnonullOptional. A single character used to group keys.
perPageintegernonullOptional. Maximum number of objects to return per page.
prefixstringnonullOptional. Restricts results to only those objects whose keys begin with the specified prefix.
startAfterstringnonullOptional. Returns objects with keys that come after the specified key in lexicographic order.

Cloudflare Tunnels

ToolPlanAccessSummary
cf_cleanup_tunnel_connectionsProDestructiveDESTRUCTIVE: Clean up Cloudflare Tunnel connections.
cf_create_tunnelProWriteCreate a Cloudflare Tunnel.
cf_create_tunnel_management_tokenProDestructiveDESTRUCTIVE: Get a Cloudflare Tunnel management token.
cf_delete_tunnelProDestructiveDESTRUCTIVE: Delete a Cloudflare Tunnel.
cf_get_tunnelFreeRead-onlyGet a Cloudflare Tunnel.
cf_get_tunnel_configurationFreeRead-onlyGet Tunnel configuration.
cf_get_tunnel_connectorFreeRead-onlyGet Cloudflare Tunnel connector.
cf_get_tunnel_tokenFreeRead-onlyGet a Cloudflare Tunnel token.
cf_list_tunnel_connectionsFreeRead-onlyList Cloudflare Tunnel connections.
cf_list_tunnelsFreeRead-onlyList Cloudflare Tunnels.
cf_set_tunnel_configurationProDestructiveDESTRUCTIVE: Update Tunnel configuration.
cf_update_tunnelProWriteUpdate a Cloudflare Tunnel.

[Cloudflare] DESTRUCTIVE: Clean up Cloudflare Tunnel connections. Why this is destructive: Disconnects live connector sessions; traffic on them drops until the connector reconnects. DELETE /accounts//cfd_tunnel//connections. Path parameters: account_id, tunnel_id. Optional filters: client_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
clientIdstringnonullOptional. UUID of the Cloudflare Tunnel connector.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] Create a Cloudflare Tunnel. Additive: creates a tunnel and changes no existing one. POST /accounts//cfd_tunnel. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: config_src, name, tunnel_secret. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: config_src, name, tunnel_secret. Cloudflare requires: name.

[Cloudflare] DESTRUCTIVE: Get a Cloudflare Tunnel management token. Why this is destructive: Mints a scoped management JWT for the tunnel: a credential mint, which the wiring manifest rules destructive whatever the verb reads like. POST /accounts//cfd_tunnel//management. Path parameters: account_id, tunnel_id. Send the request body as JSON; Cloudflare documents these fields: resources. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: resources. Cloudflare requires: resources.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] DESTRUCTIVE: Delete a Cloudflare Tunnel. Why this is destructive: Deletes the tunnel; every hostname routed through it stops resolving and the connector loses its credential. DELETE /accounts//cfd_tunnel/. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] Get a Cloudflare Tunnel. Reads one tunnel with its status and active connections. A tunnel showing healthy with no connections means cloudflared is not running where you think it is. GET /accounts//cfd_tunnel/. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] Get Tunnel configuration. Returns the ingress rule list — which hostname maps to which internal service. Read it before setting a configuration, because that write replaces the whole list. GET /accounts//cfd_tunnel//configurations. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] Get Cloudflare Tunnel connector. GET /accounts//cfd_tunnel//connectors/. Path parameters: account_id, tunnel_id, connector_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
connectorIdstringyesRequired. UUID of the Cloudflare Tunnel connector.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] Get a Cloudflare Tunnel token. Returns the tunnel run token, the value cloudflared authenticates with. Treat the response as a credential: anyone holding it can run a connector for this tunnel. GET /accounts//cfd_tunnel//token. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] List Cloudflare Tunnel connections. GET /accounts//cfd_tunnel//connections. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] List Cloudflare Tunnels. The first call for Cloudflare Tunnel. Returns each tunnel with its status and connector count; is_deleted=false hides tunnels that were removed but still appear in history. GET /accounts//cfd_tunnel. Path parameters: account_id. Optional filters: name, is_deleted, existed_at, uuid, was_active_at, was_inactive_at, include_prefix, exclude_prefix, status, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
excludePrefixstringnonullOptional. The exclude_prefix filter.
existedAtstringnonullOptional. If provided, include only resources that were created (and not deleted) before this time.
includePrefixstringnonullOptional. The include_prefix filter.
isDeletedbooleannonullOptional. If `true`, only include deleted tunnels.
namestringnonullOptional. A user-friendly name for a tunnel.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of results to display.
statusstringnonullOptional. The status of the tunnel.
uuidstringnonullOptional. UUID of the tunnel.
wasActiveAtstringnonullOptional. The was_active_at filter.
wasInactiveAtstringnonullOptional. The was_inactive_at filter.

[Cloudflare] DESTRUCTIVE: Update Tunnel configuration. Why this is destructive: Wholesale replace: the whole ingress rule list is rewritten, so any rule you omit is deleted and its hostname stops routing. PUT /accounts//cfd_tunnel//configurations. Path parameters: account_id, tunnel_id. Send the request body as JSON; Cloudflare documents these fields: config. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: config.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] Update a Cloudflare Tunnel. Partial update of the tunnel name or secret; omitted fields keep their value. PATCH /accounts//cfd_tunnel/. Path parameters: tunnel_id, account_id. Send the request body as JSON; Cloudflare documents these fields: name, tunnel_secret. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: name, tunnel_secret.
tunnelIdstringyesRequired. UUID of the tunnel.

Tunnel Routes

ToolPlanAccessSummary
cf_create_tunnel_routeProWriteCreate a tunnel route.
cf_create_tunnel_route_by_cidrProWriteCreate a tunnel route (CIDR Endpoint).
cf_delete_tunnel_routeProDestructiveDESTRUCTIVE: Delete a tunnel route.
cf_delete_tunnel_route_by_cidrProDestructiveDESTRUCTIVE: Delete a tunnel route (CIDR Endpoint).
cf_get_tunnel_routeFreeRead-onlyGet tunnel route.
cf_get_tunnel_route_by_ipFreeRead-onlyGet tunnel route by IP.
cf_list_tunnel_routesFreeRead-onlyList tunnel routes.
cf_update_tunnel_routeProWriteUpdate a tunnel route.

[Cloudflare] Create a tunnel route. Additive: adds a route and changes no existing one. POST /accounts//teamnet/routes. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: comment, network, tunnel_id, virtual_network_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: comment, network, tunnel_id, virtual_network_id. Cloudflare requires: network, tunnel_id.

[Cloudflare] Create a tunnel route (CIDR Endpoint). Additive: adds a route for the CIDR you name. POST /accounts//teamnet/routes/network/. Path parameters: ip_network_encoded, account_id. Send the request body as JSON; Cloudflare documents these fields: comment, tunnel_id, virtual_network_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: comment, tunnel_id, virtual_network_id. Cloudflare requires: tunnel_id.
ipNetworkEncodedstringyesRequired. The private network as plain CIDR, for example 10.0.0.0/8. Send it exactly as you would write it; StackJack URL-encodes it for the request path, so do NOT percent-encode the slash yourself.

[Cloudflare] DESTRUCTIVE: Delete a tunnel route. Why this is destructive: Deletes the route; the private network behind it stops being reachable. DELETE /accounts//teamnet/routes/. Path parameters: route_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
routeIdstringyesRequired. UUID of the route.

[Cloudflare] DESTRUCTIVE: Delete a tunnel route (CIDR Endpoint). Why this is destructive: Deletes the route for that CIDR; the private network behind it stops being reachable. DELETE /accounts//teamnet/routes/network/. Path parameters: ip_network_encoded, account_id. Optional filters: virtual_network_id, tun_type, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
ipNetworkEncodedstringyesRequired. The private network as plain CIDR, for example 10.0.0.0/8. Send it exactly as you would write it; StackJack URL-encodes it for the request path, so do NOT percent-encode the slash yourself.
tunTypestringnonullOptional. The type of tunnel.
tunnelIdstringnonullOptional. UUID of the tunnel.
virtualNetworkIdstringnonullOptional. UUID of the virtual network.

[Cloudflare] Get tunnel route. GET /accounts//teamnet/routes/. Path parameters: account_id, route_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
routeIdstringyesRequired. UUID of the route.

[Cloudflare] Get tunnel route by IP. GET /accounts//teamnet/routes/ip/. Path parameters: ip, account_id. Optional filters: virtual_network_id, default_virtual_network_fallback. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
defaultVirtualNetworkFallbackbooleannonullOptional. When the virtual_network_id parameter is not provided the request filter will default search routes that are in the default virtual network for the account.
ipstringyesRequired. An IP address to resolve to the tunnel route that covers it.
virtualNetworkIdstringnonullOptional. UUID of the virtual network.

[Cloudflare] List tunnel routes. The private IP ranges reachable through the tunnels on this account, each bound to a tunnel and a virtual network. This is the read behind "why can this site not reach that subnet?". GET /accounts//teamnet/routes. Path parameters: account_id. Optional filters: comment, is_deleted, network_subset, network_superset, existed_at, tunnel_id, route_id, tun_types, virtual_network_id, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
commentstringnonullOptional. Optional remark describing the route.
existedAtstringnonullOptional. If provided, include only resources that were created (and not deleted) before this time.
isDeletedbooleannonullOptional. If `true`, only include deleted routes.
networkSubsetstringnonullOptional. If set, only list routes that are contained within this IP range.
networkSupersetstringnonullOptional. If set, only list routes that contain this IP range.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of results to display.
routeIdstringnonullOptional. UUID of the route.
tunTypesstringnonullOptional. The types of tunnels to filter by, separated by commas.
tunnelIdstringnonullOptional. UUID of the tunnel.
virtualNetworkIdstringnonullOptional. UUID of the virtual network.

[Cloudflare] Update a tunnel route. Partial update; omitted fields keep their value. PATCH /accounts//teamnet/routes/. Path parameters: route_id, account_id. Send the request body as JSON; Cloudflare documents these fields: comment, network, tunnel_id, virtual_network_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: comment, network, tunnel_id, virtual_network_id.
routeIdstringyesRequired. UUID of the route.

Tunnels

ToolPlanAccessSummary
cf_list_account_tunnelsFreeRead-onlyList All Tunnels.

[Cloudflare] List All Tunnels. The account-wide tunnel inventory across every tunnel TYPE. cf_list_tunnels is narrower and older: it lists Cloudflare Tunnel (cfd_tunnel) only, which is what most tunnel tools take an id from. GET /accounts//tunnels. Path parameters: account_id. Optional filters: name, is_deleted, existed_at, uuid, was_active_at, was_inactive_at, include_prefix, exclude_prefix, tun_types, status, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
excludePrefixstringnonullOptional. The exclude_prefix filter.
existedAtstringnonullOptional. If provided, include only resources that were created (and not deleted) before this time.
includePrefixstringnonullOptional. The include_prefix filter.
isDeletedbooleannonullOptional. If `true`, only include deleted tunnels.
namestringnonullOptional. A user-friendly name for the tunnel.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of results to display.
statusstringnonullOptional. The status of the tunnel.
tunTypesstringnonullOptional. The types of tunnels to filter by, separated by commas.
uuidstringnonullOptional. UUID of the tunnel.
wasActiveAtstringnonullOptional. The was_active_at filter.
wasInactiveAtstringnonullOptional. The was_inactive_at filter.

Virtual Networks

ToolPlanAccessSummary
cf_create_virtual_networkProWriteCreate a virtual network.
cf_delete_virtual_networkProDestructiveDESTRUCTIVE: Delete a virtual network.
cf_get_virtual_networkFreeRead-onlyGet a virtual network.
cf_list_virtual_networksFreeRead-onlyList virtual networks.
cf_update_virtual_networkProWriteUpdate a virtual network.

[Cloudflare] Create a virtual network. Additive: creates a virtual network and changes no existing one. POST /accounts//teamnet/virtual_networks. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: comment, is_default, is_default_network, name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: comment, is_default, is_default_network, name. Cloudflare requires: name.

[Cloudflare] DESTRUCTIVE: Delete a virtual network. Why this is destructive: Deletes the virtual network and every route scoped to it. DELETE /accounts//teamnet/virtual_networks/. Path parameters: virtual_network_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
virtualNetworkIdstringyesRequired. UUID of the virtual network.

[Cloudflare] Get a virtual network. GET /accounts//teamnet/virtual_networks/. Path parameters: account_id, virtual_network_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
virtualNetworkIdstringyesRequired. UUID of the virtual network.

[Cloudflare] List virtual networks. GET /accounts//teamnet/virtual_networks. Path parameters: account_id. Optional filters: id, name, is_default, is_default_network, is_deleted. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringnonullOptional. UUID of the virtual network.
isDefaultbooleannonullOptional. If `true`, only include the default virtual network.
isDefaultNetworkbooleannonullOptional. If `true`, only include the default virtual network.
isDeletedbooleannonullOptional. If `true`, only include deleted virtual networks.
namestringnonullOptional. A user-friendly name for the virtual network.

[Cloudflare] Update a virtual network. Partial update; omitted fields keep their value. PATCH /accounts//teamnet/virtual_networks/. Path parameters: account_id, virtual_network_id. Send the request body as JSON; Cloudflare documents these fields: comment, is_default_network, name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: comment, is_default_network, name.
virtualNetworkIdstringyesRequired. UUID of the virtual network.

WARP Connector

ToolPlanAccessSummary
cf_create_warp_connectorProWriteCreate a Warp Connector Tunnel.
cf_delete_warp_connectorProDestructiveDESTRUCTIVE: Delete a Warp Connector Tunnel.
cf_get_warp_connectorFreeRead-onlyGet a Warp Connector Tunnel.
cf_get_warp_connector_configurationFreeRead-onlyGet WARP Connector HA configuration.
cf_get_warp_connector_connectorFreeRead-onlyGet WARP Connector Tunnel connector.
cf_get_warp_connector_tokenFreeRead-onlyGet a Warp Connector Tunnel token.
cf_list_warp_connector_connectionsFreeRead-onlyList WARP Connector Tunnel connections.
cf_list_warp_connectorsFreeRead-onlyList Warp Connector Tunnels.
cf_set_warp_connector_configurationProDestructiveDESTRUCTIVE: Update WARP Connector HA configuration.
cf_trigger_warp_connector_failoverProDestructiveDESTRUCTIVE: Trigger a manual failover for a WARP Connector Tunnel.
cf_update_warp_connectorProWriteUpdate a Warp Connector Tunnel.

[Cloudflare] Create a Warp Connector Tunnel. Additive: creates a WARP Connector tunnel and changes no existing one. POST /accounts//warp_connector. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: ha, name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: ha, name. Cloudflare requires: name.

[Cloudflare] DESTRUCTIVE: Delete a Warp Connector Tunnel. Why this is destructive: Deletes the WARP Connector tunnel; the site behind it loses connectivity. DELETE /accounts//warp_connector/. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] Get a Warp Connector Tunnel. GET /accounts//warp_connector/. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] Get WARP Connector HA configuration. GET /accounts//warp_connector//configurations. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] Get WARP Connector Tunnel connector. GET /accounts//warp_connector//connectors/. Path parameters: account_id, tunnel_id, connector_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
connectorIdstringyesRequired. UUID of the Cloudflare Tunnel connector.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] Get a Warp Connector Tunnel token. Returns the WARP Connector run token. Treat the response as a credential: anyone holding it can attach a connector to this tunnel. GET /accounts//warp_connector//token. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] List WARP Connector Tunnel connections. GET /accounts//warp_connector//connections. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] List Warp Connector Tunnels. WARP Connector tunnels are the site-to-site half of Cloudflare Tunnel: a whole network behind one connector rather than a published hostname. GET /accounts//warp_connector. Path parameters: account_id. Optional filters: name, is_deleted, existed_at, uuid, was_active_at, was_inactive_at, include_prefix, exclude_prefix, status, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
excludePrefixstringnonullOptional. The exclude_prefix filter.
existedAtstringnonullOptional. If provided, include only resources that were created (and not deleted) before this time.
includePrefixstringnonullOptional. The include_prefix filter.
isDeletedbooleannonullOptional. If `true`, only include deleted tunnels.
namestringnonullOptional. A user-friendly name for the tunnel.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Number of results to display.
statusstringnonullOptional. The status of the tunnel.
uuidstringnonullOptional. UUID of the tunnel.
wasActiveAtstringnonullOptional. The was_active_at filter.
wasInactiveAtstringnonullOptional. The was_inactive_at filter.

[Cloudflare] DESTRUCTIVE: Update WARP Connector HA configuration. Why this is destructive: Wholesale replace of the high-availability configuration; anything you omit is reset. PUT /accounts//warp_connector//configurations. Path parameters: account_id, tunnel_id. Send the request body as JSON; Cloudflare documents these fields: config, ha_mode. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: config, ha_mode. Cloudflare requires: ha_mode.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] DESTRUCTIVE: Trigger a manual failover for a WARP Connector Tunnel. Why this is destructive: Dispatches a live failover: traffic moves to another connector and sessions on the current one break. PUT /accounts//warp_connector//failover. Path parameters: account_id, tunnel_id. Send the request body as JSON; Cloudflare documents these fields: client_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: client_id. Cloudflare requires: client_id.
tunnelIdstringyesRequired. UUID of the tunnel.

[Cloudflare] Update a Warp Connector Tunnel. Partial update of the name or secret; omitted fields keep their value. PATCH /accounts//warp_connector/. Path parameters: account_id, tunnel_id. Send the request body as JSON; Cloudflare documents these fields: name, tunnel_secret. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: name, tunnel_secret.
tunnelIdstringyesRequired. UUID of the tunnel.

Members

ToolPlanAccessSummary
cf_create_organizations_memberProDestructiveDESTRUCTIVE: Create organization member.
cf_delete_organizations_memberProDestructiveDESTRUCTIVE: Delete organization member.
cf_get_organizations_memberFreeRead-onlyGet organization member.
cf_list_organizations_membersFreeRead-onlyList organization members.

[Cloudflare] DESTRUCTIVE: Create organization member. Why this is destructive: Changes a membership, role, policy or permission - who or what may reach the resource, or what they may do with it. It takes effect immediately. POST /organizations//members. Path parameters: organization_id. Send the request body as JSON; Cloudflare documents these fields: member. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: member. Cloudflare requires: member.
organizationIdstringyesRequired. The organization_id this call targets.

[Cloudflare] DESTRUCTIVE: Delete organization member. Why this is destructive: Deletes the resource this path names. Cloudflare removes it on success and the API offers no undo for it here. DELETE /organizations//members/. Path parameters: organization_id, member_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
memberIdstringyesRequired. Organization Member ID.
organizationIdstringyesRequired. The organization_id this call targets.

[Cloudflare] Get organization member. GET /organizations//members/. Path parameters: organization_id, member_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
memberIdstringyesRequired. Organization Member ID.
organizationIdstringyesRequired. The organization_id this call targets.

