Cloudflare Tools
Written By Christopher Scaminaci
Last updated 7 days ago
Cloudflare Tools
cf_ · 3453 tools · Free 1757 · Pro 1696The whole documented Cloudflare API across the accounts and zones one credential can see: DNS, R2, Workers and Pages, Zero Trust Access and Gateway, WAF and zone settings, Magic WAN, load balancing, certificates, email, Stream and Images, Radar and Cloudforce One. The credential is a scoped API token sent as a bearer against one fixed host, with no grant, no refresh and no renewal call; the legacy Global API Key pair is deliberately not offered. The token's own permission list and account/zone resource list are the real boundary, so a 403 usually means it is short one permission or one zone rather than broken, and the errors array says which. Every response is the vendor envelope {success, errors, messages, result, result_info}, passed through whole; a 200 saying success:false is a failure. Pagination has no single model. A few endpoints answer a file and return a short-lived link instead. The rate budget is the sharp edge: 1,200 requests per five minutes counted per USER.
All connector tools · Cloudflare setup guide
Cloudflare tool groups
- MCP Analytics — 3 tools
- MCP Portals — 6 tools
- MCP Servers — 6 tools
- Zerotrust — 15 tools
- Custom Ns — 5 tools
- DNS Analytics — 2 tools
- DNS Firewall — 9 tools
- DNS Record Scans — 4 tools
- DNS Records — 9 tools
- DNS Settings — 9 tools
- DNS Usage — 2 tools
- DNSSEC — 4 tools
- Secondary DNS — 28 tools
- Account Analytics — 1 tool
- Account Billable — 2 tools
- Account Firewall — 5 tools
- Account Load Balancers — 20 tools
- Account Members — 5 tools
- Account Memberships — 1 tool
- Account Organizations — 3 tools
- Account Profile — 2 tools
- Account Settings — 3 tools
- Account Tokens — 7 tools
- Account Zones — 2 tools
- Accounts — 5 tools
- Activation Check — 1 tool
- Address Validation — 1 tool
- API Tokens — 2 tools
- Audit Logs — 2 tools
- Billable Usage — 2 tools
- Billing — 13 tools
- Communication Preferences — 2 tools
- Diagnostics — 6 tools
- Entitlements — 2 tools
- Flagship — 14 tools
- Hold — 5 tools
- Invites — 3 tools
- Invoices — 1 tool
- IPs — 1 tool
- Live — 1 tool
- Load Balancing Analytics — 1 tool
- Move — 2 tools
- One — 11 tools
- Pay Bad Debt — 1 tool
- Pay Invoice — 1 tool
- Payment Methods — 6 tools
- Rate Plans — 1 tool
- Ready — 1 tool
- Receipts — 1 tool
- Signed URL — 1 tool
- Spectrum Analytics — 1 tool
- Submit — 1 tool
- Subscription — 4 tools
- Subscriptions — 16 tools
- Tags — 10 tools
- User — 2 tools
- v4 — 1 tool
- Zones — 5 tools
- R2 — 2 tools
- R2 Bucket Settings — 12 tools
- R2 Buckets — 7 tools
- R2 Data Catalog — 15 tools
- R2 Domains — 7 tools
- R2 Event Notifications — 4 tools
- R2 Migration Jobs — 5 tools
- R2 Objects — 4 tools
- Cloudflare Tunnels — 12 tools
- Tunnel Routes — 8 tools
- Tunnels — 1 tool
- Virtual Networks — 5 tools
- WARP Connector — 11 tools
- Members — 4 tools
- Members:batchCreate — 1 tool
- Tenant Accounts — 1 tool
- Tenant Billable — 1 tool
- Tenant Logs — 2 tools
- Tenant Organizations — 5 tools
- Tenant Profile — 2 tools
- Tenant Provisioning — 9 tools
- Tenant Shares — 1 tool
- Access Apps — 37 tools
- Access Authenticator Device Aaguids — 1 tool
- Access Bookmarks — 5 tools
- Access Certificates — 14 tools
- Access Custom Pages — 6 tools
- Access Gateway Ca — 3 tools
- Access Groups — 10 tools
- Access Identity Providers — 13 tools
- Access Idp Federation Grants — 4 tools
- Access Keys — 3 tools
- Access Logs — 4 tools
- Access Organizations — 10 tools
- Access Policies — 5 tools
- Access Policy Tests — 3 tools
- Access Saml Certificates — 4 tools
- Access Seats — 1 tool
- Access Service Tokens — 12 tools
- Access Tags — 5 tools
- Access Users — 10 tools
- AI — 14 tools
- AI Gateway Billing — 14 tools
- AI Gateway Custom Providers — 10 tools
- AI Gateway Evaluation Types — 1 tool
- AI Gateway Gateways — 39 tools
- AI Gateway Logging State — 2 tools
- AI Search — 49 tools
- API Gateway — 44 tools
- Schema Validation — 15 tools
- Token Validation — 15 tools
- Waiting Rooms — 24 tools
- ACM — 6 tools
- Certificate Authorities — 2 tools
- Certificates — 4 tools
- Certificates CT — 2 tools
- Client Certificates — 5 tools
- Custom Certificates — 6 tools
- Custom CSRs — 8 tools
- DCV Delegation — 1 tool
- Dls — 7 tools
- Keyless Certificates — 5 tools
- mTLS Certificates — 5 tools
- Origin TLS Client Auth — 13 tools
- SSL — 12 tools
- Cloudforce One Events — 94 tools
- Cloudforce One Banner — 1 tool
- Cloudforce One Binary — 2 tools
- Cloudforce One Requests — 23 tools
- Cloudforce One Rules — 29 tools
- Cloudforce One Scans — 5 tools
- Cloudforce One v2 — 48 tools
- Data Security — 36 tools
- DLP Custom Prompt Topics — 5 tools
- DLP Data Classes — 5 tools
- DLP Data Tag Categories — 10 tools
- DLP Data Tag Category Templates — 2 tools
- DLP Datasets — 9 tools
- DLP Document Fingerprints — 6 tools
- DLP Email — 8 tools
- DLP Entries — 12 tools
- DLP Limits — 1 tool
- DLP Patterns — 1 tool
- DLP Payload Log — 2 tools
- DLP Profiles — 14 tools
- DLP Sensitivity Groups — 14 tools
- DLP Settings — 4 tools
- Field Extractors — 3 tools
- Agent Memory — 14 tools
- Analytics Engine — 2 tools
- Artifacts — 19 tools
- Autorag — 7 tools
- Containers — 14 tools
- D1 — 12 tools
- Hyperdrive — 8 tools
- Pipelines — 19 tools
- Queues — 23 tools
- Secrets Store — 12 tools
- Storage — 14 tools
- Vectorize — 24 tools
- Workflows — 23 tools
- Email Auth — 3 tools
- Email Routing — 32 tools
- Email Security Analytics — 1 tool
- Email Security Investigate — 18 tools
- Email Security Phishguard — 1 tool
- Email Security Settings — 53 tools
- Email Security Submissions — 1 tool
- Email Sending — 29 tools
- Browser Extension — 6 tools
- Devices Client Versions — 2 tools
- Devices Deployment Groups — 5 tools
- Devices IP Profiles — 5 tools
- Devices Networks — 5 tools
- Devices Override Codes — 1 tool
- Devices Physical Devices — 4 tools