[Cloudflare] List organization members. Start here before any member write: the member id every other member tool takes is only returned by this list. The user.email filters (exact, contains, startsWith, endsWith) are how you find one person without paging the whole organization. GET /organizations//members. Path parameters: organization_id. Optional filters: status, user.email, user.email.contains, user.email.startsWith, user.email.endsWith, page_token, page_size. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
organizationIdstringyesRequired. The organization_id this call targets.
pageSizeintegernonullOptional. The amount of items to return.
pageTokenstringnonullOptional. An opaque token returned from the last list response that when provided will retrieve the next page.
statusstringnonullOptional. Filter the list of memberships by membership status.
userEmailstringnonullOptional. Filter the list of memberships for a specific email.
userEmailContainsstringnonullOptional. Filter the list of memberships for a specific email that contains a substring.
userEmailEndsWithstringnonullOptional. Filter the list of memberships for a specific email that ends with a substring.
userEmailStartsWithstringnonullOptional. Filter the list of memberships for a specific email that starts with a substring.

Members:batchCreate

ToolPlanAccessSummary
cf_create_organizations_members_batchProWriteBatch create organization members.

[Cloudflare] Batch create organization members. Additive: creates a new record and changes no existing one. One call adds many members. Cloudflare applies the batch as a unit and answers with the created members; there is no partial-success mode to inspect, so send a batch you are willing to have applied whole. POST /organizations//members:batchCreate. Path parameters: organization_id. Send the request body as JSON; Cloudflare documents these fields: members. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: members. Cloudflare requires: members.
organizationIdstringyesRequired. The organization_id this call targets.

Tenant Accounts

ToolPlanAccessSummary
cf_list_organizations_accountsFreeRead-onlyGet organization accounts.

[Cloudflare] Get organization accounts. GET /organizations//accounts. Path parameters: organization_id. Optional filters: account_pubname, account_pubname.startsWith, account_pubname.endsWith, account_pubname.contains, name, name.startsWith, name.endsWith, name.contains, order_by, direction, include_tags, include_total, page_token, page_size. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountPubnamestringnonullOptional. (case-insensitive) Filter the list of accounts to where the account_pubname is equal to a particular string.
accountPubnameContainsstringnonullOptional. (case-insensitive) Filter the list of accounts to where the account_pubname contains a particular string.
accountPubnameEndsWithstringnonullOptional. (case-insensitive) Filter the list of accounts to where the account_pubname ends with a particular string.
accountPubnameStartsWithstringnonullOptional. (case-insensitive) Filter the list of accounts to where the account_pubname starts with a particular string.
directionstringnonullOptional. Sort direction for the order_by field.
includeTagsbooleannonullOptional. Include Account tags from the resource tag mirror.
includeTotalbooleannonullOptional. Whether to calculate and return the exact result_info.total_size for cursor pagination.
namestringnonullOptional. (case-insensitive) Filter the list of accounts to where the name is equal to a particular string.
nameContainsstringnonullOptional. (case-insensitive) Filter the list of accounts to where the name contains a particular string.
nameEndsWithstringnonullOptional. (case-insensitive) Filter the list of accounts to where the name ends with a particular string.
nameStartsWithstringnonullOptional. (case-insensitive) Filter the list of accounts to where the name starts with a particular string.
orderBystringnonullOptional. Field to order results by.
organizationIdstringyesRequired. The ID of the organization to retrieve a list of accounts for.
pageSizeintegernonullOptional. The amount of items to return.
pageTokenstringnonullOptional. An opaque token returned from the last list response that when provided will retrieve the next page.

Tenant Billable

ToolPlanAccessSummary
cf_get_organization_billable_usageFreeRead-onlyGet Organization Usage (Version 2, Alpha, Restricted).

[Cloudflare] Get Organization Usage (Version 2, Alpha, Restricted). Cloudflare labels this endpoint Version 2, ALPHA and RESTRICTED in its own document: the contract may change without notice and the call 403s unless the tenant contract enables it. from/to bound the usage window. GET /organizations//billable/usage. Path parameters: organization_id. Optional filters: from, to. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
fromstringnonullOptional. Start date for the usage query (ISO 8601).
organizationIdstringyesRequired. Identifies the Cloudflare organization.
tostringnonullOptional. End date for the usage query (ISO 8601).

Tenant Logs

ToolPlanAccessSummary
cf_get_organization_audit_log_entry_historyFreeRead-onlyGet resource change history from an organization audit log entry (Version 2).
cf_list_organizations_logs_auditsFreeRead-onlyGet organization audit logs (Version 2).

[Cloudflare] Get resource change history from an organization audit log entry (Version 2). GET /organizations//logs/audit//history. Path parameters: organization_id, id. Cloudflare REQUIRES these query parameters and answers 400 without it: action_time, since, before. Optional filters: direction, limit, cursor. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
actionTimestringnonullRequired by Cloudflare - the call fails without it. RFC3339 timestamp of the source audit log entry's action time.
beforestringnonullRequired by Cloudflare - the call fails without it. Limits the returned results to logs older than the specified date.
cursorstringnonullOptional. The cursor is an opaque token used to paginate through large sets of records.
directionstringnonullOptional. Sets sorting order.
idstringyesRequired. The ID of the audit log to fetch resource history for.
limitintegernonullOptional. The number limits the objects to return.
organizationIdstringyesRequired. The unique ID that identifies the organization.
sincestringnonullRequired by Cloudflare - the call fails without it. Limits the returned results to logs newer than the specified date.

[Cloudflare] Get organization audit logs (Version 2). GET /organizations//logs/audit. Path parameters: organization_id. Cloudflare REQUIRES these query parameters and answers 400 without it: since, before. Optional filters: action_result, action_type, actor_context, actor_email, actor_id, actor_ip_address, actor_token_id, actor_token_name, actor_type, id, raw_cf_ray_id, raw_method, raw_status_code, raw_uri, resource_id, resource_product, resource_type, resource_scope, action_result.not, action_type.not, actor_context.not, actor_email.not, actor_id.not, actor_ip_address.not, actor_token_id.not, actor_token_name.not, actor_type.not, id.not, raw_cf_ray_id.not, raw_method.not, raw_status_code.not, raw_uri.not, resource_id.not, resource_product.not, resource_type.not, resource_scope.not, direction, limit, cursor. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
actionResultstringnonullOptional. Filters by whether the action was successful or not.
actionResultNotstringnonullOptional. Filters out audit logs by whether the action was successful or not.
actionTypestringnonullOptional. Filters by the action type.
actionTypeNotstringnonullOptional. Filters out audit logs by the action type.
actorContextstringnonullOptional. Filters by the actor context.
actorContextNotstringnonullOptional. Filters out audit logs by the actor context.
actorEmailstringnonullOptional. Filters by the actor's email address.
actorEmailNotstringnonullOptional. Filters out audit logs by the actor's email address.
actorIdstringnonullOptional. Filters by the actor's user ID.
actorIdNotstringnonullOptional. Filters out audit logs by the actor's user ID.
actorIpAddressstringnonullOptional. The IP address where the action was initiated.
actorIpAddressNotstringnonullOptional. Filters out audit logs IP address where the action was initiated.
actorTokenIdstringnonullOptional. Filters by the API token ID when the actor context is an api_token or oauth.
actorTokenIdNotstringnonullOptional. Filters out audit logs by the API token ID when the actor context is an api_token or oauth.
actorTokenNamestringnonullOptional. Filters by the API token name when the actor context is an api_token or oauth.
actorTokenNameNotstringnonullOptional. Filters out audit logs by the API token name when the actor context is an api_token or oauth.
actorTypestringnonullOptional. Filters by the actor type.
actorTypeNotstringnonullOptional. Filters out audit logs by the actor type.
beforestringnonullRequired by Cloudflare - the call fails without it. Limits the returned results to logs older than the specified date.
cursorstringnonullOptional. The cursor is an opaque token used to paginate through large sets of records.
directionstringnonullOptional. Sets sorting order.
idstringnonullOptional. Finds a specific log by its ID.
idNotstringnonullOptional. Filters out audit logs by their IDs.
limitintegernonullOptional. The number limits the objects to return.
organizationIdstringyesRequired. The unique id that identifies the organization.
rawCfRayIdstringnonullOptional. Filters by the response CF Ray ID.
rawCfRayIdNotstringnonullOptional. Filters out audit logs by the response CF Ray ID.
rawMethodstringnonullOptional. The HTTP method for the API call.
rawMethodNotstringnonullOptional. Filters out audit logs by the HTTP method for the API call.
rawStatusCodestringnonullOptional. The response status code that was returned.
rawStatusCodeNotstringnonullOptional. Filters out audit logs by the response status code that was returned.
rawUristringnonullOptional. Filters by the request URI.
rawUriNotstringnonullOptional. Filters out audit logs by the request URI.
resourceIdstringnonullOptional. Filters by the resource ID.
resourceIdNotstringnonullOptional. Filters out audit logs by the resource ID.
resourceProductstringnonullOptional. Filters audit logs by the Cloudflare product associated with the changed resource.
resourceProductNotstringnonullOptional. Filters out audit logs by the Cloudflare product associated with the changed resource.
resourceScopestringnonullOptional. Filters by the resource scope, specifying whether the resource is associated with an organization.
resourceScopeNotstringnonullOptional. Filters out audit logs by the resource scope, specifying whether the resource is associated with an organization.
resourceTypestringnonullOptional. Filters audit logs based on the unique type of resource changed by the action.
resourceTypeNotstringnonullOptional. Filters out audit logs based on the unique type of resource changed by the action.
sincestringnonullRequired by Cloudflare - the call fails without it. Limits the returned results to logs newer than the specified date.

Tenant Organizations

ToolPlanAccessSummary
cf_create_organizationProWriteCreate organization.
cf_delete_organizationProDestructiveDESTRUCTIVE: Delete organization.
cf_get_organizationFreeRead-onlyGet organization.
cf_list_tenant_organizationsFreeRead-onlyList organizations the user has access to.
cf_set_organizationProDestructiveDESTRUCTIVE: Modify organization.

[Cloudflare] Create organization. Additive: creates a new record and changes no existing one. POST /organizations. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: create_time, id, meta, name, parent, profile. name is the one you choose; parent and profile apply where the tenant model uses them. create_time, id and meta are readOnly in Cloudflare's own schema: it assigns them and returns them in the response, so an id or a create_time of your own is ignored at best and the organization's real id is the one that comes back.

[Cloudflare] DESTRUCTIVE: Delete organization. Why this is destructive: Deletes the organization itself. Every account, member and share under it goes with it and the API offers no undo; a tenant provider does this only after the accounts have been moved or closed. DELETE /organizations/. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
organizationIdstringyesRequired. The ID of the organization to delete.

[Cloudflare] Get organization. GET /organizations/. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
organizationIdstringyesRequired. The ID of the organization to retrieve.

[Cloudflare] List organizations the user has access to. The Tenant API root list: every organization this API token can see, which is where a tenant-provisioning session starts. The account-scoped twin cf_list_organizations answers the organizations INSIDE one account and takes an account id. GET /organizations. Optional filters: id, name, name.startsWith, name.endsWith, name.contains, containing.account, containing.user, containing.organization, parent.id, page_token, page_size. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
containingAccountstringnonullOptional. Filter the list of organizations to the ones that contain this particular account.
containingOrganizationstringnonullOptional. Filter the list of organizations to the ones that contain this particular organization.
containingUserstringnonullOptional. Filter the list of organizations to the ones that contain this particular user.
idstringnonullOptional. Only return organizations with the specified IDs (ex.
namestringnonullOptional. (case-sensitive) Filter the list of organizations to where the name is equal to a particular string.
nameContainsstringnonullOptional. (case-insensitive) Filter the list of organizations to where the name contains a particular string.
nameEndsWithstringnonullOptional. (case-insensitive) Filter the list of organizations to where the name ends with a particular string.
nameStartsWithstringnonullOptional. (case-insensitive) Filter the list of organizations to where the name starts with a particular string.
pageSizeintegernonullOptional. The amount of items to return.
pageTokenstringnonullOptional. An opaque token returned from the last list response that when provided will retrieve the next page.
parentIdstringnonullOptional. Filter the list of organizations to the ones that are a sub-organization of the specified organization.

[Cloudflare] DESTRUCTIVE: Modify organization. Why this is destructive: Wholesale replace: the organization record is rewritten from the body, so a field you omit reverts to its default rather than keeping its current value. Read it with cf_get_organization first and send the whole object back. PUT /organizations/. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON, and it REPLACES the organization record: a field you omit reverts to its default rather than keeping its stored value, so read it with cf_get_organization first and send the whole object back. Cloudflare documents these fields: create_time, id, meta, name, parent, profile; create_time, id and meta are readOnly in its own schema, and the organization this call targets is the in the path.
organizationIdstringyesRequired. The ID of the organization to modify.

Tenant Profile

ToolPlanAccessSummary
cf_get_organizations_profilesFreeRead-onlyGet organization profile.
cf_set_organizations_profileProDestructiveDESTRUCTIVE: Modify organization profile.

[Cloudflare] Get organization profile. GET /organizations//profile. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
organizationIdstringyesRequired. The ID of the organization to retrieve a profile for.

[Cloudflare] DESTRUCTIVE: Modify organization profile. Why this is destructive: Wholesale replace of the organization profile; omitted fields revert. Read cf_get_organizations_profiles first. PUT /organizations//profile. Path parameters: organization_id. Send the request body as JSON; Cloudflare documents these fields: business_address, business_email, business_name, business_phone, external_metadata. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: business_address, business_email, business_name, business_phone, external_metadata. Cloudflare requires: business_address, business_email, business_name, business_phone, external_metadata.
organizationIdstringyesRequired. The organization_id this call targets.

Tenant Provisioning

ToolPlanAccessSummary
cf_add_tenant_custom_nameserverProWriteAdd Tenant Custom Nameserver.
cf_delete_tenant_custom_nameserverProDestructiveDESTRUCTIVE: Delete Tenant Custom Nameserver.
cf_get_tenantFreeRead-onlyGet tenant.
cf_list_tenant_account_typesFreeRead-onlyGet tenant account types.
cf_list_tenant_accountsFreeRead-onlyList tenant accounts.
cf_list_tenant_custom_nameserversFreeRead-onlyList Tenant Custom Nameservers.
cf_list_tenant_entitlementsFreeRead-onlyList tenant entitlements.
cf_list_tenant_membershipsFreeRead-onlyList tenant memberships.
cf_list_user_tenantsFreeRead-onlyList user tenants.

[Cloudflare] Add Tenant Custom Nameserver. Additive: adds a nameserver to the tenant set. POST /tenants//custom_ns. Path parameters: tenant_tag. Send the request body as JSON; Cloudflare documents these fields: ns_name, ns_set. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Cloudflare documents these fields: ns_name, ns_set. Cloudflare requires: ns_name.
tenantTagstringyesRequired. The partner tenant tag, as returned by cf_list_user_tenants. It is a separate identifier from the tenant id.

[Cloudflare] DESTRUCTIVE: Delete Tenant Custom Nameserver. Why this is destructive: Removes a custom nameserver; zones delegated to it stop resolving. DELETE /tenants//custom_ns/. Path parameters: custom_ns_id, tenant_tag. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
customNsIdstringyesRequired. The FQDN of the name server.
tenantTagstringyesRequired. The partner tenant tag, as returned by cf_list_user_tenants. It is a separate identifier from the tenant id.

[Cloudflare] Get tenant. GET /tenants/. Path parameters: tenant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
tenantIdstringyesRequired. The partner tenant id, as returned by cf_list_user_tenants.

[Cloudflare] Get tenant account types. GET /tenants//account_types. Path parameters: tenant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
tenantIdstringyesRequired. The partner tenant id, as returned by cf_list_user_tenants.

[Cloudflare] List tenant accounts. The customer accounts provisioned under a partner tenant. Use it to walk a partner estate; the account id it returns is the one every account-scoped tool takes. GET /tenants//accounts. Path parameters: tenant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
tenantIdstringyesRequired. The partner tenant id, as returned by cf_list_user_tenants.

[Cloudflare] List Tenant Custom Nameservers. GET /tenants//custom_ns. Path parameters: tenant_tag. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
tenantTagstringyesRequired. The partner tenant tag, as returned by cf_list_user_tenants. It is a separate identifier from the tenant id.

[Cloudflare] List tenant entitlements. GET /tenants//entitlements. Path parameters: tenant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
tenantIdstringyesRequired. The partner tenant id, as returned by cf_list_user_tenants.

[Cloudflare] List tenant memberships. GET /tenants//memberships. Path parameters: tenant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
tenantIdstringyesRequired. The partner tenant id, as returned by cf_list_user_tenants.

[Cloudflare] List user tenants. Tells you immediately whether the stored token has partner Tenant access at all. An empty result means it does not, which is the ordinary case — the tenant surface is a Channel and Alliance partner mechanism. GET /user/tenants. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

Tenant Shares

ToolPlanAccessSummary
cf_list_organizations_sharesFreeRead-onlyList organization shares.

[Cloudflare] List organization shares. GET /organizations//shares. Path parameters: organization_id. Optional filters: status, kind, target_type, resource_types, order, direction, page, per_page. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
directionstringnonullOptional. Direction to sort objects.
kindstringnonullOptional. Filter shares by kind.
orderstringnonullOptional. Order shares by values in the given field.
organizationIdstringyesRequired. Organization identifier.
pageintegernonullOptional. Page number.
perPageintegernonullOptional. Number of objects to return per page.
resourceTypesstringnonullOptional. Filter share resources by resource_types.
statusstringnonullOptional. Filter shares by status.
targetTypestringnonullOptional. Filter shares by target_type.

Access Apps

ToolPlanAccessSummary
cf_create_access_appProWriteAdd an Access application.
cf_create_access_apps_caProWriteCreate a short-lived certificate CA.
cf_create_access_apps_policyProDestructiveDESTRUCTIVE: Create an Access application policy.
cf_create_zones_access_appProWriteAdd an Access application.
cf_create_zones_access_apps_caProWriteCreate a short-lived certificate CA.
cf_create_zones_access_apps_policyProDestructiveDESTRUCTIVE: Create an Access policy.
cf_delete_access_appProDestructiveDESTRUCTIVE: Delete an Access application.
cf_delete_access_apps_caProDestructiveDESTRUCTIVE: Delete a short-lived certificate CA.
cf_delete_access_apps_policyProDestructiveDESTRUCTIVE: Delete an Access application policy.
cf_delete_zones_access_appProDestructiveDESTRUCTIVE: Delete an Access application.
cf_delete_zones_access_apps_caProDestructiveDESTRUCTIVE: Delete a short-lived certificate CA.
cf_delete_zones_access_apps_policyProDestructiveDESTRUCTIVE: Delete an Access policy.
cf_get_access_appFreeRead-onlyGet an Access application.
cf_get_access_apps_casFreeRead-onlyGet a short-lived certificate CA.
cf_get_access_apps_policyFreeRead-onlyGet an Access application policy.
cf_get_access_apps_user_policy_checksFreeRead-onlyTest Access policies.
cf_get_zones_access_appFreeRead-onlyGet an Access application.
cf_get_zones_access_apps_casFreeRead-onlyGet a short-lived certificate CA.
cf_get_zones_access_apps_policyFreeRead-onlyGet an Access policy.
cf_get_zones_access_apps_user_policy_checksFreeRead-onlyTest Access policies.
cf_list_access_appsFreeRead-onlyList Access applications.
cf_list_access_apps_casFreeRead-onlyList short-lived certificate CAs.
cf_list_access_apps_policiesFreeRead-onlyList Access application policies.
cf_list_zones_access_appsFreeRead-onlyList Access Applications.
cf_list_zones_access_apps_casFreeRead-onlyList short-lived certificate CAs.
cf_list_zones_access_apps_policiesFreeRead-onlyList Access policies.
cf_make_reusable_access_apps_policiesProDestructiveDESTRUCTIVE: Convert an Access application policy to a reusable policy.
cf_revoke_access_app_tokensProDestructiveDESTRUCTIVE: Revoke application tokens.
cf_revoke_zones_access_app_tokensProDestructiveDESTRUCTIVE: Revoke application tokens.
cf_set_access_appProDestructiveDESTRUCTIVE: Update an Access application.
cf_set_access_apps_policyProDestructiveDESTRUCTIVE: Update an Access application policy.
cf_set_access_apps_settingProDestructiveDESTRUCTIVE: Update Access application settings.
cf_set_zones_access_appProDestructiveDESTRUCTIVE: Update an Access application.
cf_set_zones_access_apps_policyProDestructiveDESTRUCTIVE: Update an Access policy.
cf_set_zones_access_apps_settingProDestructiveDESTRUCTIVE: Update application settings.
cf_update_access_apps_settingProWriteUpdate Access application settings.
cf_update_zones_access_apps_settingProWriteUpdate application settings.