- Devices Policies — 1 tool
- Devices Policy — 18 tools
- Devices Posture — 10 tools
- Devices Registrations — 7 tools
- Devices Resilience — 2 tools
- Devices Revoke — 1 tool
- Devices Settings — 4 tools
- Devices Unrevoke — 1 tool
- DEX — 31 tools
- Gateway — 57 tools
- Infrastructure — 9 tools
- Zero Trust Gateway Devices — 2 tools
- Zero Trust Risk Scoring — 11 tools
- Client Secret — 1 tool
- IAM — 17 tools
- IAM Memberships — 4 tools
- IAM Organizations — 1 tool
- IAM Shares — 20 tools
- IAM Tokens — 7 tools
- OAuth Clients — 7 tools
- Roles — 2 tools
- SCIM — 16 tools
- Scopes — 1 tool
- SSO Connectors — 6 tools
- Abuse Reports — 10 tools
- Botnet Feed — 4 tools
- Brand Protection — 32 tools
- Cloudforce One — 29 tools
- Intel — 39 tools
- Registrar — 13 tools
- Registrar Sandbox — 10 tools
- Security Center — 26 tools
- Urlscanner — 14 tools
- Vuln Scanner — 22 tools
- Addressing — 41 tools
- CNI — 16 tools
- Connectivity — 5 tools
- Load Balancing Load Balancers — 42 tools
- Spectrum — 9 tools
- Magic Advanced DNS Protection — 6 tools
- Magic Advanced Tcp Protection — 39 tools
- Magic Apps — 5 tools
- Magic BGP — 7 tools
- Magic Cf Interconnects — 4 tools
- Magic Cloud — 33 tools
- Magic Cloudforce One Sites — 9 tools
- Magic Connectors — 14 tools
- Magic GRE Tunnels — 6 tools
- Magic IPsec Tunnels — 8 tools
- Magic Redundancy Groups — 5 tools
- Magic Routes — 7 tools
- Magic Sites — 34 tools
- Browser Rendering — 28 tools
- Images — 35 tools
- Media Stream — 49 tools
- Resource Library — 7 tools
- v1 — 7 tools
- v2 — 2 tools
- Alerting — 25 tools
- Bulk — 1 tool
- Event Subscriptions — 5 tools
- Logpush — 34 tools
- MNM — 16 tools
- Observability Analytics — 10 tools
- Observability Devices — 2 tools
- Observability Logs — 29 tools
- PCAPs — 9 tools
- Reporting — 6 tools
- Request Tracer — 1 tool
- RUM — 13 tools
- Slurper — 12 tools
- Agent Readiness — 1 tool
- Attacks — 45 tools
- Bots — 7 tools
- Email — 38 tools
- Radar AI — 13 tools
- Radar CT — 7 tools
- Radar Leaked Credential Checks — 6 tools
- Robots Txt — 2 tools
- Verified Bots — 2 tools
- Annotations — 4 tools
- AS112 — 19 tools
- BGP — 19 tools
- Datasets — 3 tools
- DNS — 25 tools
- Entities — 9 tools
- Geolocations — 2 tools
- HTTP — 41 tools
- Netflows — 6 tools
- Origins — 5 tools
- Post Quantum — 3 tools
- Quality — 6 tools
- Ranking — 6 tools
- Search — 1 tool
- Tcp Resets Timeouts — 2 tools
- Tlds — 4 tools
- Traffic Anomalies — 3 tools
- Calls — 10 tools
- MoQ — 8 tools
- Pay Per Crawl — 17 tools
- Realtime Kit — 61 tools
- AI Audit — 2 tools
- AI Security — 4 tools
- Bot Management — 4 tools
- Challenges — 6 tools
- Content Upload Scan — 8 tools
- Custom Pages — 18 tools
- Filters — 7 tools
- Fraud Detection — 2 tools
- Page Shield — 13 tools
- Rate Limit Analytics — 1 tool
- Rate Limits — 5 tools
- Rules — 11 tools
- Rulesets — 32 tools
- WAF Firewall — 42 tools
- WAF Leaked Credential Checks — 7 tools
- Builds — 32 tools
- Environments — 7 tools
- Pages — 23 tools
- Snippets — 8 tools
- Triggers — 4 tools
- Workers Account Settings — 2 tools
- Workers Dispatch — 26 tools
- Workers Domains — 4 tools
- Workers Durable Objects — 2 tools
- Workers Observability — 23 tools
- Workers Placement — 1 tool
- Workers Routes — 5 tools
- Workers Scripts — 33 tools
- Workers Scripts Search — 1 tool
- Workers Services — 4 tools
- Workers Subdomain — 3 tools
- Workers Workers — 11 tools
- Argo — 4 tools
- Available Plans — 2 tools
- Available Rate Plans — 1 tool
- Cache — 23 tools
- Cloud Connector — 2 tools
- Custom Hostnames — 11 tools
- Healthchecks — 9 tools
- Hostnames — 4 tools
- Managed Headers — 3 tools
- Media — 2 tools
- Origin — 7 tools
- Pagerules — 7 tools
- Precursor — 2 tools
- Purge Cache — 1 tool
- Smart Shield — 10 tools
- Speed API — 10 tools
- URL Normalization — 3 tools
- Web3 — 12 tools
- Zone Settings — 54 tools
- Zone Settings Stream — 1 tool
MCP Analytics
cf_get_mcp_portal_tool_calls details
cf_get_mcp_portal_tool_calls details
[Cloudflare] Per-portal MCP tool-call timeseries. GET /accounts//access/ai-controls/mcp/analytics/portals//tool-calls/timeseries. Path parameters: account_id, portal_id. Optional filters: granularity, aggregate, tz, days. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_mcp_server_tool_calls details
cf_get_mcp_server_tool_calls details
[Cloudflare] Per-server MCP tool-call timeseries. GET /accounts//access/ai-controls/mcp/analytics/servers//tool-calls/timeseries. Path parameters: account_id, server_id. Optional filters: granularity, aggregate, tz, days. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_mcp_tool_call_timeseries details
cf_get_mcp_tool_call_timeseries details
[Cloudflare] Account-global MCP tool-call timeseries. Account-wide MCP tool-call volume over time — the read that answers whether anyone is actually using the portals, and when. GET /accounts//access/ai-controls/mcp/analytics/tool-calls/timeseries. Path parameters: account_id. Optional filters: granularity, aggregate, tz, days. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
MCP Portals
cf_create_mcp_portal details
cf_create_mcp_portal details
[Cloudflare] Create a new MCP Portal. Additive: creates a new portal and changes no existing one. POST /accounts//access/ai-controls/mcp/portals. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: allow_code_mode, code_mode, description, hostname, id, name, secure_web_gateway, servers. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_mcp_portal details
cf_delete_mcp_portal details
[Cloudflare] DESTRUCTIVE: Delete an MCP Portal. Why this is destructive: Deletes the portal; every client pointed at its URL stops resolving. DELETE /accounts//access/ai-controls/mcp/portals/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_mcp_portal details
cf_get_mcp_portal details