[Cloudflare] Add an Access application. Additive: it creates one new application and changes no existing one. The application is live as soon as Cloudflare stores it, so a self_hosted app whose domain is already serving traffic starts requiring an Access login on the next request. The app type decides the whole body shape. POST /accounts//access/apps. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON, and Cloudflare accepts THIRTEEN different shapes chosen by the type field: self_hosted (requires domain and type), saas (carries the saas_app object - SAML or OIDC), ssh, vnc, app_launcher, warp, biso, bookmark, infrastructure (requires target_criteria and type), rdp (requires target_criteria), mcp and mcp_portal. Fields common to nearly all of them: name, policies (an array of reusable policy ids or inline policy objects), allowed_idps, session_duration, auto_redirect_to_identity, tags and scim_config. Send the shape for the type you chose - a field from another shape is rejected.

[Cloudflare] Create a short-lived certificate CA. Additive: it generates a new short-lived certificate CA and public key for this application. An application can hold one CA, so read cf_get_access_apps_cas first - and the new public key must be installed on every target host before browser SSH works. POST /accounts//access/apps//ca. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Create an Access application policy. Why this is destructive: An Access policy is what decides who may reach the customer's internal application: change it and the next request from a real user is allowed or refused by the new rule, with no deploy step in between. This one creates a policy scoped exclusively to this application. Cloudflare itself recommends creating a REUSABLE policy with cf_create_access_policy and referencing its id from the application instead. POST /accounts//access/apps//policies. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The application ID.
bodyJsonstringyesRequired. The request body as JSON. name, decision and include are required: decision is allow, deny, non_identity or bypass, and include is an ARRAY of rule objects - one key each, from email, email_list, email_domain, everyone, ip, ip_list, geo, group, certificate, common_name, service_token, any_valid_service_token, linked_app_token, auth_method, auth_context, login_method, device_posture, user_risk_score, external_evaluation, azureAD, github-organization, gsuite, okta, saml, oidc or cloudflare_account_member. exclude and require take the same array shape; require rules must all match and exclude rules deny outright. Optional: precedence (lower runs first), session_duration, approval_required with approval_groups, purpose_justification_required and isolation_required.

[Cloudflare] Add an Access application. Additive: it creates one application on this zone and changes no existing one. The application takes effect immediately, so a self_hosted app on a domain already serving traffic starts requiring an Access login on the next request. ZONE-scoped: this route reaches the Access applications of ONE zone, not the whole account. Use the account-level twin for an account-wide view. POST /zones//access/apps. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON, in one of EIGHT type-keyed shapes: self_hosted (requires domain and type), saas (carries saas_app - SAML or OIDC), ssh, vnc, app_launcher, warp, biso and bookmark (requires domain and type). Common fields: name, policies, allowed_idps, session_duration, auto_redirect_to_identity and scim_config. Send the shape for the type you chose.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Create a short-lived certificate CA. Additive: it generates a new short-lived certificate CA and public key for this application. The new public key must reach every target host before browser SSH works. POST /zones//access/apps//ca. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Create an Access policy. Why this is destructive: An Access policy is what decides who may reach the customer's internal application: change it and the next request from a real user is allowed or refused by the new rule, with no deploy step in between. This creates a policy on a zone-level application. POST /zones//access/apps//policies. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. UUID.
bodyJsonstringyesRequired. The request body as JSON. name, decision and include are required: decision is allow, deny, non_identity or bypass, and include is an ARRAY of one-key rule objects (email, email_domain, everyone, ip, group, service_token, any_valid_service_token, certificate, azureAD, github-organization, gsuite, okta, saml and the rest of Cloudflare's rule vocabulary). exclude and require take the same shape. Optional: precedence, approval_required with approval_groups, purpose_justification_required and isolation_required.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete an Access application. Why this is destructive: The application stops existing, and with it every policy scoped exclusively to it. Users who reach the domain are no longer challenged by Access at all, so whatever the origin serves is exposed to anyone who can route to it. There is no undo. DELETE /accounts//access/apps/. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The app_id this call targets.

[Cloudflare] DESTRUCTIVE: Delete a short-lived certificate CA. Why this is destructive: The short-lived certificate CA for this application is destroyed. Every SSH certificate it signed stops validating, so users mid-session lose access to the target hosts, and the hosts keep trusting a CA public key that no longer signs anything until it is replaced. DELETE /accounts//access/apps//ca. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Delete an Access application policy. Why this is destructive: The policy is removed from the application. If it was the last policy allowing a group of users in, they lose access on their next request; if it was the only DENY, whoever it kept out is now allowed in by the remaining policies. A reusable policy is deleted with cf_delete_access_policy instead - this route only removes the app-scoped one. DELETE /accounts//access/apps//policies/. Path parameters: app_id, policy_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The application ID.
policyIdstringyesRequired. The policy ID.

[Cloudflare] DESTRUCTIVE: Delete an Access application. Why this is destructive: The application stops existing, along with every policy scoped exclusively to it, and the domain it protected is no longer challenged by Access at all. There is no undo. DELETE /zones//access/apps/. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. The app_id this call targets.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete a short-lived certificate CA. Why this is destructive: The short-lived certificate CA for this application is destroyed, every SSH certificate it signed stops validating, and the target hosts keep trusting a CA public key that no longer signs anything until it is replaced. DELETE /zones//access/apps//ca. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete an Access policy. Why this is destructive: The policy is removed from the application. Losing the last allow rule locks the application's users out; losing a deny rule lets whoever it excluded back in. DELETE /zones//access/apps//policies/. Path parameters: policy_id, app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. UUID. Fills the segment of the request path.
policyIdstringyesRequired. UUID. Fills the segment of the request path.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Get an Access application. The single-application read behind cf_list_access_apps, including the app's inline policies, its allowed identity providers and (for a SaaS app) its saas_app block. GET /accounts//access/apps/. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The app_id this call targets.

[Cloudflare] Get a short-lived certificate CA. Returns the CA and its PUBLIC key for one application - the key an administrator pastes into the target host's trusted-user-CA configuration. GET /accounts//access/apps//ca. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. UUID.

[Cloudflare] Get an Access application policy. Fetches one policy of an application, whether it is owned exclusively by the app or a reusable policy the app references. GET /accounts//access/apps//policies/. Path parameters: app_id, policy_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The application ID.
policyIdstringyesRequired. The policy ID.

[Cloudflare] Test Access policies. A DRY RUN, despite the vendor calling it a test: it evaluates this application's policies for the calling identity and reports which ones matched. It changes nothing and grants nothing. GET /accounts//access/apps//user_policy_checks. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The app_id this call targets.

[Cloudflare] Get an Access application. The zone-scoped single-application read, including the app's inline policies and its saas_app block when it is a SaaS application. GET /zones//access/apps/. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. The app_id this call targets.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Get a short-lived certificate CA. Returns the CA and its PUBLIC key for one zone-level application - the key that goes into the target host's trusted-user-CA configuration. GET /zones//access/apps//ca. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Get an Access policy. Fetches a single policy of a zone-level Access application. GET /zones//access/apps//policies/. Path parameters: policy_id, app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. UUID. Fills the segment of the request path.
policyIdstringyesRequired. UUID. Fills the segment of the request path.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Test Access policies. A DRY RUN: it evaluates the zone-level application's policies for the calling identity and reports which matched. It changes nothing and grants nothing. GET /zones//access/apps//user_policy_checks. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. The app_id this call targets.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List Access applications. Account-scoped: Access applications live on the account, and this is the route Cloudflare's current documentation uses. This is the reach-first read of the whole Access surface: every other apps tool takes its app_id (the uid Cloudflare returns) from here, and each row carries the app type (self_hosted, saas, ssh, vnc, app_launcher, warp, biso, bookmark, infrastructure, rdp, mcp), its domain and its inline policies. The aud value is the application audience tag an Access JWT is issued for. GET /accounts//access/apps. Path parameters: account_id. Optional filters: name, domain, aud, target_attributes, exact, search, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
audstringnonullOptional. The application audience (AUD) tag - the value an Access JWT carries for this app. Use it to find the app a token belongs to.
domainstringnonullOptional. The domain of the app.
exactbooleannonullOptional. True matches the name and domain filters exactly instead of as substrings.
namestringnonullOptional. The name of the app.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.
searchstringnonullOptional. Free-text search across the other listed filters.
targetAttributesstringnonullOptional. Infrastructure applications only: filter by target criteria in key=value form.

[Cloudflare] List short-lived certificate CAs. A short-lived certificate CA is what signs the ephemeral SSH certificates Access issues for a browser-SSH application; the response is the CA's PUBLIC key, never a private key. Each row names the app_id whose CA it is. GET /accounts//access/apps/ca. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.

[Cloudflare] List Access application policies. Lists the policies attached to ONE application, both the policies owned exclusively by it and the reusable policies it references. Each row carries the decision (allow, deny, non_identity or bypass), its precedence and its include, exclude and require rules. GET /accounts//access/apps//policies. Path parameters: app_id, account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The application ID.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.

[Cloudflare] List Access Applications. ZONE-scoped: this route reaches the Access applications of ONE zone, not the whole account. Use the account-level twin for an account-wide view. The zone route offers a smaller application shape than the account one (eight types, no infrastructure or MCP applications) and no filters at all. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/apps. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List short-lived certificate CAs. The zone-scoped list of short-lived certificate CAs and their PUBLIC keys, one per browser-SSH application in this zone. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/apps/ca. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List Access policies. Lists the policies attached to one zone-level application, with each policy's decision, precedence and rule lists. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/apps//policies. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Convert an Access application policy to a reusable policy. Why this is destructive: This conversion is ONE-WAY and Cloudflare documents no reverse. The policy stops being owned by this application and becomes an account-level reusable policy, so every later edit has to go through cf_set_access_policy - and an edit made there then changes every application that references it, not just this one. Takes no request body: the path alone names the policy to convert. PUT /accounts//access/apps//policies//make_reusable. Path parameters: app_id, policy_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The application ID.
policyIdstringyesRequired. The policy ID.

[Cloudflare] DESTRUCTIVE: Revoke application tokens. Why this is destructive: It revokes ALL tokens issued for this application, and it mints nothing. Every user with a live Access session for the app is signed out immediately and has to authenticate again at the identity provider; service tokens presented afterwards are refused the same way. Use it when a session is believed compromised, not as routine maintenance. POST /accounts//access/apps//revoke_tokens. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The app_id this call targets.

[Cloudflare] DESTRUCTIVE: Revoke application tokens. Why this is destructive: It revokes ALL tokens issued for this application and mints nothing. Every live Access session for the app ends at once and each user has to authenticate again. POST /zones//access/apps//revoke_tokens. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. The app_id this call targets.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Update an Access application. Why this is destructive: A PUT replaces the WHOLE application from the body. A field you leave out is cleared, not kept - omitting policies detaches every policy from the app, and omitting allowed_idps drops the identity provider restriction. Read the app with cf_get_access_app first and send it back changed. PUT /accounts//access/apps/. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The app_id this call targets.
bodyJsonstringyesRequired. The request body as JSON, and it is the SAME thirteen type-keyed shapes as cf_create_access_app (self_hosted, saas, ssh, vnc, app_launcher, warp, biso, bookmark, infrastructure, rdp, mcp, mcp_portal). It REPLACES the stored application: send every field you want to keep, not only the ones you are changing.

[Cloudflare] DESTRUCTIVE: Update an Access application policy. Why this is destructive: An Access policy is what decides who may reach the customer's internal application: change it and the next request from a real user is allowed or refused by the new rule, with no deploy step in between. A PUT replaces the whole policy from the body, so an include or exclude rule you leave out is deleted - omit the include array's service_token rule and every machine client using that token is locked out on the next call. PUT /accounts//access/apps//policies/. Path parameters: app_id, policy_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The application ID.
bodyJsonstringyesRequired. The request body as JSON, the same shape as cf_create_access_apps_policy (name, decision and include required; include, exclude and require are ARRAYS of one-key rule objects). It REPLACES the policy: send every rule you want to keep.
policyIdstringyesRequired. The policy ID.

[Cloudflare] DESTRUCTIVE: Update Access application settings. Why this is destructive: A PUT replaces the whole settings object, so a field you omit falls back to Cloudflare's default rather than keeping its stored value. Use cf_update_access_apps_setting when you only mean to change one of them. PUT /accounts//access/apps//settings. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The app_id this call targets.
bodyJsonstringyesRequired. The request body as JSON with allow_iframe (allow the application to be rendered inside an iframe) and skip_interstitial (skip the Access interstitial before the identity redirect). It REPLACES the settings object - send both.

[Cloudflare] DESTRUCTIVE: Update an Access application. Why this is destructive: A PUT replaces the WHOLE application from the body: omit policies and every policy detaches from the app, omit allowed_idps and the identity provider restriction is gone. Read it with cf_get_zones_access_app first and send it back changed. PUT /zones//access/apps/. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. The app_id this call targets.
bodyJsonstringyesRequired. The request body as JSON, the same EIGHT type-keyed shapes as cf_create_zones_access_app. It REPLACES the stored application: send every field you want to keep, not only the ones you are changing.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Update an Access policy. Why this is destructive: An Access policy is what decides who may reach the customer's internal application: change it and the next request from a real user is allowed or refused by the new rule, with no deploy step in between. A PUT replaces the whole policy from the body, so any include, exclude or require rule you leave out is deleted. PUT /zones//access/apps//policies/. Path parameters: policy_id, app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. UUID. Fills the segment of the request path.
bodyJsonstringyesRequired. The request body as JSON, the same shape as cf_create_zones_access_apps_policy (name, decision and include required; the three rule lists are ARRAYS of one-key objects). It REPLACES the policy: send every rule you want to keep.
policyIdstringyesRequired. UUID. Fills the segment of the request path.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Update application settings. Why this is destructive: A PUT replaces the whole settings object, so a field you omit falls back to Cloudflare's default instead of keeping its stored value. PUT /zones//access/apps//settings. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. The app_id this call targets.
bodyJsonstringyesRequired. The request body as JSON with allow_iframe and skip_interstitial. It REPLACES the settings object - send both.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Update Access application settings. Partial update: Cloudflare applies only the fields present in the body and leaves the rest alone. Both fields loosen browser protections - allow_iframe lets the app be framed and skip_interstitial removes the click-through Access shows before an identity redirect. PATCH /accounts//access/apps//settings. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
appIdstringyesRequired. The app_id this call targets.
bodyJsonstringyesOptional in effect but sent as JSON: allow_iframe (allow this application to be rendered inside an iframe) and skip_interstitial (skip the Access interstitial page before redirecting to the identity provider). Send only the field you are changing.

[Cloudflare] Update application settings. Partial update: only the fields you send change. Both of them loosen browser protections - allow_iframe permits framing and skip_interstitial removes the click-through before an identity redirect. PATCH /zones//access/apps//settings. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
appIdstringyesRequired. The app_id this call targets.
bodyJsonstringyesOptional in effect but sent as JSON: allow_iframe and skip_interstitial. Send only the field you are changing.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

Access Authenticator Device Aaguids

ToolPlanAccessSummary
cf_list_access_authenticator_device_aaguidsFreeRead-onlyList authenticator device AAGUIDs.

[Cloudflare] List authenticator device AAGUIDs. An AAGUID identifies a MODEL of hardware authenticator (a YubiKey 5, a Windows Hello platform key). This is the catalogue Cloudflare matches against when an Access MFA policy restricts sign-in to particular device models; it describes no customer's own keys and carries no key material. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/authenticator_device_aaguids. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

Access Bookmarks

ToolPlanAccessSummary
cf_create_access_bookmarkProWriteCreate a Bookmark application.
cf_delete_access_bookmarkProDestructiveDESTRUCTIVE: Delete a Bookmark application.
cf_get_access_bookmarkFreeRead-onlyGet a Bookmark application.
cf_list_access_bookmarksFreeRead-onlyList Bookmark applications.
cf_set_access_bookmarkProDestructiveDESTRUCTIVE: Update a Bookmark application.

[Cloudflare] Create a Bookmark application. Additive: it publishes one new App Launcher tile and changes no existing one. Cloudflare replaced Bookmark applications with ordinary Access applications of type bookmark: create one with cf_create_access_app and list them with cf_list_access_apps. Note the unusual contract: the CALLER chooses the bookmark_id and sends it in the path, so a POST to an id that already exists overwrites that bookmark rather than creating a second one. POST /accounts//access/bookmarks/. Path parameters: bookmark_id, account_id. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON, per Cloudflare's documented sample for this endpoint.
bookmarkIdstringyesRequired. Required. The uid to create the bookmark under - the caller picks it, and an id that already exists is overwritten.

[Cloudflare] DESTRUCTIVE: Delete a Bookmark application. Why this is destructive: The bookmark tile disappears from the App Launcher for everyone in the organization. Nothing behind the link changes - the link itself is simply no longer published. Cloudflare replaced Bookmark applications with ordinary Access applications of type bookmark: create one with cf_create_access_app and list them with cf_list_access_apps. Cloudflare declares an empty JSON body on this operation, so StackJack sends none. DELETE /accounts//access/bookmarks/. Path parameters: bookmark_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bookmarkIdstringyesRequired. UUID.

[Cloudflare] Get a Bookmark application. Cloudflare replaced Bookmark applications with ordinary Access applications of type bookmark: create one with cf_create_access_app and list them with cf_list_access_apps. GET /accounts//access/bookmarks/. Path parameters: bookmark_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bookmarkIdstringyesRequired. UUID.

[Cloudflare] List Bookmark applications. Cloudflare replaced Bookmark applications with ordinary Access applications of type bookmark: create one with cf_create_access_app and list them with cf_list_access_apps. A bookmark is a tile in the Access App Launcher that links out to a site Access does not itself protect. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/bookmarks. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DESTRUCTIVE: Update a Bookmark application. Why this is destructive: A PUT replaces the whole bookmark from the body, so a field you leave out is cleared rather than kept - and the tile it publishes changes for every user at once. Cloudflare replaced Bookmark applications with ordinary Access applications of type bookmark: create one with cf_create_access_app and list them with cf_list_access_apps. PUT /accounts//access/bookmarks/. Path parameters: bookmark_id, account_id. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON, per Cloudflare's documented sample for this endpoint.
bookmarkIdstringyesRequired. UUID.