[Cloudflare] Read details of an MCP Portal. Returns the portal with its bound servers and its hostname. Read it before an update: the update replaces the portal wholesale, so this is where you get the current binding list to send back. GET /accounts//access/ai-controls/mcp/portals/. Path parameters: id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_mcp_server_redirect_uri details
cf_get_mcp_server_redirect_uri details
[Cloudflare] Resolve an MCP server OAuth redirect URI. GET /accounts//access/ai-controls/mcp/portals//servers//effective-redirect-uri. Path parameters: portal_id, server_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_mcp_portals details
cf_list_mcp_portals details
[Cloudflare] List MCP Portals. An MCP Portal is the Zero Trust front door that publishes a set of MCP servers to users behind an Access policy. The portal id this returns is what the read, update and delete tools take, and it pairs with a server id on the redirect-URI tool. GET /accounts//access/ai-controls/mcp/portals. Path parameters: account_id. Optional filters: page, per_page, search. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_mcp_portal details
cf_update_mcp_portal details
[Cloudflare] DESTRUCTIVE: Update an MCP Portal. Why this is destructive: Wholesale replace: the portal is rewritten from the body, so any server binding or Access policy you omit is removed. PUT /accounts//access/ai-controls/mcp/portals/. Path parameters: id, account_id. Send the request body as JSON; Cloudflare documents these fields: allow_code_mode, code_mode, description, hostname, name, secure_web_gateway, servers. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
MCP Servers
cf_create_mcp_server details
cf_create_mcp_server details
[Cloudflare] Create a new MCP Server. Additive: registers a new server and changes no existing one. POST /accounts//access/ai-controls/mcp/servers. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: auth_credentials, auth_type, client_secret, description, hostname, id, is_shared_oauth_callback_enabled, name, secure_web_gateway, updated_prompts, updated_tools. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_mcp_server details
cf_delete_mcp_server details
[Cloudflare] DESTRUCTIVE: Delete an MCP Server. Why this is destructive: Deletes the server and unbinds it from every portal that referenced it. DELETE /accounts//access/ai-controls/mcp/servers/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_mcp_server details
cf_get_mcp_server details
[Cloudflare] Read the details of an MCP Server. Returns the server with its upstream URL and last-synced capabilities. Read it before an update, which replaces the record wholesale. GET /accounts//access/ai-controls/mcp/servers/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_mcp_servers details
cf_list_mcp_servers details
[Cloudflare] List MCP Servers. The MCP servers registered on the account, each with the upstream URL and the capabilities Cloudflare last synced from it. If a portal is serving stale tools, sync the server rather than recreating it. GET /accounts//access/ai-controls/mcp/servers. Path parameters: account_id. Optional filters: page, per_page, search. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_sync_mcp_server details
cf_sync_mcp_server details
[Cloudflare] Sync MCP Server Capabilities. Re-reads the upstream server capabilities; nothing the customer authored is replaced. POST /accounts//access/ai-controls/mcp/servers//sync. Path parameters: id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_mcp_server details
cf_update_mcp_server details
[Cloudflare] DESTRUCTIVE: Update an MCP Server. Why this is destructive: Wholesale replace: the server record is rewritten from the body, so an omitted field reverts to its default. PUT /accounts//access/ai-controls/mcp/servers/. Path parameters: id, account_id. Send the request body as JSON; Cloudflare documents these fields: auth_credentials, client_secret, description, is_shared_oauth_callback_enabled, name, secure_web_gateway, updated_prompts, updated_tools. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Zerotrust
cf_create_zerotrust_routes_hostname details
cf_create_zerotrust_routes_hostname details
[Cloudflare] Create hostname route. Additive: creates a new record and changes no existing one. POST /accounts//zerotrust/routes/hostname. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: comment, hostname, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zerotrust_subnets_warp details
cf_create_zerotrust_subnets_warp details
[Cloudflare] Create WARP IP subnet. Additive: creates a new record and changes no existing one. POST /accounts//zerotrust/subnets/warp. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: comment, is_default_network, name, network. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zerotrust_routes_hostname details
cf_delete_zerotrust_routes_hostname details
[Cloudflare] DESTRUCTIVE: Delete hostname route. Why this is destructive: Deletes the hostname route; traffic for that hostname stops going down the tunnel immediately and resolves wherever public DNS points it. DELETE /accounts//zerotrust/routes/hostname/. Path parameters: account_id, hostname_route_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zerotrust_subnets_warp details
cf_delete_zerotrust_subnets_warp details
[Cloudflare] DESTRUCTIVE: Delete WARP IP subnet. Why this is destructive: Deletes the WARP IP subnet. Devices assigned addresses from it lose their tunnel addressing, so this disconnects users rather than only editing a record. DELETE /accounts//zerotrust/subnets/warp/. Path parameters: account_id, subnet_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zerotrust_connectivity_settings details
cf_get_zerotrust_connectivity_settings details
[Cloudflare] Get Zero Trust Connectivity Settings. The account-wide Zero Trust connectivity posture (ICMP proxy, WARP-to-WARP, default settings for new tunnels). Read it before changing a route or subnet: these settings decide whether a route is reachable at all. GET /accounts//zerotrust/connectivity_settings. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zerotrust_routes_hostname details