Access Certificates

ToolPlanAccessSummary
cf_create_access_certificateProWriteAdd an mTLS certificate.
cf_create_zones_access_certificateProWriteAdd an mTLS certificate.
cf_delete_access_certificateProDestructiveDESTRUCTIVE: Delete an mTLS certificate.
cf_delete_zones_access_certificateProDestructiveDESTRUCTIVE: Delete an mTLS certificate.
cf_get_access_certificateFreeRead-onlyGet an mTLS certificate.
cf_get_zones_access_certificateFreeRead-onlyGet an mTLS certificate.
cf_list_access_certificatesFreeRead-onlyList mTLS certificates.
cf_list_access_certificates_settingsFreeRead-onlyList all mTLS hostname settings.
cf_list_zones_access_certificatesFreeRead-onlyList mTLS certificates.
cf_list_zones_access_certificates_settingsFreeRead-onlyList all mTLS hostname settings.
cf_set_access_certificateProDestructiveDESTRUCTIVE: Update an mTLS certificate.
cf_set_access_certificates_settingProDestructiveDESTRUCTIVE: Update an mTLS certificate's hostname settings.
cf_set_zones_access_certificateProDestructiveDESTRUCTIVE: Update an mTLS certificate.
cf_set_zones_access_certificates_settingProDestructiveDESTRUCTIVE: Update an mTLS certificate's hostname settings.

[Cloudflare] Add an mTLS certificate. Additive: it stores one new root certificate and changes no existing one. The certificate only starts being checked on the hostnames you list in associated_hostnames, so a create with none is inert until cf_set_access_certificate or cf_set_access_certificates_setting arms it. POST /accounts//access/certificates. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. certificate and name are required: certificate is the ROOT CA's PEM-encoded public certificate (not a private key and not a leaf), and associated_hostnames is an optional array of the hostnames mTLS is enforced on.

[Cloudflare] Add an mTLS certificate. Additive: it stores one new root certificate on this zone and changes no existing one. It is inert until a hostname is associated with it. POST /zones//access/certificates. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. certificate and name are required: certificate is the ROOT CA's PEM-encoded public certificate, and associated_hostnames is an optional array of the hostnames mTLS is enforced on.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete an mTLS certificate. Why this is destructive: The root certificate is removed from the account. Any policy rule that admitted users by a certificate signed by this CA stops matching, so those clients are refused on their next request. There is no undo and the PEM has to be re-uploaded to recover. DELETE /accounts//access/certificates/. Path parameters: certificate_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
certificateIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Delete an mTLS certificate. Why this is destructive: The root certificate is removed from the zone, and any policy rule that admitted clients by a certificate from this CA stops matching. There is no undo. DELETE /zones//access/certificates/. Path parameters: certificate_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
certificateIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Get an mTLS certificate. An mTLS root certificate is the CA Access checks a client certificate against, so a policy rule of certificate or common_name can admit a device by the certificate it presents. Returns one certificate with its fingerprint, expiry and associated_hostnames. GET /accounts//access/certificates/. Path parameters: certificate_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
certificateIdstringyesRequired. UUID.

[Cloudflare] Get an mTLS certificate. An mTLS root certificate is the CA Access checks a client certificate against, so a policy rule of certificate or common_name can admit a device by the certificate it presents. The zone-scoped single-certificate read. GET /zones//access/certificates/. Path parameters: certificate_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
certificateIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List mTLS certificates. An mTLS root certificate is the CA Access checks a client certificate against, so a policy rule of certificate or common_name can admit a device by the certificate it presents. The reach-first read of the mTLS lane: every other certificate tool takes its certificate_id from here, and each row carries the fingerprint, the expiry and the associated_hostnames the certificate is armed on. GET /accounts//access/certificates. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.

[Cloudflare] List all mTLS hostname settings. The per-hostname half of the mTLS lane: for each hostname it reports whether a client certificate is requested at all (china_network, client_certificate_forwarding) rather than which CA is trusted. Certificates themselves are cf_list_access_certificates. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/certificates/settings. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] List mTLS certificates. An mTLS root certificate is the CA Access checks a client certificate against, so a policy rule of certificate or common_name can admit a device by the certificate it presents. ZONE-scoped twin of cf_list_access_certificates: it reaches only the certificates held on this one zone. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/certificates. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List all mTLS hostname settings. The per-hostname client-certificate settings of ONE zone - whether a certificate is requested and whether it is forwarded to the origin. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/certificates/settings. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Update an mTLS certificate. Why this is destructive: A PUT replaces the certificate record from the body, and associated_hostnames is required - send the full list, because a hostname you omit stops enforcing mTLS at once. The PEM itself cannot be changed here; upload a new certificate instead. PUT /accounts//access/certificates/. Path parameters: certificate_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. associated_hostnames is required and is the FULL array of hostnames this certificate is enforced on - it replaces the stored list. name is an optional rename.
certificateIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Update an mTLS certificate's hostname settings. Why this is destructive: The settings array REPLACES every stored hostname setting for the account, not just the hostnames you name. A hostname you leave out loses its client-certificate configuration, so devices that were being asked for a certificate silently stop being asked. Read cf_list_access_certificates_settings first and send the full set back. PUT /accounts//access/certificates/settings. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON with one field, settings, which is an ARRAY of objects - hostname, china_network (whether the hostname is served from Cloudflare's China network) and client_certificate_forwarding (whether the client certificate is forwarded to the origin). The array replaces the whole stored set.

[Cloudflare] DESTRUCTIVE: Update an mTLS certificate. Why this is destructive: A PUT replaces the certificate record from the body and associated_hostnames is required - a hostname you omit stops enforcing mTLS at once. PUT /zones//access/certificates/. Path parameters: certificate_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. associated_hostnames is required and is the FULL array of hostnames this certificate is enforced on; name is an optional rename.
certificateIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Update an mTLS certificate's hostname settings. Why this is destructive: The settings array REPLACES every stored hostname setting for this zone. A hostname you leave out loses its client-certificate configuration and stops being asked for one. Read cf_list_zones_access_certificates_settings first and send the full set back. PUT /zones//access/certificates/settings. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON with one field, settings, an ARRAY of objects with hostname, china_network and client_certificate_forwarding. The array replaces the whole stored set for the zone.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

Access Custom Pages

ToolPlanAccessSummary
cf_create_access_custom_pageProWriteCreate a custom page.
cf_delete_access_custom_pageProDestructiveDESTRUCTIVE: Delete a custom page.
cf_get_access_custom_pageFreeRead-onlyGet a custom page.
cf_list_access_custom_pagesFreeRead-onlyList custom pages.
cf_set_access_custom_pageProDestructiveDESTRUCTIVE: Update a custom page.
cf_validate_access_custom_pagesFreeRead-onlyValidate a custom page template.

[Cloudflare] Create a custom page. Additive: it stores one new page and changes no existing one. A stored page is not shown to anyone until an application or the organization points at it. POST /accounts//access/custom_pages. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullRequired in practice although Cloudflare declares the body optional. custom_html, name and type are required: type is identity_denied or forbidden, and custom_html is the Liquid template rendered to the end user. Validate the template with cf_validate_access_custom_pages first - a broken template reaches real users.

[Cloudflare] DESTRUCTIVE: Delete a custom page. Why this is destructive: The page is removed. Any application still pointing at it falls back to Cloudflare's default block screen, so the customer's branding and its own support instructions disappear from what a blocked user sees. The HTML is not recoverable from the API. DELETE /accounts//access/custom_pages/. Path parameters: custom_page_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
customPageIdstringyesRequired. UUID.

[Cloudflare] Get a custom page. A custom page is the HTML Access serves in place of its own block or identity-denied screen. Unlike the list, this read returns the page's HTML as well as its metadata. GET /accounts//access/custom_pages/. Path parameters: custom_page_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
customPageIdstringyesRequired. UUID.

[Cloudflare] List custom pages. A custom page is the HTML Access serves in place of its own block or identity-denied screen. The reach-first read: other custom-page tools take their custom_page_id from here. The list omits the HTML itself - cf_get_access_custom_page returns it. GET /accounts//access/custom_pages. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.

[Cloudflare] DESTRUCTIVE: Update a custom page. Why this is destructive: A PUT replaces the whole page, and custom_html, name and type are all required - there is no partial edit here, and the new HTML is what blocked users see from the next request on. Validate it first with cf_validate_access_custom_pages. PUT /accounts//access/custom_pages/. Path parameters: custom_page_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullRequired. The request body as JSON: custom_html, name and type (identity_denied or forbidden) are required and REPLACE the stored page.
customPageIdstringyesRequired. UUID.

[Cloudflare] Validate a custom page template. A DRY RUN and the one POST in this family that changes nothing: Cloudflare states it returns the template's errors and warnings WITHOUT persisting it. Ruling R4 ships it read-only, Free and on the read permission for that reason. Run it before cf_create_access_custom_page or cf_set_access_custom_page. POST /accounts//access/custom_pages/validate. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional by Cloudflare's declaration but send it: template (the Liquid source to check), type (identity_denied or forbidden) and version.

Access Gateway Ca

ToolPlanAccessSummary
cf_create_access_gateway_caProWriteAdd a new SSH Certificate Authority (CA).
cf_delete_access_gateway_caProDestructiveDESTRUCTIVE: Delete an SSH Certificate Authority (CA).
cf_list_access_gateway_casFreeRead-onlyList SSH Certificate Authorities (CA).

[Cloudflare] Add a new SSH Certificate Authority (CA). Additive: it generates a new SSH Certificate Authority and returns its public key. It takes no request body. The new public key has to be installed on every SSH target before certificates it signs are accepted. POST /accounts//access/gateway_ca. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DESTRUCTIVE: Delete an SSH Certificate Authority (CA). Why this is destructive: The SSH Certificate Authority is destroyed. Every certificate it signed stops being trusted, so users lose SSH access through Gateway until a new CA is generated and its public key is deployed to every target host. There is no undo. DELETE /accounts//access/gateway_ca/. Path parameters: certificate_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
certificateIdstringyesRequired. UUID.

[Cloudflare] List SSH Certificate Authorities (CA). The Gateway SSH Certificate Authority is the account-wide CA that signs short-lived SSH certificates for Gateway's SSH proxy - it is not the per-application CA of cf_list_access_apps_cas. The response carries each CA's PUBLIC key, which is what goes into a target host's sshd configuration, and the certificate_id the delete tool takes. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/gateway_ca. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

Access Groups

ToolPlanAccessSummary
cf_create_access_groupProDestructiveDESTRUCTIVE: Create an Access group.
cf_create_zones_access_groupProDestructiveDESTRUCTIVE: Create an Access group.
cf_delete_access_groupProDestructiveDESTRUCTIVE: Delete an Access group.
cf_delete_zones_access_groupProDestructiveDESTRUCTIVE: Delete an Access group.
cf_get_access_groupFreeRead-onlyGet an Access group.
cf_get_zones_access_groupFreeRead-onlyGet an Access group.
cf_list_access_groupsFreeRead-onlyList Access groups.
cf_list_zones_access_groupsFreeRead-onlyList Access groups.
cf_set_access_groupProDestructiveDESTRUCTIVE: Update an Access group.
cf_set_zones_access_groupProDestructiveDESTRUCTIVE: Update an Access group.

[Cloudflare] DESTRUCTIVE: Create an Access group. Why this is destructive: It creates a new group, and the group only matters once a policy references it - except when is_default is true, which applies it to new applications automatically. Marked destructive because a group is an access-control object: getting its include rules wrong widens who reaches every application that later references it. POST /accounts//access/groups. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. name and include are required. include is an ARRAY of one-key rule objects (email, email_list, email_domain, everyone, ip, ip_list, geo, group, certificate, common_name, service_token, any_valid_service_token, auth_method, device_posture, user_risk_score, external_evaluation, azureAD, github-organization, gsuite, okta, saml, oidc), exclude and require take the same shape, and is_default applies the group to new applications automatically.

[Cloudflare] DESTRUCTIVE: Create an Access group. Why this is destructive: It creates a new group on this zone. Marked destructive because a group is an access-control object: its include rules decide who reaches every application whose policy later references it. POST /zones//access/groups. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. name and include are required; include, exclude and require are ARRAYS of one-key rule objects (email, email_domain, everyone, ip, group, certificate, service_token, azureAD, github-organization, gsuite, okta, saml and the rest of Cloudflare's rule vocabulary).
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete an Access group. Why this is destructive: The group is deleted. Every policy that referenced it loses that rule, so users who reached an application only through this group are refused on their next request - across every application at once. There is no undo and the rules have to be rebuilt by hand. DELETE /accounts//access/groups/. Path parameters: group_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
groupIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Delete an Access group. Why this is destructive: The group is deleted and every policy that referenced it loses that rule, so users who reached an application only through this group are refused on their next request. DELETE /zones//access/groups/. Path parameters: group_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
groupIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Get an Access group. An Access group is a named, reusable set of identity rules - the same include, exclude and require vocabulary a policy uses - that policies then reference by id instead of repeating the rules. Returns one group with its full rule lists. GET /accounts//access/groups/. Path parameters: group_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
groupIdstringyesRequired. UUID.

[Cloudflare] Get an Access group. An Access group is a named, reusable set of identity rules - the same include, exclude and require vocabulary a policy uses - that policies then reference by id instead of repeating the rules. The zone-scoped single-group read. GET /zones//access/groups/. Path parameters: group_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
groupIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List Access groups. An Access group is a named, reusable set of identity rules - the same include, exclude and require vocabulary a policy uses - that policies then reference by id instead of repeating the rules. The reach-first read: a policy's group rule carries the group_id this list returns. is_default marks a group applied to new applications automatically. GET /accounts//access/groups. Path parameters: account_id. Optional filters: name, search, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
namestringnonullOptional. The name of the group.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.
searchstringnonullOptional. Search for groups by other listed query parameters.

[Cloudflare] List Access groups. An Access group is a named, reusable set of identity rules - the same include, exclude and require vocabulary a policy uses - that policies then reference by id instead of repeating the rules. ZONE-scoped twin of cf_list_access_groups. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/groups. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Update an Access group. Why this is destructive: An Access group is referenced by policies, so this change propagates to EVERY application whose policy names the group, immediately and with no deploy step. A PUT replaces the whole group from the body: a rule you leave out of include is gone, and name and include are both required. PUT /accounts//access/groups/. Path parameters: group_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. name and include are required and REPLACE the stored group - include, exclude and require are ARRAYS of one-key rule objects, and any rule you omit is deleted. is_default applies the group to new applications.
groupIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Update an Access group. Why this is destructive: An Access group is referenced by policies, so this change propagates to EVERY application whose policy names the group, immediately and with no deploy step. A PUT replaces the whole group from the body, so a rule you leave out of include is gone. PUT /zones//access/groups/. Path parameters: group_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. name and include are required and REPLACE the stored group; include, exclude and require are ARRAYS of one-key rule objects.
groupIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

Access Identity Providers

ToolPlanAccessSummary
cf_create_access_identity_providerProWriteAdd an Access identity provider.
cf_create_access_identity_providers_saml_certificateProWriteCreate SAML encryption certificate for Identity Provider.
cf_create_zones_access_identity_providerProWriteAdd an Access identity provider.
cf_delete_access_identity_providerProDestructiveDESTRUCTIVE: Delete an Access identity provider.
cf_delete_zones_access_identity_providerProDestructiveDESTRUCTIVE: Delete an Access identity provider.
cf_get_access_identity_providerFreeRead-onlyGet an Access identity provider.
cf_get_zones_access_identity_providerFreeRead-onlyGet an Access identity provider.
cf_list_access_identity_providersFreeRead-onlyList Access identity providers.
cf_list_access_identity_providers_scim_groupsFreeRead-onlyList SCIM Group resources.
cf_list_access_identity_providers_scim_usersFreeRead-onlyList SCIM User resources.
cf_list_zones_access_identity_providersFreeRead-onlyList Access identity providers.
cf_set_access_identity_providerProDestructiveDESTRUCTIVE: Update an Access identity provider.
cf_set_zones_access_identity_providerProDestructiveDESTRUCTIVE: Update an Access identity provider.

[Cloudflare] Add an Access identity provider. Additive: it adds one identity provider and changes no existing one. Nobody signs in through it until an application lists it in allowed_idps, but the OAuth client secret it carries is live from the moment Cloudflare stores it. POST /accounts//access/identity_providers. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON, and Cloudflare accepts FIFTEEN shapes chosen by type: azureAD, centrify, facebook, github, google, google-apps, linkedin, oidc, okta, onelogin, pingone, saml, yandex, onetimepin and cloudflare. name, type and config are required on every one. config is type-specific - the OAuth providers take client_id and client_secret (SECRET), oidc adds auth_url, token_url, certs_url and scopes, saml takes issuer_url, sso_target_url and idp_public_certs, and onetimepin takes none. scim_config turns on SCIM directory sync and carries its own secret.

[Cloudflare] Create SAML encryption certificate for Identity Provider. IDEMPOTENT by Cloudflare's own statement: if this provider already has a certificate set, the existing one comes back with a 200 and nothing is created. It takes no request body. Enabling encryption is a further step - set config.enable_encryption and saml_certificate_set_id on the provider with cf_set_access_identity_provider, then load the certificate's public key into the external SAML provider. Creates the SAML encryption certificate set used to decrypt SAML assertions and assigns it to this identity provider. The private key stays at Cloudflare; only the public certificate is ever returned. POST /accounts//access/identity_providers//saml_certificate. Path parameters: account_id, identity_provider_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
identityProviderIdstringyesRequired. UUID.

[Cloudflare] Add an Access identity provider. Additive: it adds one identity provider on this zone. The OAuth client secret it carries is live from the moment Cloudflare stores it. POST /zones//access/identity_providers. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON, in one of FOURTEEN type-keyed shapes (azureAD, centrify, facebook, github, google, google-apps, linkedin, oidc, okta, onelogin, pingone, saml, yandex, onetimepin). name, type and config are required; the OAuth types take config.client_id and config.client_secret (SECRET), saml takes issuer_url, sso_target_url and idp_public_certs.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete an Access identity provider. Why this is destructive: The identity provider is removed from the account. Every application that listed it in allowed_idps loses that login option, and if it was the only one those users cannot sign in at all. SCIM-provisioned users and groups from this provider stop being synced. The client secret is not recoverable - re-adding it means re-registering the application at the provider. DELETE /accounts//access/identity_providers/. Path parameters: identity_provider_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
identityProviderIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Delete an Access identity provider. Why this is destructive: The identity provider is removed from the zone. Applications that listed it lose that login option, and if it was the only one those users cannot sign in at all. The client secret is not recoverable. DELETE /zones//access/identity_providers/. Path parameters: identity_provider_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
identityProviderIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Get an Access identity provider. An identity provider is the login source Access sends users to - Entra ID, Okta, Google Workspace, a generic SAML or OIDC provider, or Cloudflare's own one-time PIN. Returns one provider with its type and config block. GET /accounts//access/identity_providers/. Path parameters: identity_provider_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
identityProviderIdstringyesRequired. UUID.