cf_get_zerotrust_routes_hostname details
[Cloudflare] Get hostname route. GET /accounts//zerotrust/routes/hostname/. Path parameters: account_id, hostname_route_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zerotrust_subnets_initial_resolved_ip details
cf_get_zerotrust_subnets_initial_resolved_ip details
[Cloudflare] Get Initial Resolved IP Subnet. GET /accounts//zerotrust/subnets/initial_resolved_ip/. Path parameters: account_id, address_family. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zerotrust_subnets_warp details
cf_get_zerotrust_subnets_warp details
[Cloudflare] Get WARP IP subnet. GET /accounts//zerotrust/subnets/warp/. Path parameters: account_id, subnet_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zerotrust_routes_hostnames details
cf_list_zerotrust_routes_hostnames details
[Cloudflare] List hostname routes. Hostname routes send a named host down a tunnel instead of an IP range. The route id every other hostname-route tool takes comes from here. GET /accounts//zerotrust/routes/hostname. Path parameters: account_id. Optional filters: id, hostname, tunnel_id, comment, existed_at, is_deleted, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zerotrust_subnets details
cf_list_zerotrust_subnets details
[Cloudflare] List Subnets. GET /accounts//zerotrust/subnets. Path parameters: account_id. Optional filters: name, comment, network, existed_at, address_family, is_default_network, is_deleted, sort_order, subnet_types, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zerotrust_subnets_initial_resolved_ip details
cf_set_zerotrust_subnets_initial_resolved_ip details
[Cloudflare] DESTRUCTIVE: Update Initial Resolved IP Subnet. Why this is destructive: Wholesale replace of the initial resolved-IP subnet; the previous value is gone and in-flight sessions re-resolve. PUT /accounts//zerotrust/subnets/initial_resolved_ip/. Path parameters: account_id, address_family. Send the request body as JSON; Cloudflare documents these fields: comment, name, network. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_zerotrust_connectivity_setting details
cf_update_zerotrust_connectivity_setting details
[Cloudflare] Updates the Zero Trust Connectivity Settings. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//zerotrust/connectivity_settings. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: icmp_proxy_enabled, offramp_warp_enabled. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_zerotrust_routes_hostname details
cf_update_zerotrust_routes_hostname details
[Cloudflare] Update hostname route. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//zerotrust/routes/hostname/. Path parameters: account_id, hostname_route_id. Send the request body as JSON; Cloudflare documents these fields: comment, hostname, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_zerotrust_subnets_cloudflare_source details
cf_update_zerotrust_subnets_cloudflare_source details
[Cloudflare] Update Cloudflare Source Subnet. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//zerotrust/subnets/cloudflare_source/. Path parameters: account_id, address_family. Send the request body as JSON; Cloudflare documents these fields: comment, name, network. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_zerotrust_subnets_warp details
cf_update_zerotrust_subnets_warp details
[Cloudflare] Update WARP IP subnet. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//zerotrust/subnets/warp/. Path parameters: account_id, subnet_id. Send the request body as JSON; Cloudflare documents these fields: comment, is_default_network, name, network. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Custom Ns
cf_create_custom_ns details
cf_create_custom_ns details
[Cloudflare] Add Account Custom Nameserver. Additive: it registers one more nameserver hostname on the account and changes no zone. A zone only begins answering from it once that zone is pointed at the matching nameserver set. Account custom nameservers need a Business or Enterprise account - Cloudflare's own plan table marks Free and Pro false - and the API token needs the Account Settings Write permission group. POST /accounts//custom_ns. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_custom_ns details
cf_delete_custom_ns details
[Cloudflare] DESTRUCTIVE: Delete Account Custom Nameserver. Why this is destructive: The account stops offering that nameserver hostname to its zones. A zone still delegated to it at the registrar keeps sending the world to a name Cloudflare no longer serves for this account, so move the zones off the set and fix the registrar's NS records BEFORE deleting. Account custom nameservers need a Business or Enterprise account - Cloudflare's own plan table marks Free and Pro false - and the API token needs the Account Settings Write permission group. DELETE /accounts//custom_ns/. Path parameters: custom_ns_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_custom_ns details
cf_list_custom_ns details
[Cloudflare] List Account Custom Nameservers. Account custom nameservers are the vanity nameserver hostnames - ns1.example.com and friends - an account can delegate its zones to instead of Cloudflare's shared pair. Start here: each entry's ns_name is the FQDN cf_delete_custom_ns takes, and its ns_set number is the set a zone is pointed at through cf_update_zones_dns_setting's nameservers object. Cloudflare paginates nothing here: the whole collection comes back in one response. Account custom nameservers need a Business or Enterprise account - Cloudflare's own plan table marks Free and Pro false - and the API token needs the Account Settings Read permission group. GET /accounts//custom_ns. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones_custom_ns details
cf_list_zones_custom_ns details
[Cloudflare] Get Account Custom Nameserver Related Zone Metadata. Reads whether this zone uses the account's custom nameservers and which nameserver set it is on. Cloudflare's own document deprecates it in favour of Show DNS Settings for a zone, which StackJack exposes as cf_get_zones_dns_settings - prefer that tool and read nameservers.type and nameservers.ns_set there. Account custom nameservers need a Business or Enterprise account - Cloudflare's own plan table marks Free and Pro false - and the API token needs the Account Settings Read permission group. GET /zones//custom_ns. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_set_zones_custom_ns details
cf_set_zones_custom_ns details
[Cloudflare] DESTRUCTIVE: Set Account Custom Nameserver Related Zone Metadata. Why this is destructive: A PUT replaces this zone's whole account-custom-nameserver metadata from the body: leave enabled out and it is cleared, leave ns_set out and the zone's set assignment goes with it. Turning enabled off, or moving the zone to a different set, changes which nameservers answer for the zone, and the NS records at the registrar have to be changed to match or the zone stops resolving. Cloudflare deprecates this in favour of Update DNS Settings for a zone, which StackJack exposes as cf_update_zones_dns_setting - set nameservers.type and nameservers.ns_set there instead. Cloudflare also notes that making NEW zones in the account use account custom nameservers by default is an account setting (use_account_custom_ns_by_default), not a per-zone call. Account custom nameservers need a Business or Enterprise account - Cloudflare's own plan table marks Free and Pro false - and the API token needs the Account Settings Write permission group. PUT /zones//custom_ns. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
DNS Analytics
cf_get_zones_dns_analytics_report_bytimes details
cf_get_zones_dns_analytics_report_bytimes details
[Cloudflare] DNS Analytics time series for a zone. The same zone metrics as cf_get_zones_dns_analytics_reports, bucketed over time: time_delta picks the bucket size and the result carries one value per bucket. Cloudflare marks this deprecated and points at its API deprecation notice dated 2025-12-09, a date that has already passed - the endpoint still answers, and Cloudflare names no REST replacement for it, so there is no non-deprecated sibling to move to. GET /zones//dns_analytics/report/bytime. Path parameters: zone_id. Optional filters: metrics, dimensions, since, until, limit, sort, filters, time_delta. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_get_zones_dns_analytics_reports details
cf_get_zones_dns_analytics_reports details
[Cloudflare] DNS Analytics report table for a zone. One aggregated row per combination of the dimensions you group by, over the whole window - the table view rather than a time series; cf_get_zones_dns_analytics_report_bytimes is the series. The numbers are this zone's own authoritative query traffic. Cloudflare marks this deprecated and points at its API deprecation notice dated 2025-12-09, a date that has already passed - the endpoint still answers, and Cloudflare names no REST replacement for it, so there is no non-deprecated sibling to move to. GET /zones//dns_analytics/report. Path parameters: zone_id. Optional filters: metrics, dimensions, since, until, limit, sort, filters. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
DNS Firewall
cf_create_dns_firewall details
cf_create_dns_firewall details
[Cloudflare] Create DNS Firewall Cluster. Additive: it stands up a new cluster and touches no existing one. Nothing resolves through it until the customer points resolvers at the addresses Cloudflare returns. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Write permission group. POST /accounts//dns_firewall. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_dns_firewall details
cf_delete_dns_firewall details
[Cloudflare] DESTRUCTIVE: Delete DNS Firewall Cluster. Why this is destructive: The cluster goes and Cloudflare releases the addresses it answered on. Every resolver still pointed at those addresses stops getting answers the moment it does, so move them off first - a rebuilt cluster is given new addresses and the old ones are not held for you. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Write permission group. DELETE /accounts//dns_firewall/. Path parameters: dns_firewall_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_dns_firewall details
cf_get_dns_firewall details
[Cloudflare] DNS Firewall Cluster Details. Reads one cluster's whole configuration - upstream_ips, the cache TTL bounds, the rate limit and the attack-mitigation settings. Worth doing before cf_update_dns_firewall, because upstream_ips is an array that the PATCH replaces wholesale. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Read or DNS Firewall Write permission group. GET /accounts//dns_firewall/. Path parameters: dns_firewall_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_dns_firewall_dns_analytics_report_bytimes details
cf_get_dns_firewall_dns_analytics_report_bytimes details
[Cloudflare] DNS Analytics time series for a DNS Firewall cluster. The same cluster metrics as cf_get_dns_firewall_dns_analytics_reports, bucketed over time by time_delta. Cloudflare marks this deprecated and points at its API deprecation notice dated 2025-12-09, a date that has already passed - the endpoint still answers, and Cloudflare names no REST replacement for it, so there is no non-deprecated sibling to move to. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Read or DNS Firewall Write permission group. GET /accounts//dns_firewall//dns_analytics/report/bytime. Path parameters: dns_firewall_id, account_id. Optional filters: metrics, dimensions, since, until, limit, sort, filters, time_delta. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_get_dns_firewall_dns_analytics_reports details
cf_get_dns_firewall_dns_analytics_reports details