[Cloudflare] Get an Access identity provider. An identity provider is the login source Access sends users to - Entra ID, Okta, Google Workspace, a generic SAML or OIDC provider, or Cloudflare's own one-time PIN. The zone-scoped single-provider read. GET /zones//access/identity_providers/. Path parameters: identity_provider_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
identityProviderIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List Access identity providers. An identity provider is the login source Access sends users to - Entra ID, Okta, Google Workspace, a generic SAML or OIDC provider, or Cloudflare's own one-time PIN. The reach-first read of the identity lane: an application's allowed_idps array and a policy's login_method rule both carry the identity_provider_id this list returns. Each row names its type (azureAD, okta, google-apps, saml, oidc, onetimepin and the rest) and whether SCIM provisioning is on. GET /accounts//access/identity_providers. Path parameters: account_id. Optional filters: scim_enabled, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.
scimEnabledstringnonullOptional. Filter to identity providers with SCIM directory sync enabled, or without it.

[Cloudflare] List SCIM Group resources. The GROUPS an external identity provider has pushed into Cloudflare over SCIM. This is directory data synced from the provider, not Access groups - Access groups are cf_list_access_groups. cf_resource_id is Cloudflare's id for the synced group and idp_resource_id is the provider's own. GET /accounts//access/identity_providers//scim/groups. Path parameters: identity_provider_id, account_id. Optional filters: cf_resource_id, idp_resource_id, name, page, per_page. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
cfResourceIdstringnonullOptional. Filter by Cloudflare's own identifier for the synced group.
identityProviderIdstringyesRequired. UUID.
idpResourceIdstringnonullOptional. Filter by the identity provider's identifier for the group.
namestringnonullOptional. The display name of the SCIM Group resource.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.

[Cloudflare] List SCIM User resources. The USERS an external identity provider has pushed into Cloudflare over SCIM, with the provider's own resource id beside Cloudflare's. Zero Trust seats and Access users are separate reads (cf_list_access_users). GET /accounts//access/identity_providers//scim/users. Path parameters: identity_provider_id, account_id. Optional filters: cf_resource_id, idp_resource_id, username, email, name, page, per_page. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
cfResourceIdstringnonullOptional. Filter by Cloudflare's own identifier for the synced user.
emailstringnonullOptional. The email address of the SCIM User resource.
identityProviderIdstringyesRequired. UUID.
idpResourceIdstringnonullOptional. Filter by the identity provider's identifier for the user.
namestringnonullOptional. The name of the SCIM User resource.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.
usernamestringnonullOptional. The username of the SCIM User resource.

[Cloudflare] List Access identity providers. An identity provider is the login source Access sends users to - Entra ID, Okta, Google Workspace, a generic SAML or OIDC provider, or Cloudflare's own one-time PIN. ZONE-scoped twin of cf_list_access_identity_providers. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/identity_providers. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Update an Access identity provider. Why this is destructive: A PUT replaces the WHOLE provider from the body, so a config field you leave out is cleared - and clearing client_secret breaks every sign-in through this provider until it is set again. Users are affected on their next authentication, not at their next session expiry. PUT /accounts//access/identity_providers/. Path parameters: identity_provider_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON, the same FIFTEEN type-keyed shapes as cf_create_access_identity_provider (name, type and config required on each). It REPLACES the stored provider: send the full config, including client_secret, not only the fields you are changing.
identityProviderIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Update an Access identity provider. Why this is destructive: A PUT replaces the WHOLE provider from the body, so a config field you leave out is cleared - and clearing client_secret breaks every sign-in through this provider until it is set again. PUT /zones//access/identity_providers/. Path parameters: identity_provider_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON, the same FOURTEEN type-keyed shapes as cf_create_zones_access_identity_provider. It REPLACES the stored provider: send the full config, including client_secret.
identityProviderIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

Access Idp Federation Grants

ToolPlanAccessSummary
cf_create_access_idp_federation_grantProDestructiveDESTRUCTIVE: Create an IdP federation grant.
cf_delete_access_idp_federation_grantProDestructiveDESTRUCTIVE: Delete an IdP federation grant.
cf_get_access_idp_federation_grantFreeRead-onlyGet an IdP federation grant.
cf_list_access_idp_federation_grantsFreeRead-onlyList IdP federation grants.

[Cloudflare] DESTRUCTIVE: Create an IdP federation grant. Why this is destructive: It publishes one identity provider to every other account in the Cloudflare organization, which widens who can authenticate against the customer's own directory. Cloudflare's own limits: the account must belong to an organization, one-time PIN and Cloudflare-managed providers cannot be federated, and at most five providers may be federated at once. Marked destructive because it grants another account the use of this one's identity provider. POST /accounts//access/idp_federation_grants. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON with one required field, idp_id - the identity provider to publish, from cf_list_access_identity_providers.

[Cloudflare] DESTRUCTIVE: Delete an IdP federation grant. Why this is destructive: The identity provider stays in this account but stops being available to the other accounts in the organization, so any of them relying on it for sign-in loses that login source on the next authentication. DELETE /accounts//access/idp_federation_grants/. Path parameters: account_id, grant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
grantIdstringyesRequired. UID of the IdP federation grant.

[Cloudflare] Get an IdP federation grant. An IdP federation grant publishes ONE of this account's identity providers to the other accounts in the same Cloudflare organization, so they can authenticate users against it without re-registering it. Returns one grant by its uid. GET /accounts//access/idp_federation_grants/. Path parameters: account_id, grant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
grantIdstringyesRequired. UID of the IdP federation grant.

[Cloudflare] List IdP federation grants. An IdP federation grant publishes ONE of this account's identity providers to the other accounts in the same Cloudflare organization, so they can authenticate users against it without re-registering it. The reach-first read: each row carries the grant_id the get and delete tools take and the idp_id it publishes. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/idp_federation_grants. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

Access Keys

ToolPlanAccessSummary
cf_get_access_keysFreeRead-onlyGet the Access key configuration.
cf_rotate_access_keysProDestructiveDESTRUCTIVE: Rotate Access keys.
cf_set_access_keyProDestructiveDESTRUCTIVE: Update the Access key configuration.

[Cloudflare] Get the Access key configuration. These are the keys Access signs its own application JWTs with - the ones an origin verifies through Cloudflare's public JWKS endpoint. They are not API tokens and not service tokens. The read returns the rotation SETTINGS and status only - the interval, the last rotation time and the days until the next one. No key material is in the response. GET /accounts//access/keys. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DESTRUCTIVE: Rotate Access keys. Why this is destructive: It rotates the Access JWT signing keys NOW, ahead of the configured schedule, and takes no request body. Any origin or middleware that caches Cloudflare's public keys rejects tokens signed with the new key until it refetches the JWKS, so users can see failures at an origin that caches aggressively. There is no un-rotate. POST /accounts//access/keys/rotate. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DESTRUCTIVE: Update the Access key configuration. Why this is destructive: It sets how often Access rotates its JWT signing keys; it mints nothing by itself. Shortening the interval means Cloudflare replaces the signing key sooner, and anything that caches Access's public keys rejects freshly signed tokens until it refetches the JWKS. Marked destructive because it governs the credential every Access-protected origin verifies against. PUT /accounts//access/keys. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON with one required field, key_rotation_interval_days - how many days Cloudflare waits between automatic rotations of the Access JWT signing keys.

Access Logs

ToolPlanAccessSummary
cf_get_access_logs_jit_requestFreeRead-onlyGet an Access JIT request log.
cf_list_access_logs_access_requestsFreeRead-onlyGet Access authentication logs.
cf_list_access_logs_jit_requestsFreeRead-onlyList Access JIT request logs.
cf_list_access_logs_scim_updatesFreeRead-onlyList Access SCIM update logs.

[Cloudflare] Get an Access JIT request log. One JIT access request with its lifecycle events in chronological order - raised, approved or denied, by whom and when. The knock_request_id comes from cf_list_access_logs_jit_requests. GET /accounts//access/logs/jit_requests/. Path parameters: account_id, knock_request_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
knockRequestIdstringyesRequired. The knock_request_id this call targets.

[Cloudflare] Get Access authentication logs. The Access authentication audit trail: one row per sign-in decision, with the user's email, the application, the identity provider, the country, the ray id and whether Access allowed the request. This is the read to reach for when a customer asks why somebody could or could not get in. Cloudflare's document declares the OPERATOR parameters (allowedOp, country_codeOp and the rest) but NOT the value parameters they modify, so email is the only filter whose value can be sent - StackJack mirrors the vendor document exactly and invents nothing. GET /accounts//access/logs/access_requests. Path parameters: account_id. Optional filters: limit, direction, since, until, page, per_page, email, email_exact, user_id, allowedOp, country_codeOp, app_typeOp, app_uidOp, ray_idOp, emailOp, idpOp, non_identityOp, user_idOp, fields. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
allowedOpstringnonullOptional. Comparison operator (eq or neq) for the allowed filter. Cloudflare's document declares no allowed value parameter, so this operator has nothing to act on today.
appTypeOpstringnonullOptional. Comparison operator (eq or neq) for the app_type filter, whose value parameter Cloudflare's document does not declare.
appUidOpstringnonullOptional. Comparison operator (eq or neq) for the app_uid filter, whose value parameter Cloudflare's document does not declare.
countryCodeOpstringnonullOptional. Comparison operator (eq or neq) for the country_code filter, whose value parameter Cloudflare's document does not declare.
directionstringnonullOptional. Chronological sort order, desc (newest first, the default) or asc.
emailstringnonullOptional. Filter by user email. Substring by default; set email_exact=true or emailOp=eq for an exact match.
emailExactbooleannonullOptional. True matches email exactly instead of as a substring. It wins over emailOp when both are set.
emailOpstringnonullOptional. Match mode for the email filter: eq (exact), neq (exclude) or contains (substring). email_exact=true wins over it.
fieldsstringnonullOptional. Comma-separated list of fields to return, for example action,allowed,app_name,country,created_at,ray_id,user_email. All fields come back when omitted.
idpOpstringnonullOptional. Comparison operator (eq or neq) for the idp filter, whose value parameter Cloudflare's document does not declare.
limitintegernonullOptional. The maximum number of log entries to retrieve. StackJack caps it at 100 and sends 100 when you omit it; Cloudflare's own default is 25.
nonIdentityOpstringnonullOptional. Comparison operator (eq or neq) for the non_identity filter, whose value parameter Cloudflare's document does not declare.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.
rayIdOpstringnonullOptional. Comparison operator (eq or neq) for the ray_id filter, whose value parameter Cloudflare's document does not declare.
sincestringnonullOptional. The earliest event timestamp to query, RFC 3339, for example 2026-09-01T00:00:00Z.
untilstringnonullOptional. The latest event timestamp to query, RFC 3339.
userIdstringnonullOptional. DEPRECATED by Cloudflare: accepted for compatibility and no longer applied as a filter. Use email.
userIdOpstringnonullOptional. DEPRECATED alongside user_id and no longer applied.

[Cloudflare] List Access JIT request logs. JIT (just-in-time) requests are the access requests a user raises for an application that needs approval, reconstructed from their lifecycle events. Each row carries the knock_request_id cf_get_access_logs_jit_request takes. GET /accounts//access/logs/jit_requests. Path parameters: account_id. Optional filters: page, per_page, status, search, since, until. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.
searchstringnonullOptional. Free-text search across the request records.
sincestringnonullOptional. The earliest request timestamp to include, RFC 3339.
statusstringnonullOptional. Filter by request state, for example pending, approved or denied.
untilstringnonullOptional. The latest request timestamp to include, RFC 3339.

[Cloudflare] List Access SCIM update logs. The audit trail of what an identity provider changed through SCIM: users and groups created, updated or deprovisioned in Cloudflare by the directory. idp_id is REQUIRED - this log is read one identity provider at a time, from cf_list_access_identity_providers. GET /accounts//access/logs/scim/updates. Path parameters: account_id. Cloudflare REQUIRES this query parameter and answers 400 without it: idp_id. Optional filters: limit, direction, since, until, status, resource_type, request_method, resource_user_email, resource_group_name, cf_resource_id, idp_resource_id, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
cfResourceIdstringnonullOptional. Filter by Cloudflare's own identifier for the synced resource.
directionstringnonullOptional. Chronological sort order, desc (newest first) or asc.
idpIdstringnonullRequired by Cloudflare - the call fails without it. Required. The identity provider whose SCIM activity to read, from cf_list_access_identity_providers. Cloudflare rejects the call without it.
idpResourceIdstringnonullOptional. Filter by the identity provider's identifier for the resource.
limitintegernonullOptional. Maximum number of log entries to retrieve. StackJack caps it at 100; Cloudflare's own default is 20.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.
requestMethodstringnonullOptional. Filter by the SCIM HTTP verb the provider used, for example POST, PATCH or DELETE.
resourceGroupNamestringnonullOptional. Filter to the SCIM updates for one group, by name.
resourceTypestringnonullOptional. Filter to User or Group records.
resourceUserEmailstringnonullOptional. Filter to the SCIM updates for one user, by email.
sincestringnonullOptional. the timestamp of the earliest update log.
statusstringnonullOptional. Filter by the outcome of the SCIM operation.
untilstringnonullOptional. the timestamp of the most-recent update log.

Access Organizations

ToolPlanAccessSummary
cf_create_access_organizationProWriteCreate your Zero Trust organization.
cf_create_zones_access_organizationProWriteCreate your Zero Trust organization.
cf_get_access_organizationsFreeRead-onlyGet your Zero Trust organization.
cf_get_access_organizations_dohsFreeRead-onlyGet your Zero Trust organization DoH settings.
cf_get_zones_access_organizationsFreeRead-onlyGet your Zero Trust organization.
cf_revoke_access_organization_user_tokensProDestructiveDESTRUCTIVE: Revoke all Access tokens for a user.
cf_revoke_zones_access_org_user_tokensProDestructiveDESTRUCTIVE: Revoke all Access tokens for a user.
cf_set_access_organizationProDestructiveDESTRUCTIVE: Update your Zero Trust organization.
cf_set_access_organizations_dohProDestructiveDESTRUCTIVE: Update your Zero Trust organization DoH settings.
cf_set_zones_access_organizationProDestructiveDESTRUCTIVE: Update your Zero Trust organization.

[Cloudflare] Create your Zero Trust organization. Additive: it sets up the account's Zero Trust organization, which exists once. auth_domain and name are required, and auth_domain becomes the team domain every user signs in at - Cloudflare does not let it be changed casually afterwards. POST /accounts//access/organizations. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. auth_domain and name are required: auth_domain is the team domain users authenticate at (for example acme.cloudflareaccess.com). The fields that matter next are session_duration (how long an Access session lasts), auto_redirect_to_identity, is_ui_read_only with ui_read_only_toggle_reason, user_seat_expiration_inactive_time, login_design, mfa_config and mfa_required_for_all_apps.

[Cloudflare] Create your Zero Trust organization. Additive: it sets up the Zero Trust organization from the zone route. auth_domain and name are required, and auth_domain becomes the team domain every user signs in at. POST /zones//access/organizations. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. auth_domain and name are required; the zone route also accepts is_ui_read_only with ui_read_only_toggle_reason, login_design and user_seat_expiration_inactive_time.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Get your Zero Trust organization. The Zero Trust organization is the account-wide Access configuration: the auth_domain (the team domain users see at sign-in, for example acme.cloudflareaccess.com), the global session duration, the login page design and the MFA requirements. There is exactly one per account. Read this before any organization write - the PUT replaces the whole object, so this response is the baseline you edit. GET /accounts//access/organizations. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get your Zero Trust organization DoH settings. The organization's DNS-over-HTTPS settings: how long a DoH JWT lasts and which service token authenticates the DoH endpoint. Nothing in the response is the token itself - service_token_id is an identifier. GET /accounts//access/organizations/doh. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get your Zero Trust organization. The Zero Trust organization is the account-wide Access configuration: the auth_domain (the team domain users see at sign-in, for example acme.cloudflareaccess.com), the global session duration, the login page design and the MFA requirements. There is exactly one per account. ZONE-scoped twin of cf_get_access_organizations, with the smaller zone-level field set. GET /zones//access/organizations. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Revoke all Access tokens for a user. Why this is destructive: It revokes the named user's Access across EVERY application at once: their live sessions end immediately and they must re-authenticate everywhere. With devices=true their WARP device registration goes too, so the device has to be re-enrolled, and warp_session_reauth forces WARP re-authentication. This is the offboarding and compromised-account lever, not a routine one. Note that devices appears BOTH as a query parameter and as a body field in Cloudflare's own document; the body form is the documented one. POST /accounts//access/organizations/revoke_user. Path parameters: account_id. Optional filters: devices. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. email is required and names the user to revoke. Optional: user_uid, devices (also revoke the user's WARP device registrations) and warp_session_reauth (force WARP re-authentication).
devicesbooleannonullOptional. The query-string form of the body's devices flag - revoke the user's WARP device registrations as well. Cloudflare declares it in both places.

[Cloudflare] DESTRUCTIVE: Revoke all Access tokens for a user. Why this is destructive: It revokes the named user's Access across EVERY application at once - their live sessions end immediately and they must re-authenticate everywhere. The zone route takes email only; use the account route when you also need to revoke WARP devices. POST /zones//access/organizations/revoke_user. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON with one required field, email - the user whose Access is revoked.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Update your Zero Trust organization. Why this is destructive: A PUT replaces the WHOLE organization configuration from the body, and this is the highest-blast-radius write in the Access family: change auth_domain and every existing Access login URL, every bookmarked team domain and every SAML integration pointed at the old one stops working. A field you leave out is cleared, so read the organization first and send it back changed. is_ui_read_only locks the Zero Trust dashboard for everyone, and deny_unmatched_requests refuses traffic that matches no application. PUT /accounts//access/organizations. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON, and it REPLACES the whole organization configuration. The fields that matter: auth_domain (the team domain - changing it breaks every existing login URL), session_duration, auto_redirect_to_identity, is_ui_read_only with ui_read_only_toggle_reason, mfa_config, mfa_required_for_all_apps, deny_unmatched_requests with deny_unmatched_requests_exempted_zone_names, user_seat_expiration_inactive_time, custom_pages, login_design, allow_authenticate_via_warp and the two warp_auth fields. Read cf_get_access_organizations first and send its result back changed.

[Cloudflare] DESTRUCTIVE: Update your Zero Trust organization DoH settings. Why this is destructive: A PUT replaces the whole DoH settings object, so an omitted field falls back to Cloudflare's default rather than keeping its stored value. Pointing service_token_id at a different token stops every DoH client still presenting the old one. PUT /accounts//access/organizations/doh. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional by Cloudflare's declaration. doh_jwt_duration is how long a DoH JWT stays valid, and service_token_id names the service token (from cf_list_access_service_tokens) that authenticates the DoH endpoint - the id, never the secret.

[Cloudflare] DESTRUCTIVE: Update your Zero Trust organization. Why this is destructive: A PUT replaces the WHOLE organization configuration from the body, and this is the highest-blast-radius write in the Access family: change auth_domain and every existing Access login URL, every bookmarked team domain and every SAML integration pointed at the old one stops working. A field you leave out is cleared, so read the organization first and send it back changed. The zone route carries a smaller field set than the account one but writes the same account-wide organization. PUT /zones//access/organizations. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON, and it REPLACES the whole organization configuration: auth_domain (changing it breaks every existing login URL), name, is_ui_read_only with ui_read_only_toggle_reason, login_design and user_seat_expiration_inactive_time. Read cf_get_zones_access_organizations first.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

Access Policies

ToolPlanAccessSummary
cf_create_access_policyProDestructiveDESTRUCTIVE: Create an Access reusable policy.
cf_delete_access_policyProDestructiveDESTRUCTIVE: Delete an Access reusable policy.
cf_get_access_policyFreeRead-onlyGet an Access reusable policy.
cf_list_access_policiesFreeRead-onlyList Access reusable policies.
cf_set_access_policyProDestructiveDESTRUCTIVE: Update an Access reusable policy.

[Cloudflare] DESTRUCTIVE: Create an Access reusable policy. Why this is destructive: It creates a reusable policy. The policy governs nothing until an application references its id - but it is an access-control object, and once referenced its include rules decide who reaches that application. POST /accounts//access/policies. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. name, decision and include are required: decision is allow, deny, non_identity or bypass, and include is an ARRAY of one-key rule objects (email, email_list, email_domain, everyone, ip, ip_list, geo, group, certificate, common_name, service_token, any_valid_service_token, linked_app_token, auth_method, auth_context, login_method, device_posture, user_risk_score, external_evaluation, azureAD, github-organization, gsuite, okta, saml, oidc, cloudflare_account_member). exclude and require take the same shape. Optional: session_duration, approval_required with approval_groups, purpose_justification_required, isolation_required and connection_rules.

[Cloudflare] DESTRUCTIVE: Delete an Access reusable policy. Why this is destructive: The reusable policy is deleted and every application that referenced it loses that rule at once. If it was an application's only allow policy its users are locked out on the next request; if it was the deny, whoever it kept out is let in. There is no undo, and the rules have to be rebuilt by hand. DELETE /accounts//access/policies/. Path parameters: account_id, policy_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
policyIdstringyesRequired. The UUID of the policy.

[Cloudflare] Get an Access reusable policy. A reusable policy is defined once on the account and referenced by id from any number of applications, which is the shape Cloudflare recommends over app-scoped policies. Returns one reusable policy with its decision and full rule lists. GET /accounts//access/policies/. Path parameters: account_id, policy_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
policyIdstringyesRequired. The UUID of the policy.

[Cloudflare] List Access reusable policies. A reusable policy is defined once on the account and referenced by id from any number of applications, which is the shape Cloudflare recommends over app-scoped policies. The reach-first read: an application's policies array carries the policy ids this list returns, and each row shows the decision, the rules and how many applications use it. GET /accounts//access/policies. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.

[Cloudflare] DESTRUCTIVE: Update an Access reusable policy. Why this is destructive: An Access policy decides who may reach the customer's internal applications, and a reusable policy is shared: this edit takes effect on EVERY application that references it, immediately. A PUT replaces the whole policy, so any include, exclude or require rule you leave out is deleted. PUT /accounts//access/policies/. Path parameters: account_id, policy_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON, the same shape as cf_create_access_policy (name, decision and include required; the three rule lists are ARRAYS of one-key objects). It REPLACES the policy on every application that references it - send every rule you want to keep.
policyIdstringyesRequired. The UUID of the policy.

Access Policy Tests

ToolPlanAccessSummary
cf_create_access_policy_testProWriteStart Access policy test.
cf_get_access_policy_testFreeRead-onlyGet the current status of a given Access policy test.
cf_list_access_policy_tests_usersFreeRead-onlyGet an Access policy test users page.

[Cloudflare] Start Access policy test. A SIMULATION: it evaluates the policies you send against the organization's users and reports who would be allowed. It grants nothing and changes no application. It is a write only because Cloudflare persists the run - it returns a policy_test_id that cf_get_access_policy_test and cf_list_access_policy_tests_users then read, and it costs an evaluation over every user in the organization. POST /accounts//access/policy-tests. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesOptional in effect but sent as JSON: policies, an ARRAY of either reusable policy ids or full inline policy objects (name, decision and include) to evaluate. Send the policy you are about to apply, not the one already applied.

[Cloudflare] Get the current status of a given Access policy test. The status of a policy test started by cf_create_access_policy_test - whether the evaluation has finished and the headline counts. The per-user results are paged through cf_list_access_policy_tests_users. GET /accounts//access/policy-tests/. Path parameters: account_id, policy_test_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
policyTestIdstringyesRequired. The UUID of the policy test.

[Cloudflare] Get an Access policy test users page. One page of per-user results from a policy test: who the simulated policy would let in and who it would refuse. Filter by status to see only one outcome. GET /accounts//access/policy-tests//users. Path parameters: account_id, policy_test_id. Optional filters: page, per_page, status. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. How many results to return per page.
policyTestIdstringyesRequired. The UUID of the policy test.
statusstringnonullOptional. Return only the users with this simulated outcome, for example success or failure.

Access Saml Certificates

ToolPlanAccessSummary
cf_download_access_saml_certificate_pemFreeRead-onlyDownload current certificate in PEM format.
cf_get_access_saml_certificateFreeRead-onlyGet SAML certificate set.
cf_list_access_saml_certificatesFreeRead-onlyList SAML certificate sets.
cf_rotate_access_saml_certificatesProDestructiveDESTRUCTIVE: Rotate SAML certificate.

[Cloudflare] Download current certificate in PEM format. Downloads the CURRENT certificate's PUBLIC key as PEM text, which is what an administrator uploads to the external SAML identity provider so it can encrypt assertions. The response is the PEM itself (Cloudflare answers application/x-pem-file), not the usual JSON envelope, and it contains no private key. GET /accounts//access/saml_certificates//pem. Path parameters: account_id, saml_cert_set_id. Returns the response body as plain text exactly as Cloudflare sent it, not JSON.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
samlCertSetIdstringyesRequired. UID of the SAML certificate set.

[Cloudflare] Get SAML certificate set. A SAML certificate set holds the CURRENT and (after a rotation) the PREVIOUS encryption certificate an identity provider uses to encrypt SAML assertions to Cloudflare. Cloudflare keeps the private key; only public certificates are ever returned. Returns one set, current and previous certificate together. GET /accounts//access/saml_certificates/. Path parameters: account_id, saml_cert_set_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
samlCertSetIdstringyesRequired. UID of the SAML certificate set.

[Cloudflare] List SAML certificate sets. A SAML certificate set holds the CURRENT and (after a rotation) the PREVIOUS encryption certificate an identity provider uses to encrypt SAML assertions to Cloudflare. Cloudflare keeps the private key; only public certificates are ever returned. The reach-first read: each row carries the saml_cert_set_id the other three tools take, and both certificates with their expiry dates. GET /accounts//access/saml_certificates. Path parameters: account_id. Optional filters: page, per_page, id. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringnonullOptional. Return only the certificate set with this uid.
pageintegernonullOptional. Page number of paginated results.
perPageintegernonullOptional. Maximum number of results per page.

[Cloudflare] DESTRUCTIVE: Rotate SAML certificate. Why this is destructive: It generates a new certificate, moves the current one into the previous slot and - Cloudflare says this explicitly - DEACTIVATES AND REMOVES whatever was in the previous slot already. Both current and previous stay valid during the transition so there is no downtime, but an identity provider still encrypting with the certificate that just fell out of the set can no longer be decrypted: upload the new public key (from cf_download_access_saml_certificate_pem) to the provider before rotating twice. Cloudflare rotates automatically 30 days before expiry, so a manual rotation is rarely needed. POST /accounts//access/saml_certificates//rotate. Path parameters: account_id, saml_cert_set_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
samlCertSetIdstringyesRequired. UID of the SAML certificate set to rotate.

Access Seats

ToolPlanAccessSummary
cf_update_access_seatProDestructiveDESTRUCTIVE: Update a user seat.

[Cloudflare] DESTRUCTIVE: Update a user seat. Why this is destructive: This is the REMOVE-A-SEAT call: Cloudflare's own description says setting both access_seat and gateway_seat to false removes the user from their Zero Trust seat. That user loses Access and Gateway entitlement, their sessions end and the seat returns to the customer's licence pool. Send the flags true to restore it. The body is an ARRAY, so several seats can be changed in one call. PATCH /accounts//access/seats. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON, and it is an ARRAY of seat objects - each with seat_uid (the Zero Trust seat identifier, from cf_list_access_users), access_seat (true if the seat keeps its Access entitlement) and gateway_seat (true if it keeps Gateway). All three are required on every entry, and both flags false removes the user from the seat.

Access Service Tokens

ToolPlanAccessSummary
cf_create_access_service_tokenProDestructiveDESTRUCTIVE: Create a service token.
cf_create_zones_access_service_tokenProDestructiveDESTRUCTIVE: Create a service token.
cf_delete_access_service_tokenProDestructiveDESTRUCTIVE: Delete a service token.
cf_delete_zones_access_service_tokenProDestructiveDESTRUCTIVE: Delete a service token.
cf_get_access_service_tokenFreeRead-onlyGet a service token.
cf_get_zones_access_service_tokenFreeRead-onlyGet a service token.
cf_list_access_service_tokensFreeRead-onlyList service tokens.
cf_list_zones_access_service_tokensFreeRead-onlyList service tokens.
cf_refresh_access_service_tokensProDestructiveDESTRUCTIVE: Refresh a service token.
cf_rotate_access_service_tokensProDestructiveDESTRUCTIVE: Rotate a service token.
cf_set_access_service_tokenProDestructiveDESTRUCTIVE: Update a service token.
cf_set_zones_access_service_tokenProDestructiveDESTRUCTIVE: Update a service token.

[Cloudflare] DESTRUCTIVE: Create a service token. Why this is destructive: It mints a live machine credential, and Cloudflare states this is the ONLY time the client secret is returned: if it is lost the token has to be rotated or replaced. The token reaches nothing until a policy admits it with a service_token or any_valid_service_token rule. POST /accounts//access/service_tokens. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. name is required. duration sets the token's lifetime (for example 8760h, Cloudflare's default of one year), enabled turns it on or off, and client_secret_version selects the secret version to issue.

[Cloudflare] DESTRUCTIVE: Create a service token. Why this is destructive: It mints a live machine credential, and Cloudflare states this is the ONLY time the client secret is returned - on the zone route the recovery is to create a new token outright. The token reaches nothing until a policy admits it. POST /zones//access/service_tokens. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. name is required; duration sets the lifetime, enabled turns the token on or off, and client_secret_version selects the secret version to issue.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Delete a service token. Why this is destructive: The token stops working immediately, and every script or service still presenting its client id and secret starts getting refused by Access. The secret cannot be recovered - recovery means creating a new token and redeploying it everywhere it was used. DELETE /accounts//access/service_tokens/. Path parameters: service_token_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
serviceTokenIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Delete a service token. Why this is destructive: The token stops working immediately and every client still presenting its id and secret is refused. The secret cannot be recovered. DELETE /zones//access/service_tokens/. Path parameters: service_token_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
serviceTokenIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] Get a service token. A service token is a machine credential - a client_id and client_secret pair a script or service presents in CF-Access-Client-Id and CF-Access-Client-Secret headers instead of signing in - and an Access policy admits it through a service_token or any_valid_service_token rule. Returns one token's metadata - id, client_id, expiry, last seen. The secret is not in the response. GET /accounts//access/service_tokens/. Path parameters: service_token_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
serviceTokenIdstringyesRequired. UUID.

[Cloudflare] Get a service token. A service token is a machine credential - a client_id and client_secret pair a script or service presents in CF-Access-Client-Id and CF-Access-Client-Secret headers instead of signing in - and an Access policy admits it through a service_token or any_valid_service_token rule. The zone-scoped single-token read; metadata only, no secret. GET /zones//access/service_tokens/. Path parameters: service_token_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
serviceTokenIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] List service tokens. A service token is a machine credential - a client_id and client_secret pair a script or service presents in CF-Access-Client-Id and CF-Access-Client-Secret headers instead of signing in - and an Access policy admits it through a service_token or any_valid_service_token rule. The reach-first read: it returns each token's id, client_id, expiry and last-seen time. The client SECRET is never in this response - Cloudflare returns it only when the token is created or rotated. GET /accounts//access/service_tokens. Path parameters: account_id. Optional filters: name, search, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
namestringnonullOptional. The name of the service token.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.
searchstringnonullOptional. Search for service tokens by other listed query parameters.

[Cloudflare] List service tokens. A service token is a machine credential - a client_id and client_secret pair a script or service presents in CF-Access-Client-Id and CF-Access-Client-Secret headers instead of signing in - and an Access policy admits it through a service_token or any_valid_service_token rule. ZONE-scoped twin of cf_list_access_service_tokens. The client secret is never in this response. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/service_tokens. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

[Cloudflare] DESTRUCTIVE: Refresh a service token. Why this is destructive: It EXTENDS the token's expiration and mints nothing - the client id and secret are unchanged, so nothing that uses the token needs redeploying. Marked destructive because it keeps a machine credential alive that was about to expire, which is a security decision rather than a maintenance one. It takes no request body. POST /accounts//access/service_tokens//refresh. Path parameters: service_token_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
serviceTokenIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Rotate a service token. Why this is destructive: It generates a NEW client secret and revokes the old one, and the new secret is in the response - the only time Cloudflare returns it. Every client still using the old secret is refused as soon as it expires, so set previous_client_secret_expires_at to buy a window in which both work while the new secret is deployed. POST /accounts//access/service_tokens//rotate. Path parameters: service_token_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body with one field, previous_client_secret_expires_at - an RFC 3339 timestamp until which the OLD client secret keeps working. Omit it and the old secret is revoked at once, which breaks every client that has not been updated.
serviceTokenIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Update a service token. Why this is destructive: It updates the token's settings and mints no new secret. A PUT replaces the record, so a field you omit falls back to its default rather than keeping its stored value - and enabled=false turns the token off, which refuses every client still presenting it. PUT /accounts//access/service_tokens/. Path parameters: service_token_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON: name, duration (the token lifetime, for example 8760h), enabled (false turns the token off for every client using it), client_secret_version and previous_client_secret_expires_at. It REPLACES the stored settings - send what you want to keep.
serviceTokenIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Update a service token. Why this is destructive: It updates the token's settings and mints no new secret. A PUT replaces the record, so an omitted field falls back to its default - and enabled=false turns the token off for every client using it. PUT /zones//access/service_tokens/. Path parameters: service_token_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON: name, duration, enabled (false turns the token off for every client using it), client_secret_version and previous_client_secret_expires_at. It REPLACES the stored settings.
serviceTokenIdstringyesRequired. UUID.
zoneIdstringyesRequired. The Cloudflare zone id — one zone is one domain. Get it from cf_list_zones, or from the right-hand column of the zone Overview page.

Access Tags

ToolPlanAccessSummary
cf_create_access_tagProWriteCreate a tag.
cf_delete_access_tagProDestructiveDESTRUCTIVE: Delete a tag.
cf_get_access_tagFreeRead-onlyGet a tag.
cf_list_access_tagsFreeRead-onlyList tags.
cf_set_access_tagProDestructiveDESTRUCTIVE: Update a tag.

[Cloudflare] Create a tag. Additive: it creates one label and changes no application. POST /accounts//access/tags. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional by Cloudflare's declaration but send it: name, the tag's name, which is also the identifier every other tag tool uses.

[Cloudflare] DESTRUCTIVE: Delete a tag. Why this is destructive: The tag is deleted and disappears from every application carrying it, so the App Launcher grouping the customer built is gone. No application is otherwise changed and no access is affected. DELETE /accounts//access/tags/. Path parameters: account_id, tag_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tagNamestringyesRequired. Required. The tag's NAME, which is its identifier - there is no separate uid.

[Cloudflare] Get a tag. An Access tag is a label put on applications so the App Launcher can group them; it grants nothing and restricts nothing. Note that a tag is addressed by its NAME, not by a uid. GET /accounts//access/tags/. Path parameters: account_id, tag_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
tagNamestringyesRequired. Required. The tag's NAME, which is its identifier - there is no separate uid.

[Cloudflare] List tags. An Access tag is a label put on applications so the App Launcher can group them; it grants nothing and restricts nothing. Note that a tag is addressed by its NAME, not by a uid. Each row carries the tag name the other tools take and the number of applications carrying it. GET /accounts//access/tags. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.

[Cloudflare] DESTRUCTIVE: Update a tag. Why this is destructive: A PUT replaces the tag record. Renaming it through the name field re-labels it for every application carrying it, and the old name stops resolving. PUT /accounts//access/tags/. Path parameters: account_id, tag_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullRequired. The request body as JSON with name required - the tag's name after the update. created_at and updated_at are read-only fields Cloudflare echoes back.
tagNamestringyesRequired. Required. The tag's CURRENT name, which is its identifier; the body's name field is the new one.

Access Users

ToolPlanAccessSummary
cf_create_access_userProWriteCreate a user.
cf_delete_access_userProDestructiveDESTRUCTIVE: Delete a user.
cf_delete_access_users_mfa_authenticatorProDestructiveDESTRUCTIVE: Delete a user's MFA device.
cf_get_access_userFreeRead-onlyGet a user.
cf_get_access_users_active_sessionFreeRead-onlyGet single active session.
cf_get_access_users_last_seen_identitiesFreeRead-onlyGet last seen identity.
cf_list_access_usersFreeRead-onlyGet users.
cf_list_access_users_active_sessionsFreeRead-onlyGet active sessions.
cf_list_access_users_failed_loginsFreeRead-onlyGet failed logins.
cf_set_access_userProDestructiveDESTRUCTIVE: Update a user.

[Cloudflare] Create a user. Additive: it creates one user record and changes no existing one. The record does not grant access by itself - what a user may reach is decided by the policies of each application. POST /accounts//access/users. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. email is required and identifies the user; name is optional.

[Cloudflare] DESTRUCTIVE: Delete a user. Why this is destructive: Cloudflare states that deleting the user ALSO revokes their active seats and tokens: every live Access session ends, their Zero Trust seat is released and the audit identity goes with the record. The person can authenticate again from scratch if a policy still admits them, but the history and the seat assignment are not recoverable. DELETE /accounts//access/users/. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
userIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Delete a user's MFA device. Why this is destructive: The user's enrolled MFA device - a PIV card, a FIDO2 security key or a TOTP authenticator - is de-enrolled, and Cloudflare returns a null result on success. If it was their only factor and the organization requires MFA, they cannot sign in until they enroll another one, so this is the deliberate step after a lost key rather than a cleanup action. Cloudflare only offers it while MFA is turned on for the organization. DELETE /accounts//access/users//mfa_authenticators/. Path parameters: user_id, account_id, authenticator_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
authenticatorIdstringyesRequired. Required. The enrolled MFA device to remove, from the user's record - not the AAGUID of the device model.
userIdstringyesRequired. UUID.

[Cloudflare] Get a user. A Zero Trust user is a person who has authenticated to Access at least once or has been provisioned into the account; the user_id here is what the sessions, logins and MFA reads below take. Returns one user record. GET /accounts//access/users/. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
userIdstringyesRequired. UUID.

[Cloudflare] Get single active session. One live Access session of a user, with the identity Access recorded for it. GET /accounts//access/users//active_sessions/. Path parameters: user_id, account_id, nonce. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
noncestringyesRequired. Required. The session's nonce, from cf_list_access_users_active_sessions - it identifies one live session of this user.
userIdstringyesRequired. UUID.

[Cloudflare] Get last seen identity. The identity Access last saw for this user: the identity provider, the groups and the claims that came back at their most recent sign-in. This is what a policy's group and claim rules are actually matched against, so it is the read that explains an unexpected allow or deny. GET /accounts//access/users//last_seen_identity. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
userIdstringyesRequired. UUID.