[Cloudflare] DNS Analytics report table for a DNS Firewall cluster. The aggregated table for ONE DNS Firewall cluster's own resolver traffic - queries that passed through the cluster, not a zone's authoritative traffic. Cloudflare marks this deprecated and points at its API deprecation notice dated 2025-12-09, a date that has already passed - the endpoint still answers, and Cloudflare names no REST replacement for it, so there is no non-deprecated sibling to move to. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Read or DNS Firewall Write permission group. GET /accounts//dns_firewall//dns_analytics/report. Path parameters: dns_firewall_id, account_id. Optional filters: metrics, dimensions, since, until, limit, sort, filters. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_get_dns_firewall_reverse_dns details
cf_get_dns_firewall_reverse_dns details
[Cloudflare] Show DNS Firewall Cluster Reverse DNS. Reads the PTR records Cloudflare publishes for the cluster's own IP addresses - the reverse DNS an upstream nameserver sees when the cluster queries it. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Read or DNS Firewall Write permission group. GET /accounts//dns_firewall//reverse_dns. Path parameters: dns_firewall_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_dns_firewalls details
cf_list_dns_firewalls details
[Cloudflare] List DNS Firewall Clusters. A DNS Firewall cluster is a Cloudflare-hosted resolver placed in front of a customer's own authoritative nameservers, caching, rate-limiting and mitigating attacks on the way through. Start here: each cluster's id is what every other DNS Firewall tool takes, and the addresses Cloudflare returns are the ones the customer points resolvers at. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Read or DNS Firewall Write permission group. GET /accounts//dns_firewall. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_dns_firewall details
cf_update_dns_firewall details
[Cloudflare] DESTRUCTIVE: Update DNS Firewall Cluster. Why this is destructive: Partial update: Cloudflare applies only the fields present in the body. upstream_ips is the exception that bites - it is an ARRAY, so sending it replaces the whole upstream list rather than adding to it, and a short or mistyped list stops the cluster resolving for everything behind it. Read cf_get_dns_firewall first and send the complete list. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Write permission group. PATCH /accounts//dns_firewall/. Path parameters: dns_firewall_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_dns_firewall_reverse_dns details
cf_update_dns_firewall_reverse_dns details
[Cloudflare] Update DNS Firewall Cluster Reverse DNS. Partial update: Cloudflare applies only the fields present in the body. ptr is a MAP of cluster IP address to PTR content, and Cloudflare does not document whether an address left out of the map is kept or cleared - read cf_get_dns_firewall_reverse_dns first and send the complete map. DNS Firewall is Enterprise-only in Cloudflare's own plan table, and the API token needs the DNS Firewall Write permission group. PATCH /accounts//dns_firewall//reverse_dns. Path parameters: dns_firewall_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
DNS Record Scans
cf_list_scanned_dns_records details
cf_list_scanned_dns_records details
[Cloudflare] List Scanned DNS Records. GET /zones//dns_records/scan/review. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_review_scanned_dns_records details
cf_review_scanned_dns_records details
[Cloudflare] Review Scanned DNS Records. Additive: accepts scanned records into the zone and removes none. POST /zones//dns_records/scan/review. Path parameters: zone_id. Send the request body as JSON; Cloudflare documents these fields: accepts, rejects. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_scan_dns_records details
cf_scan_dns_records details
[Cloudflare] Scan DNS Records. Additive: the scan adds records it discovers and removes none. POST /zones//dns_records/scan. Path parameters: zone_id. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_trigger_dns_record_scan details
cf_trigger_dns_record_scan details
[Cloudflare] Trigger DNS Record Scan. Starts a scan; nothing is written to the zone until the review call accepts it. POST /zones//dns_records/scan/trigger. Path parameters: zone_id. An optional JSON request body is accepted; Cloudflare publishes no sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
DNS Records
cf_batch_dns_records details
cf_batch_dns_records details
[Cloudflare] DESTRUCTIVE: Batch DNS Records. Why this is destructive: One batch carries deletes, patches and puts together and applies them atomically, so it can remove records. POST /zones//dns_records/batch. Path parameters: zone_id. Optional filters: include_shadow_metadata. Send the request body as JSON; Cloudflare documents these fields: deletes, patches, posts, puts. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_dns_record details
cf_create_dns_record details
[Cloudflare] Create DNS Record. Additive, and the plan task rules DNS record create false. Cloudflare requires type, name and content; ttl of 1 means automatic, and proxied only applies to record types Cloudflare can proxy. A duplicate name and type is refused rather than merged. POST /zones//dns_records. Path parameters: zone_id. Optional filters: include_shadow_metadata. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_dns_record details
cf_delete_dns_record details
[Cloudflare] DESTRUCTIVE: Delete DNS Record. Why this is destructive: Deletes the record; resolution for that name stops immediately. DELETE /zones//dns_records/. Path parameters: dns_record_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_export_dns_records details
cf_export_dns_records details
[Cloudflare] Export DNS Records. Returns the whole zone as a BIND file, which is the quickest way to hand a customer or an auditor a complete picture of their DNS. This is the one Cloudflare response in this connector that is not JSON. GET /zones//dns_records/export. Path parameters: zone_id. Returns the zone file as plain text exactly as Cloudflare sent it, not JSON.