[Cloudflare] Get users. A Zero Trust user is a person who has authenticated to Access at least once or has been provisioned into the account; the user_id here is what the sessions, logins and MFA reads below take. The reach-first read of the user lane, filterable by name, email or free text, and the source of the seat_uid cf_update_access_seat takes. GET /accounts//access/users. Path parameters: account_id. Optional filters: name, email, search, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
emailstringnonullOptional. The email of the user.
namestringnonullOptional. The name of the user.
pageintegernonullOptional. Page number of results.
perPageintegernonullOptional. Number of results per page.
searchstringnonullOptional. Search for users by other listed query parameters.

[Cloudflare] Get active sessions. The live Access sessions of one user, each with the nonce cf_get_access_users_active_session takes. To end them all, use cf_revoke_access_organization_user_tokens. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/users//active_sessions. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
userIdstringyesRequired. UUID.

[Cloudflare] Get failed logins. Every failed sign-in attempt recorded for one user, with the reason Access refused it. The first read when a customer reports that somebody cannot get in. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/users//failed_logins. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
userIdstringyesRequired. UUID.

[Cloudflare] DESTRUCTIVE: Update a user. Why this is destructive: Cloudflare updates the user's NAME only and requires their current email in the body as confirmation - the email itself cannot be changed here. Sending a different email does not move the record, it fails. PUT /accounts//access/users/. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. email and name are both required: email must be the user's CURRENT email and acts as confirmation, and name is the value being changed.
userIdstringyesRequired. UUID.

AI

ToolPlanAccessSummary
cf_create_ai_finetuneProWriteCreate a new Finetune.
cf_create_ai_finetunes_finetune_assetProWriteUpload a Finetune Asset.
cf_create_ai_runProWriteExecute AI model.
cf_create_ai_tomarkdownProWriteConvert Files into Markdown.
cf_delete_ai_finetuneProDestructiveDESTRUCTIVE: Delete a Finetune.
cf_get_ai_finetunesFreeRead-onlyList Finetunes.
cf_get_ai_finetunes_finetune_assetFreeRead-onlyDownload a Finetune Asset.
cf_get_ai_models_schemasFreeRead-onlyGet Model Schema.
cf_list_ai_finetunes_publicsFreeRead-onlyList Public Finetunes.
cf_list_ai_tomarkdown_supportedsFreeRead-onlyGet all converted formats supported.
cf_run_aiProWriteExecute AI Model (Generic).
cf_search_ai_authorsFreeRead-onlyAuthor Search.
cf_search_ai_modelsFreeRead-onlyModel Search.
cf_search_ai_tasksFreeRead-onlyTask Search.

[Cloudflare] Create a new Finetune. Additive: creates a new record and changes no existing one. Creates the fine-tune record only. Its training data is uploaded separately with cf_create_ai_finetunes_finetune_asset against the id this call returns. POST /accounts//ai/finetunes. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare requires model and name: model is a base model id from cf_search_ai_models and name labels the fine-tune. description and public are optional.

[Cloudflare] Upload a Finetune Asset. Additive: creates a new record and changes no existing one. Uploads the training data for a fine-tune created by cf_create_ai_finetune. StackJack takes the file either as base64 or as a public https URL it downloads server-side. POST /accounts//ai/finetunes//finetune-assets. Path parameters: account_id, finetune_id. Cloudflare takes this request as a multipart/form-data body with these parts: file, file_name. A file part is supplied EITHER as base64 in the call OR as a public https URL StackJack downloads server-side; give exactly one of the two per file, and StackJack refuses a non-https URL, a redirect to another host, or anything over 25 MB. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
fileBase64stringnonullRequired. The file file's bytes as base64. Give this OR fileUrl, never both. Maximum 25 MB decoded.
fileFileNamestringnonullOptional. A file name for the file part. It labels the upload; it does not change where Cloudflare stores it.
fileNamestringyesRequired. The name this asset is stored under for the fine-tune. It is the same value cf_get_ai_finetunes_finetune_asset takes to fetch the asset back.
fileUrlstringnonullRequired. A public https URL StackJack downloads the file file from. Give this OR fileBase64, never both. Maximum 25 MB.
finetuneIdstringyesRequired. The finetune_id this call targets.

[Cloudflare] Execute AI model. Runs a model on demand. Nothing the customer authored is changed, but the call is metered Workers AI usage and is charged to the account. Runs the Workers AI model named in the path. This is a metered inference call: every invocation consumes the account's Workers AI allowance and is billed beyond it. The body fields Cloudflare documents here are the union across model types, so only the ones in that model's own schema apply - read cf_get_ai_models_schemas first. POST /accounts//ai/run/. Path parameters: account_id, model_name. Send the request body as JSON; Cloudflare documents these fields: text, guidance, height, image, image_b64, mask, negative_prompt, num_steps, prompt, seed, strength, width. Cloudflare documents 5 more fields; see its API docs. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare documents these fields: text, guidance, height, image, image_b64, mask, negative_prompt, num_steps, prompt, seed, strength, width, lang, source_lang, target_lang, input_text, max_length.
modelNamestringyesRequired. The Workers AI model id to run, taken from cf_search_ai_models, for example @cf/meta/llama-3.1-8b-instruct.

[Cloudflare] Convert Files into Markdown. Converts a document and returns the Markdown. Nothing stored is changed, but a format that needs a model to read it is metered Workers AI usage. Converts an uploaded document to Markdown. cf_list_ai_tomarkdown_supporteds is the list of formats Cloudflare accepts; a format that needs a model to read it is a metered Workers AI call. POST /accounts//ai/tomarkdown. Path parameters: account_id. Cloudflare takes this request as a multipart/form-data body with these parts: files. A file part is supplied EITHER as base64 in the call OR as a public https URL StackJack downloads server-side; give exactly one of the two per file, and StackJack refuses a non-https URL, a redirect to another host, or anything over 25 MB. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
filesBase64stringnonullRequired. The files file's bytes as base64. Give this OR filesUrl, never both. Maximum 25 MB decoded.
filesFileNamestringnonullOptional. A file name for the files part. It labels the upload; it does not change where Cloudflare stores it.
filesUrlstringnonullRequired. A public https URL StackJack downloads the files file from. Give this OR filesBase64, never both. Maximum 25 MB.

[Cloudflare] DESTRUCTIVE: Delete a Finetune. Why this is destructive: Removes the fine-tune named by finetune_id. Any Workers AI call that names that fine-tune stops resolving from the moment it succeeds, and the API offers no undo; retraining is the only way back. DELETE /accounts//ai/finetunes/. Path parameters: account_id, finetune_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
finetuneIdstringyesRequired. The finetune_id this call targets.

[Cloudflare] List Finetunes. The reach-first read for fine-tuning: every fine-tune this account has created, with its status. The id on each row is the finetune_id that cf_create_ai_finetunes_finetune_asset, cf_get_ai_finetunes_finetune_asset and cf_delete_ai_finetune take. No page size is documented, so the whole list comes back at once. GET /accounts//ai/finetunes. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Download a Finetune Asset. Despite the vendor title this does NOT return the file bytes: Cloudflare answers a pre-signed R2 URL for the asset, which you fetch separately and which expires. StackJack passes that JSON through unchanged and keeps no copy of the file. GET /accounts//ai/finetunes//finetune-assets/. Path parameters: account_id, finetune_id, file_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
fileNamestringyesRequired. The file_name this call targets.
finetuneIdstringyesRequired. The finetune_id this call targets.

[Cloudflare] Get Model Schema. The input and output JSON schema for ONE Workers AI model - what cf_run_ai and cf_create_ai_run expect in their request body. Read it before composing a model call. GET /accounts//ai/models/schema. Path parameters: account_id. Cloudflare REQUIRES this query parameter and answers 400 without it: model. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
modelstringnonullRequired by Cloudflare - the call fails without it. Cloudflare REQUIRES this one despite its position in the query: the model id whose schema you want, for example @cf/meta/llama-3.1-8b-instruct. Omitting it is a 400, not an unfiltered answer.

[Cloudflare] List Public Finetunes. Fine-tunes Cloudflare publishes for anyone to use, NOT this account's own fine-tunes - cf_get_ai_finetunes is that read. GET /accounts//ai/finetunes/public. Path parameters: account_id. Optional filters: limit, offset, orderBy. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
limitintegernonullOptional. Pagination Limit.
offsetintegernonullOptional. Pagination Offset.
orderBystringnonullOptional. Order By Column Name.

[Cloudflare] Get all converted formats supported. The file formats cf_create_ai_tomarkdown accepts. It takes no arguments and the whole list comes back in one response. GET /accounts//ai/tomarkdown/supported. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Execute AI Model (Generic). Runs a model on demand. Nothing the customer authored is changed, but the call is metered Workers AI usage and is charged to the account. Runs a Workers AI model named in the request body rather than in the path. This is a metered inference call: every invocation consumes the account's Workers AI allowance and is billed beyond it. Read the model's own schema with cf_get_ai_models_schemas first - the input field shape differs per model. POST /accounts//ai/run. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare requires model and input: model is a model id from cf_search_ai_models and input is that model's own documented input object, whose shape cf_get_ai_models_schemas returns. options is optional.

[Cloudflare] Author Search. Cloudflare-wide catalogue data, not this account's: it answers the authors and organizations that publish Workers AI models. It takes no filter arguments and no page size, so the whole list comes back in one response, and the names in it are what the author filter on cf_search_ai_models matches. GET /accounts//ai/authors/search. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Model Search. The reach-first read for Workers AI: Cloudflare's whole model catalogue, filterable by task, author and free text. The model ids it returns are what cf_create_ai_run takes in its path and cf_run_ai takes in its body. Set include_deprecated only when you deliberately want models Cloudflare has retired. GET /accounts//ai/models/search. Path parameters: account_id. Optional filters: per_page, page, task, author, source, hide_experimental, search, include_deprecated, format. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
authorstringnonullOptional. Filter by Author.
formatstringnonullOptional. If set, return models in the requested marketplace format instead of the default response.
hideExperimentalbooleannonullOptional. Filter to hide experimental models.
includeDeprecatedbooleannonullOptional. If true, include models for up to three months after their deprecation date.
pageintegernonullOptional. Which page of results to return, starting at 1.
perPageintegernonullOptional. How many results to return per page.
searchstringnonullOptional. Search.
sourcenumbernonullOptional. Filter by Source Id.
taskstringnonullOptional. Filter by Task Name.

[Cloudflare] Task Search. The task types Workers AI models are grouped under, for example text-generation or text-embeddings. These are the values the task filter on cf_search_ai_models accepts. It takes no arguments and the whole list comes back in one response. GET /accounts//ai/tasks/search. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

AI Gateway Billing

ToolPlanAccessSummary
cf_create_ai_gateway_billing_spending_limitProWriteSet spending limit (deprecated).
cf_create_ai_gateway_billing_topupProDestructiveDESTRUCTIVE: Create a top-up.
cf_create_ai_gateway_billing_topup_configProDestructiveDESTRUCTIVE: Set auto top-up configuration.
cf_create_ai_gateway_billing_topup_eligibilityFreeRead-onlyGet top-up eligibility.
cf_delete_ai_gateway_billing_spending_limitProDestructiveDESTRUCTIVE: Delete spending limit.
cf_delete_ai_gateway_billing_topup_configProDestructiveDESTRUCTIVE: Delete auto top-up configuration.
cf_get_ai_gateway_billing_credit_balancesFreeRead-onlyGet credit balance.
cf_get_ai_gateway_billing_invoice_historiesFreeRead-onlyGet invoice history.
cf_get_ai_gateway_billing_invoice_previewsFreeRead-onlyGet invoice preview.
cf_get_ai_gateway_billing_spending_limitsFreeRead-onlyGet spending limit.
cf_get_ai_gateway_billing_topup_configsFreeRead-onlyGet auto top-up configuration.
cf_get_ai_gateway_billing_topup_limitsFreeRead-onlyGet account top-up limits.
cf_get_ai_gateway_billing_topup_statusFreeRead-onlyCheck top-up status.
cf_get_ai_gateway_billing_usage_historiesFreeRead-onlyGet usage history.

[Cloudflare] Set spending limit (deprecated). Cloudflare answers 403 to every call, so nothing changes - but it is a write and is tiered as one. DEPRECATED and inert: Cloudflare's own document says spending limits can no longer be created, enabled or modified and that this endpoint always responds 403. It is built so the surface is complete and so an agent gets the vendor's own refusal rather than a missing tool. There is no replacement write, and cf_delete_ai_gateway_billing_spending_limit is the only spending-limit change still accepted. POST /accounts//ai-gateway/billing/spending-limit. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON: amount, duration and strategy, all three required. Cloudflare rejects the call with 403 whatever you send.

[Cloudflare] DESTRUCTIVE: Create a top-up. Why this is destructive: SPENDS THE CUSTOMER'S MONEY. It charges the account's default payment method for the amount given, in cents, minimum 1000 (USD 10.00), and buys AI Gateway credit. A completed charge cannot be reversed through this API - a refund is a support matter. Confirm the amount with the customer first, and read cf_get_ai_gateway_billing_topup_limits and cf_get_ai_gateway_billing_credit_balances before calling it. Its response carries the Stripe PaymentIntent client_secret, and cf_get_ai_gateway_billing_topup_status takes the payment_intent_id it also returns to poll how the charge settled. POST /accounts//ai-gateway/billing/topup. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON with one field, amount: the top-up in CENTS, minimum 1000. cf_get_ai_gateway_billing_topup_limits returns the account's own minimum and maximum.

[Cloudflare] DESTRUCTIVE: Set auto top-up configuration. Why this is destructive: ARMS AUTOMATIC CHARGES. From the moment it succeeds Cloudflare charges the account's default payment method the given amount, without asking again, every time the credit balance falls below the given threshold. Both values are in cents. cf_delete_ai_gateway_billing_topup_config is what disarms it. POST /accounts//ai-gateway/billing/topup/config. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON. Both fields are required and both are in CENTS: threshold is the balance that triggers a charge (minimum 500) and amount is how much is charged each time (minimum 1000).

[Cloudflare] Get top-up eligibility. A POST that only ASKS: it reports whether the account can self-serve a credit top-up and, if not, why. It charges nothing and changes nothing, so it ships as a read. POST /accounts//ai-gateway/billing/topup/eligibility. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body with one documented field, payment_methods: the account-level payment methods the dashboard forwards. Omit it to have Cloudflare use what is already on file.

[Cloudflare] DESTRUCTIVE: Delete spending limit. Why this is destructive: Removes the spending cap on AI Gateway usage for the whole account. Afterwards nothing in AI Gateway stops spend at a threshold, and because cf_create_ai_gateway_billing_spending_limit is deprecated and answers 403, the limit cannot be put back through this API once it is gone. DELETE /accounts//ai-gateway/billing/spending-limit. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] DESTRUCTIVE: Delete auto top-up configuration. Why this is destructive: Disarms automatic top-up for the account. Nothing charges the card automatically after this, so AI Gateway calls start failing on an empty balance instead of buying more credit - which may be exactly what the customer wants, or an outage. It reads back as absent on cf_get_ai_gateway_billing_topup_configs. DELETE /accounts//ai-gateway/billing/topup/config. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get credit balance. The reach-first read for AI Gateway Unified Billing: the current credit balance, the payment method on file and the auto top-up configuration in one response. Read it before any of the top-up tools, which spend real money. GET /accounts//ai-gateway/billing/credit-balance. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get invoice history. Past AI Gateway invoices for the account, newest first. GET /accounts//ai-gateway/billing/invoice-history. Path parameters: account_id. Optional filters: type. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
typestringnonullOptional. Narrows the history to one invoice kind. Cloudflare documents no value list for it, so omit it unless the value came from an invoice you have already read.

[Cloudflare] Get invoice preview. What the next AI Gateway invoice would look like today, with line items and tax. A preview only - it charges nothing. GET /accounts//ai-gateway/billing/invoice-preview. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get spending limit. The spending limit currently configured for the account. The matching write, cf_create_ai_gateway_billing_spending_limit, is deprecated and always refuses; cf_delete_ai_gateway_billing_spending_limit is the one change still accepted. GET /accounts//ai-gateway/billing/spending-limit. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get auto top-up configuration. The current auto top-up threshold and amount, plus any error state from the last automatic charge. Auto top-up charges the card without asking again, so read this before changing it. GET /accounts//ai-gateway/billing/topup/config. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Get account top-up limits. The smallest and largest top-up this account may buy, in cents. Read it before cf_create_ai_gateway_billing_topup, which spends real money. GET /accounts//ai-gateway/billing/topup/limits. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.

[Cloudflare] Check top-up status. A POST that only ASKS: how a top-up charge settled. It moves no money and changes nothing, so it ships as a read. POST /accounts//ai-gateway/billing/topup/status. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringyesRequired. The request body as JSON with one field, payment_intent_id - the value cf_create_ai_gateway_billing_topup returned for the charge you are checking.

[Cloudflare] Get usage history. Aggregated AI Gateway usage meters over a time window, which is what an invoice is built from. It is metering rather than per-request logs - cf_list_ai_gateway_logs is the request log. GET /accounts//ai-gateway/billing/usage-history. Path parameters: account_id. Cloudflare REQUIRES this query parameter and answers 400 without it: value_grouping_window. Optional filters: start_time, end_time. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
endTimenumbernonullOptional. End of the window, as the numeric timestamp Cloudflare documents.
startTimenumbernonullOptional. Start of the window, as the numeric timestamp Cloudflare documents. Omit both bounds to take the vendor's default window.
valueGroupingWindowstringnonullRequired by Cloudflare - the call fails without it. Cloudflare REQUIRES this one despite its position in the query: the bucket size the meters are grouped into. Omitting it is a 400, not an ungrouped answer.

AI Gateway Custom Providers

ToolPlanAccessSummary
cf_create_ai_gateway_custom_providerProWriteCreate a new Account Provider.
cf_create_ai_gateway_custom_providers_costProWriteCreate a new Account Provider Cost.
cf_delete_ai_gateway_custom_providerProDestructiveDESTRUCTIVE: Delete a Account Provider.
cf_delete_ai_gateway_custom_providers_costProDestructiveDESTRUCTIVE: Delete a Account Provider Cost.
cf_get_ai_gateway_custom_providerFreeRead-onlyFetch a Account Provider.
cf_get_ai_gateway_custom_providers_costFreeRead-onlyFetch a Account Provider Cost.
cf_list_ai_gateway_custom_providersFreeRead-onlyList Account Providers.
cf_list_ai_gateway_custom_providers_costsFreeRead-onlyList Account Provider Costs.
cf_update_ai_gateway_custom_providerProWriteUpdate a Account Provider.
cf_update_ai_gateway_custom_providers_costProWriteUpdate a Account Provider Cost.

[Cloudflare] Create a new Account Provider. Additive: creates a new record and changes no existing one. Adds an AI provider of the account's own to AI Gateway. The slug you choose is how the provider is named in a gateway provider config and in a dynamic route. POST /accounts//ai-gateway/custom-providers. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare requires base_url, name and slug: base_url is the provider's API root and slug is the short id other AI Gateway calls use. beta, curl_example, description, enable, headers, js_example, link and position are optional presentation and routing fields.