cf_get_dns_record details
cf_get_dns_record details
[Cloudflare] DNS Record Details. Reads one record by the id the list tool returned. Use it to confirm the current content, TTL and proxy state before an update, since the overwrite tool resets anything left out. GET /zones//dns_records/. Path parameters: dns_record_id, zone_id. Optional filters: include_shadow_metadata. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_import_dns_records details
cf_import_dns_records details
[Cloudflare] DESTRUCTIVE: Import DNS Records. Why this is destructive: A BIND file import writes every record it contains in one call and overwrites a record of the same name and type. Takes the BIND zone text itself, not a file path or an upload. Review the export of the target zone first: this writes every record the file contains in one call. POST /zones//dns_records/import. Path parameters: zone_id. Send the BIND zone file text itself as the file argument - this is not a file upload, it is the zone text. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_dns_records details
cf_list_dns_records details
[Cloudflare] List DNS Records. The first call for almost any DNS question. Narrow with type (A, AAAA, CNAME, MX, TXT) and name; match=all means every filter must hit, match=any means at least one. The record id it returns is what the get, update, overwrite and delete tools take. GET /zones//dns_records. Path parameters: zone_id. Optional filters: name, name.exact, name.contains, name.startswith, name.endswith, type, content, content.exact, content.contains, content.startswith, content.endswith, proxied, match, comment, comment.present, comment.absent, comment.exact, comment.contains, comment.startswith, comment.endswith, tag, tag.present, tag.absent, tag.exact, tag.contains, tag.startswith, tag.endswith, search, tag_match, page, per_page, order, direction, include_shadow_metadata, shadowed_by_name, shadowing_name. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_overwrite_dns_record details
cf_overwrite_dns_record details
[Cloudflare] DESTRUCTIVE: Overwrite DNS Record. Why this is destructive: Wholesale replace: Cloudflare calls this Overwrite, and every field you omit is reset to its default rather than kept. PUT /zones//dns_records/. Path parameters: dns_record_id, zone_id. Optional filters: include_shadow_metadata. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_dns_record details
cf_update_dns_record details
[Cloudflare] Update DNS Record. Partial update: omitted fields keep their value, and the plan task rules DNS record update false. The safe way to change one field of a record: anything you leave out keeps its current value. Prefer it over the overwrite tool unless you deliberately want the omitted fields reset. PATCH /zones//dns_records/. Path parameters: dns_record_id, zone_id. Optional filters: include_shadow_metadata. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
DNS Settings
cf_create_dns_settings_view details
cf_create_dns_settings_view details
[Cloudflare] Create Internal DNS View. Additive: it creates a view and leaves every existing one alone. A zone named in zones starts being answered through this view immediately, so a zone bound to the wrong view answers the wrong clients. Internal DNS views are Enterprise-only, and the API token needs the DNS View Write permission group, which is separate from plain DNS Write. POST /accounts//dns_settings/views. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_dns_settings_view details
cf_delete_dns_settings_view details
[Cloudflare] DESTRUCTIVE: Delete Internal DNS View. Why this is destructive: The view goes and every zone bound to it loses that binding, so clients that were resolving those zones through the view stop getting the view's answers. The zones themselves survive; the binding does not, and it cannot be recovered from here. Internal DNS views are Enterprise-only, and the API token needs the DNS View Write permission group, which is separate from plain DNS Write. DELETE /accounts//dns_settings/views/. Path parameters: account_id, view_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_dns_settings details
cf_get_dns_settings details
[Cloudflare] Show account DNS settings. The ACCOUNT-level settings that sit above every zone: enforce_dns_only, and the zone_defaults block new zones inherit. cf_get_zones_dns_settings is the per-zone read - Cloudflare gives both operations the same summary, so check the path when choosing. The API token needs the Account DNS Settings Read permission group. GET /accounts//dns_settings. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_dns_settings_view details
cf_get_dns_settings_view details
[Cloudflare] DNS Internal View Details. Reads one view and the zone ids bound to it. Worth doing before cf_update_dns_settings_view, because zones is an array that the PATCH replaces. Internal DNS views are Enterprise-only, and the API token needs the DNS View Read or DNS View Write permission group, which is separate from plain DNS Read. GET /accounts//dns_settings/views/. Path parameters: account_id, view_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_dns_settings details
cf_get_zones_dns_settings details
[Cloudflare] Show zone DNS settings. The per-ZONE settings: nameservers.type and nameservers.ns_set, which decide the nameservers the zone is delegated to, plus zone_mode, flatten_all_cnames, multi_provider, secondary_overrides, ns_ttl and the SOA components. cf_get_dns_settings is the account-level read - Cloudflare gives both operations the same summary, so check the path when choosing. The API token needs Zone DNS Settings Read or DNS Read. GET /zones//dns_settings. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_dns_settings_views details
cf_list_dns_settings_views details
[Cloudflare] List Internal DNS Views. An internal DNS view binds a set of zones together so they are answered only to clients resolving through that view - Cloudflare's split-horizon construct. Start here: each view's id is what the get, update and delete tools take, and zones is the list of zone ids bound to it. Narrow with name and the name.exact / name.contains / name.startswith / name.endswith forms, or by zone_id or zone_name; match=all requires every filter to hit and match=any at least one. Internal DNS views are Enterprise-only, and the API token needs the DNS View Read or DNS View Write permission group, which is separate from plain DNS Read. GET /accounts//dns_settings/views. Path parameters: account_id. Optional filters: name, name.exact, name.contains, name.startswith, name.endswith, zone_id, zone_name, match, page, per_page, order, direction. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_dns_setting details
cf_update_dns_setting details
[Cloudflare] DESTRUCTIVE: Update account DNS settings. Why this is destructive: This is the account-wide override. Cloudflare's own words for enforce_dns_only are that it 'forces all proxied DNS records in the account to behave as DNS-only at the edge, regardless of each record's individual proxy setting' - one call changes how every proxied record in every zone on the account is served, and each record's own proxy setting is ignored while it is on. The derived verdict read this as an ordinary partial update; the blast radius is the whole account. zone_defaults carries the settings a NEW zone starts with, so a change there is not retroactive, while enforce_dns_only takes effect for existing zones immediately. The API token needs the Account DNS Settings Write permission group. PATCH /accounts//dns_settings. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_dns_settings_view details
cf_update_dns_settings_view details