[Cloudflare] Create a new Account Provider Cost. Additive: creates a new record and changes no existing one. Adds a price rule so AI Gateway can cost requests to a custom provider. It changes what usage REPORTS say; it does not change what any vendor charges. POST /accounts//ai-gateway/custom-providers/costs. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare requires account_provider_id (from cf_list_ai_gateway_custom_providers) and model. cost_in and cost_out are the per-token prices, cost_type and token_pricing say how they are counted, model_rule matches model names and enable turns the rule on.

[Cloudflare] DESTRUCTIVE: Delete a Account Provider. Why this is destructive: Removes the custom provider from the account. Any gateway provider config or dynamic route that named it stops resolving to it, and its price rules go with it. The API offers no undo; putting it back means recreating the provider and its costs. DELETE /accounts//ai-gateway/custom-providers/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. The id this call targets.

[Cloudflare] DESTRUCTIVE: Delete a Account Provider Cost. Why this is destructive: Removes one price rule from a custom provider. Requests AI Gateway logs afterwards are costed by whatever rule is left, or not costed at all, so usage reporting for that model changes. It does not change what the provider charges, and the API offers no undo. DELETE /accounts//ai-gateway/custom-providers/costs/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. The id this call targets.

[Cloudflare] Fetch a Account Provider. One custom provider by id. Cloudflare's own summary for this operation says dataset; the path and its schema are a provider. GET /accounts//ai-gateway/custom-providers/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. The id this call targets.

[Cloudflare] Fetch a Account Provider Cost. One price rule by id. Cloudflare's own summary for this operation says dataset; the path and its schema are a provider cost. GET /accounts//ai-gateway/custom-providers/costs/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. The id this call targets.

[Cloudflare] List Account Providers. The reach-first read for custom providers: AI model providers the account has added to AI Gateway beyond the ones Cloudflare ships. The id on each row is what cf_get_ai_gateway_custom_provider, cf_update_ai_gateway_custom_provider and cf_delete_ai_gateway_custom_provider take, and the beta filter selects providers Cloudflare marks beta. Cloudflare's own summary for this operation says evaluator types; the path and its schema are providers. GET /accounts//ai-gateway/custom-providers. Path parameters: account_id. Optional filters: page, per_page, beta, enable, search. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
betabooleannonullOptional. The beta filter.
enablebooleannonullOptional. The enable filter.
pageintegernonullOptional. Which page of results to return, starting at 1.
perPageintegernonullOptional. How many results to return per page.
searchstringnonullOptional. Search by id, name, slug.

[Cloudflare] List Account Provider Costs. Per-model price rules attached to the account's custom providers, which is what AI Gateway uses to put a cost on a logged request. Filter by account_provider_id to see one provider's rules. Cloudflare's own summary for this operation says evaluator types; the path and its schema are provider costs. GET /accounts//ai-gateway/custom-providers/costs. Path parameters: account_id. Optional filters: page, per_page, enable, account_provider_id, model_rule, cost_type, search. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
accountProviderIdstringnonullOptional. The account_provider_id filter.
costTypestringnonullOptional. The cost_type filter.
enablebooleannonullOptional. The enable filter.
modelRulestringnonullOptional. The model_rule filter.
pageintegernonullOptional. Which page of results to return, starting at 1.
perPageintegernonullOptional. How many results to return per page.
searchstringnonullOptional. Search by model, changed_by.

[Cloudflare] Update a Account Provider. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//ai-gateway/custom-providers/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body; only the fields you send change. base_url and slug are the two that change routing - everything else (beta, curl_example, description, enable, headers, js_example, link, logo, name, position) is presentation or a toggle.
idstringyesRequired. The id this call targets.

[Cloudflare] Update a Account Provider Cost. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//ai-gateway/custom-providers/costs/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body; only the fields you send change. cost_in and cost_out are the per-token prices, cost_type and token_pricing say how they are counted, model and model_rule choose what the rule matches, and enable turns it on or off.
idstringyesRequired. The id this call targets.

AI Gateway Evaluation Types

ToolPlanAccessSummary
cf_list_ai_gateway_evaluation_typesFreeRead-onlyList Evaluators.

[Cloudflare] List Evaluators. The evaluators AI Gateway can score logged responses with. The ids it returns are what cf_create_ai_gateway_gateways_evaluation takes in evaluation_type_ids. Account-wide, not per gateway. GET /accounts//ai-gateway/evaluation-types. Path parameters: account_id. Optional filters: page, per_page, order_by, order_by_direction. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
orderBystringnonullOptional. The order_by filter.
orderByDirectionstringnonullOptional. The order_by_direction filter.
pageintegernonullOptional. Which page of results to return, starting at 1.
perPageintegernonullOptional. How many results to return per page.

AI Gateway Gateways

ToolPlanAccessSummary
cf_create_ai_gateway_gatewayProWriteCreate a new Gateway.
cf_create_ai_gateway_gateways_custom_domainProWriteCreate a custom domain for a gateway.
cf_create_ai_gateway_gateways_datasetProWriteCreate a new Dataset.
cf_create_ai_gateway_gateways_evaluationProWriteCreate a new Evaluation.
cf_create_ai_gateway_gateways_provider_configProWriteCreate a new Provider Configs.
cf_create_ai_gateway_gateways_routeProWriteCreate a new AI Gateway Dynamic Route.
cf_create_ai_gateway_gateways_routes_deploymentProWriteCreate a new AI Gateway Dynamic Route Deployment.
cf_create_ai_gateway_gateways_routes_versionProWriteCreate a new AI Gateway Dynamic Route Version.
cf_delete_ai_gateway_gatewayProDestructiveDESTRUCTIVE: Delete a Gateway.
cf_delete_ai_gateway_gateways_custom_domainProDestructiveDESTRUCTIVE: Delete a Custom Domain.
cf_delete_ai_gateway_gateways_datasetProDestructiveDESTRUCTIVE: Delete a Dataset.
cf_delete_ai_gateway_gateways_evaluationProDestructiveDESTRUCTIVE: Delete a Evaluation.
cf_delete_ai_gateway_gateways_provider_configProDestructiveDESTRUCTIVE: Delete a Provider Configs.
cf_delete_ai_gateway_gateways_routeProDestructiveDESTRUCTIVE: Delete an AI Gateway Dynamic Route.
cf_delete_ai_gateway_logsProDestructiveDESTRUCTIVE: Delete Gateway Logs.
cf_get_ai_gateway_gatewayFreeRead-onlyFetch a Gateway.
cf_get_ai_gateway_gateways_custom_domainFreeRead-onlyFetch a Custom Domain.
cf_get_ai_gateway_gateways_datasetFreeRead-onlyFetch a Dataset.
cf_get_ai_gateway_gateways_evaluationFreeRead-onlyFetch a Evaluation.
cf_get_ai_gateway_gateways_logFreeRead-onlyGet Gateway Log Detail.
cf_get_ai_gateway_gateways_routeFreeRead-onlyGet an AI Gateway Dynamic Route.
cf_get_ai_gateway_gateways_routes_versionFreeRead-onlyGet an AI Gateway Dynamic Route Version.
cf_get_ai_gateway_gateways_urlFreeRead-onlyGet Gateway URL.
cf_list_ai_gateway_gatewaysFreeRead-onlyList Gateways.
cf_list_ai_gateway_gateways_custom_domainsFreeRead-onlyList Custom Domains.
cf_list_ai_gateway_gateways_datasetsFreeRead-onlyList Datasets.
cf_list_ai_gateway_gateways_evaluationsFreeRead-onlyList Evaluations.
cf_list_ai_gateway_gateways_logs_requestsFreeRead-onlyGet Gateway Log Request.
cf_list_ai_gateway_gateways_logs_responsesFreeRead-onlyGet Gateway Log Response.
cf_list_ai_gateway_gateways_provider_configsFreeRead-onlyList Provider Configs.
cf_list_ai_gateway_gateways_routesFreeRead-onlyList all AI Gateway Dynamic Routes.
cf_list_ai_gateway_gateways_routes_deploymentsFreeRead-onlyList all AI Gateway Dynamic Route Deployments.
cf_list_ai_gateway_gateways_routes_versionsFreeRead-onlyList all AI Gateway Dynamic Route Versions.
cf_list_ai_gateway_logsFreeRead-onlyList Gateway Logs.
cf_set_ai_gateway_gatewayProDestructiveDESTRUCTIVE: Update a Gateway.
cf_set_ai_gateway_gateways_datasetProDestructiveDESTRUCTIVE: Update a Dataset.
cf_set_ai_gateway_gateways_provider_configProDestructiveDESTRUCTIVE: Update a Provider Configs.
cf_update_ai_gateway_gateways_logProWritePatch Gateway Log.
cf_update_ai_gateway_gateways_routeProWriteUpdate an AI Gateway Dynamic Route.

[Cloudflare] Create a new Gateway. Additive: creates a new record and changes no existing one. Creates a gateway. The id you choose becomes part of the gateway's public URL, which cf_get_ai_gateway_gateways_url returns per provider. POST /accounts//ai-gateway/gateways. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare requires six fields: id (the gateway slug), collect_logs, cache_ttl, cache_invalidate_on_update, rate_limiting_interval and rate_limiting_limit. Two optional fields change how money is spent: workers_ai_billing_mode picks postpaid (billed through Workers AI) or unified (billed through AI Gateway credit), and byok_only forces the customer's own provider credentials and blocks the fallback to Unified Billing. logpush, logpush_public_key, log_management, log_management_strategy, retry_backoff, retry_delay, retry_max_attempts, rate_limiting_technique, authentication, store_id and zdr are the rest.

[Cloudflare] Create a custom domain for a gateway. Provisions a new hostname and a certificate for it. Nothing existing is replaced, but the domain does not serve until the customer points DNS at the CNAME target this returns. Provisions a Cloudflare for SaaS custom hostname for the gateway and returns the CNAME target the customer's DNS has to point at. Nothing serves on the domain until that DNS record exists and the certificate is issued. POST /accounts//ai-gateway/gateways//custom-domains. Path parameters: account_id, gateway_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare requires domain (the hostname to serve the gateway on) and zone_id (the Cloudflare zone that hostname belongs to). minTLS is optional.
gatewayIdstringyesRequired. gateway id.

[Cloudflare] Create a new Dataset. Additive: creates a new record and changes no existing one. POST /accounts//ai-gateway/gateways//datasets. Path parameters: gateway_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. All three fields are required: name labels the dataset, filters is the array of log-filter objects that decides which logged requests belong to it, and enable turns it on.
gatewayIdstringyesRequired. gateway id.

[Cloudflare] Create a new Evaluation. Creates a new evaluation run and leaves existing ones alone. Scoring runs models, so the run is metered usage charged to the account. Starts an evaluation run. Scoring logged responses runs models, so an evaluation is metered usage on the account. POST /accounts//ai-gateway/gateways//evaluations. Path parameters: gateway_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. All three fields are required: name labels the run, dataset_ids are ids from cf_list_ai_gateway_gateways_datasets and evaluation_type_ids are ids from cf_list_ai_gateway_evaluation_types.
gatewayIdstringyesRequired. gateway id.

[Cloudflare] Create a new Provider Configs. Stores a live provider credential on the gateway. From the moment it succeeds the gateway authenticates to that provider with the key you sent, so a wrong value breaks every request routed to that provider until it is corrected. Stores the customer's own API key for one upstream provider on this gateway, which is what byok_only mode requires. Cloudflare returns secret_id and a preview, never the key. POST /accounts//ai-gateway/gateways//provider_configs. Path parameters: account_id, gateway_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Cloudflare requires provider_slug (which provider), alias (the name this config is referenced by) and default_config. secret is the provider's API key itself - send it only when you are storing a new key, and use secret_id instead to point at one already stored. rate_limit and rate_limit_period are optional.
gatewayIdstringyesRequired. gateway id.

[Cloudflare] Create a new AI Gateway Dynamic Route. Additive: creates a new record and changes no existing one. Creates a dynamic route. It does not start serving until a version is deployed with cf_create_ai_gateway_gateways_routes_deployment. POST /accounts//ai-gateway/gateways//routes. Path parameters: account_id, gateway_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body. Both fields are required: name labels the route and elements is the array of routing steps - the providers and models, in order - that decides where a matching request goes.
gatewayIdstringyesRequired. The gateway_id this call targets.

[Cloudflare] Create a new AI Gateway Dynamic Route Deployment. Puts a route version into service. Live gateway traffic is routed by the new version from the moment it succeeds and the previous one stops serving. Nothing is deleted - rolling back means deploying the previous version_id again. Makes one version of a dynamic route the live one. Read cf_list_ai_gateway_gateways_routes_deployments first so you know what is being replaced. POST /accounts//ai-gateway/gateways//routes//deployments. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body with one required field, version_id - an id from cf_list_ai_gateway_gateways_routes_versions.
gatewayIdstringyesRequired. The gateway_id this call targets.
idstringyesRequired. The id this call targets.

[Cloudflare] Create a new AI Gateway Dynamic Route Version. Additive: creates a new record and changes no existing one. Saves a new definition of a dynamic route WITHOUT putting it into service. cf_create_ai_gateway_gateways_routes_deployment is what makes it live. POST /accounts//ai-gateway/gateways//routes//versions. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
bodyJsonstringnonullOptional. A JSON request body with one required field, elements - the array of routing steps, in order, that this version of the route sends matching requests through.
gatewayIdstringyesRequired. The gateway_id this call targets.
idstringyesRequired. The id this call targets.

[Cloudflare] DESTRUCTIVE: Delete a Gateway. Why this is destructive: Deletes the WHOLE gateway named by id - its configuration, its custom domains, its datasets, its evaluations and its logs. Every application still pointing at that gateway URL starts failing. Mind the near-identical name: cf_delete_ai_gateway_logs, plural, deletes only LOG ENTRIES and leaves the gateway alone. The API offers no undo. Cloudflare's own summary for this operation says dataset; the path is the gateway itself. DELETE /accounts//ai-gateway/gateways/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. gateway id.

[Cloudflare] DESTRUCTIVE: Delete a Custom Domain. Why this is destructive: Removes the custom hostname from the gateway. Anything calling the gateway on that hostname stops working immediately; the gateway's own cloudflare URL is unaffected. The API offers no undo, and adding it back provisions a new certificate. DELETE /accounts//ai-gateway/gateways//custom-domains/. Path parameters: account_id, gateway_id, hostname. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
gatewayIdstringyesRequired. gateway id.
hostnamestringyesRequired. the customer-owned custom hostname.

[Cloudflare] DESTRUCTIVE: Delete a Dataset. Why this is destructive: Removes the saved log filter. Evaluations that named this dataset lose their input, and scores already computed from it are no longer reproducible. The API offers no undo. DELETE /accounts//ai-gateway/gateways//datasets/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
gatewayIdstringyesRequired. gateway id.
idstringyesRequired. The id this call targets.

[Cloudflare] DESTRUCTIVE: Delete a Evaluation. Why this is destructive: Removes the evaluation run and the scores it produced. The logs it scored stay; the result does not, and re-running it costs another metered evaluation. DELETE /accounts//ai-gateway/gateways//evaluations/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
gatewayIdstringyesRequired. gateway id.
idstringyesRequired. The id this call targets.

[Cloudflare] DESTRUCTIVE: Delete a Provider Configs. Why this is destructive: Removes the stored credential and the routing entry for one upstream provider on this gateway. Every request the gateway routes to that provider starts failing authentication immediately, and the key itself is gone - putting it back means having the original value again. The API offers no undo. DELETE /accounts//ai-gateway/gateways//provider_configs/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
gatewayIdstringyesRequired. gateway id.
idstringyesRequired. The id this call targets.

[Cloudflare] DESTRUCTIVE: Delete an AI Gateway Dynamic Route. Why this is destructive: Removes the dynamic route, its versions and its deployments. Requests that matched it stop being routed by it from that moment, which for a gateway relying on it is an outage rather than a configuration change. The API offers no undo. DELETE /accounts//ai-gateway/gateways//routes/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
gatewayIdstringyesRequired. The gateway_id this call targets.
idstringyesRequired. The id this call targets.

[Cloudflare] DESTRUCTIVE: Delete Gateway Logs. Why this is destructive: Bulk-deletes the gateway request logs. CRITICAL: limit here is how MANY entries are DELETED, not a page size, and omitting it does not mean one - StackJack always sends an explicit limit and resolves an omitted one to 100, so a call with no arguments beyond the ids destroys up to 100 log entries. Ask for more and StackJack trims it to 1000. Narrow with filters and order_by first, read the same selection back with cf_list_ai_gateway_logs, and expect no undo: the logs are the only record of what was proxied and what it cost. This deletes LOG ENTRIES, not the gateway. cf_delete_ai_gateway_gateway, singular, is the one that deletes the gateway itself. DELETE /accounts//ai-gateway/gateways//logs. Path parameters: account_id, gateway_id. Optional filters: order_by, order_by_direction, filters, limit. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
filtersstringnonullOptional. A JSON array of filter objects, each with key, operator and value, sent as one query value. This is what narrows the deletion - without it you are deleting whatever order_by and order_by_direction put first, which by default is the oldest entries by created_at.
gatewayIdstringyesRequired. gateway id.
limitintegernonullOptional. How many log entries to DELETE - not a page size. Omitted, StackJack sends 100. A larger ask is trimmed to 1000. Cloudflare's own maximum is 10000 and its own default is 10000, but StackJack always sends an explicit value, so that default never applies.
orderBystringnonullOptional. Which field decides WHICH entries are deleted first. The vendor default is created_at.
orderByDirectionstringnonullOptional. asc or desc, applied to order_by. With the vendor default asc it is the OLDEST entries that go.

[Cloudflare] Fetch a Gateway. ONE gateway by id, the whole configuration. Mind the near-identical name: cf_list_ai_gateway_logs, plural, is the LOG list for a gateway, and cf_list_ai_gateway_gateways is the list of gateways. Cloudflare's own summary for this operation says dataset; the path and its schema are a gateway. GET /accounts//ai-gateway/gateways/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
idstringyesRequired. gateway id.

[Cloudflare] Fetch a Custom Domain. One custom hostname by name, with its provisioning status. Cloudflare's own summary for this operation says dataset; the path and its schema are a custom domain. GET /accounts//ai-gateway/gateways//custom-domains/. Path parameters: account_id, gateway_id, hostname. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
gatewayIdstringyesRequired. gateway id.
hostnamestringyesRequired. the customer-owned custom hostname.

[Cloudflare] Fetch a Dataset. One dataset by id, with the filters that define it. Cloudflare's own summary for this operation says an AI Gateway dataset, and here that is accurate. GET /accounts//ai-gateway/gateways//datasets/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
gatewayIdstringyesRequired. gateway id.
idstringyesRequired. The id this call targets.

[Cloudflare] Fetch a Evaluation. One evaluation run with its scores. Cloudflare's own summary for this operation says dataset; the path and its schema are an evaluation. GET /accounts//ai-gateway/gateways//evaluations/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.

ParamTypeRequiredDefaultDescription
accountIdstringyesRequired. The Cloudflare account id. Get it from cf_list_accounts, or from the right-hand column of any account Overview page in the dashboard.
gatewayIdstringyesRequired. gateway id.
idstringyesRequired. The id this call targets.

[Cloudflare] Get Gateway Log Detail. One log