[Cloudflare] DESTRUCTIVE: Update Internal DNS View. Why this is destructive: Partial update: Cloudflare applies only the fields present. zones is an ARRAY, so sending it replaces the whole binding list and a zone left out of it stops being answered through this view. Read cf_get_dns_settings_view first and send the complete list. Internal DNS views are Enterprise-only, and the API token needs the DNS View Write permission group, which is separate from plain DNS Write. PATCH /accounts//dns_settings/views/. Path parameters: account_id, view_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_zones_dns_setting details
cf_update_zones_dns_setting details
[Cloudflare] DESTRUCTIVE: Update zone DNS settings. Why this is destructive: nameservers.type and nameservers.ns_set decide which nameservers the WHOLE zone is delegated to - cloudflare.standard, cloudflare.advanced, custom.account, custom.tenant or custom.zone - and a zone whose delegation stops matching the NS records at its registrar stops resolving for everyone. zone_mode switches the entire zone between standard, cdn_only and dns_only, and flatten_all_cnames changes what every CNAME in the zone answers. Cloudflare deprecated PUT /zones//custom_ns in favour of THIS operation, and that one is destructive, so the replacement cannot be gentler than the call it replaces. The derived verdict read this as an ordinary partial update. The one tool here that changes zone-wide DNS behaviour rather than a single record; cf_update_dns_record is what you want for one name. foundation_dns is deprecated in Cloudflare's own schema - use nameservers.type to configure Advanced Nameservers. The API token needs Zone DNS Settings Write plus DNS Write. PATCH /zones//dns_settings. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
DNS Usage
cf_get_account_dns_record_usage details
cf_get_account_dns_record_usage details
[Cloudflare] Get DNS Record Usage for Account. GET /accounts//dns_records/usage. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zone_dns_record_usage details
cf_get_zone_dns_record_usage details
[Cloudflare] Get DNS Record Usage. GET /zones//dns_records/usage. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
DNSSEC
cf_delete_zones_dnssec details
cf_delete_zones_dnssec details
[Cloudflare] DESTRUCTIVE: Delete DNSSEC records. Why this is destructive: DNSSEC is turned off for the zone and Cloudflare discards the signing material. If the registrar still publishes the zone's DS record, every validating resolver refuses the whole domain from that moment - remove the DS record at the registrar FIRST. Enabling again later produces a new key and a new DS record, so the old one never becomes valid again. DELETE /zones//dnssec. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_dnssecs details
cf_get_zones_dnssecs details
[Cloudflare] DNSSEC Details. The zone's DNSSEC state and the DS record the customer has to publish at their REGISTRAR: status, algorithm, digest, digest_type, key_tag, flags and public_key, plus a ready-made ds string. Read this first - DNSSEC only takes effect once that DS record is at the registrar, and removing it there is the first step of turning DNSSEC off safely. GET /zones//dnssec. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones_dnssec_zsks details
cf_list_zones_dnssec_zsks details
[Cloudflare] List DNSSEC ZSKs. The Zone Signing Keys DNSSEC uses for this zone: each entry carries its DNSKEY record, a lifecycle Tag (active, publish, external, retired, revoked or removed) and the storage Location Cloudflare keeps the key material in. The SigningKey member includes the key's encrypted PRIVATE key material, so treat the whole result as credential material and do not persist it. Cloudflare paginates nothing here: the whole collection comes back in one response. GET /zones//dnssec/zsk. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_zones_dnssec details
cf_update_zones_dnssec details
[Cloudflare] DESTRUCTIVE: Edit DNSSEC Status. Why this is destructive: Cloudflare's own description of this operation is 'Enable or disable DNSSEC', and status takes active or disabled. Disabling DNSSEC while the registrar still publishes the zone's DS record makes every validating resolver refuse the WHOLE domain - the DS record has to be removed at the registrar first. dnssec_presigned and dnssec_multi_signer also change how the zone is signed for everyone who validates it. The summary-verb arm reads the vendor's summary, which here is the neutral 'Edit DNSSEC Status', so the derived verdict never saw the disable. Enabling returns the DS record to publish at the registrar; nothing validates until it is there. PATCH /zones//dnssec. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Secondary DNS
cf_create_secondary_dns_acl details
cf_create_secondary_dns_acl details
[Cloudflare] Create ACL. Additive: it widens what the account accepts transfer traffic from and narrows nothing. The range applies to the ENTIRE account, not to one zone. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. POST /accounts//secondary_dns/acls. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_secondary_dns_peer details
cf_create_secondary_dns_peer details
[Cloudflare] Create Peer. Additive: it registers one more peer on the account. Only name is required, so the peer arrives without an address and transfers nothing until cf_set_secondary_dns_peer fills in ip, port and any tsig_id. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. POST /accounts//secondary_dns/peers. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_secondary_dns_tsig details
cf_create_secondary_dns_tsig details
[Cloudflare] Create TSIG. Additive: it stores one more TSIG key on the account and rebinds no peer - a transfer only starts using it once cf_set_secondary_dns_peer names its id as tsig_id. The secret you send IS the shared secret, and the response echoes it back. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. POST /accounts//secondary_dns/tsigs. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_secondary_dns_force_axfr details
cf_create_zones_secondary_dns_force_axfr details
[Cloudflare] DESTRUCTIVE: Force AXFR. Why this is destructive: It dispatches a full AXFR to the zone's primary nameservers right now, and Cloudflare replaces its copy of the zone with whatever the primary answers - every record in the zone, at once. A primary serving a truncated or wrong zone at that moment becomes what the internet sees within the TTL. It also bypasses the auto_refresh_seconds schedule, so it is the call that turns a primary-side mistake into a live one immediately. Cloudflare answers with the ordinary JSON envelope and performs the transfer asynchronously, so read the zone's records or cf_get_zones_secondary_dns_incomings afterwards to see what arrived. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/force_axfr. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_secondary_dns_incoming details
cf_create_zones_secondary_dns_incoming details
[Cloudflare] Create Secondary Zone Configuration. Additive for this zone: it registers the incoming transfer configuration and names the peers Cloudflare will pull from. Once it exists the zone's contents come from the primary nameserver over AXFR/IXFR rather than from records edited at Cloudflare. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/incoming. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_secondary_dns_outgoing details
cf_create_zones_secondary_dns_outgoing details
[Cloudflare] Create Primary Zone Configuration. Additive for this zone: it registers the outgoing transfer configuration naming the secondaries Cloudflare will serve. Creating the configuration and switching transfers on are separate calls here - cf_enable_zones_secondary_dns_outgoing is the switch. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/outgoing. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_secondary_dns_outgoing_force_notify details
cf_create_zones_secondary_dns_outgoing_force_notify details
[Cloudflare] DESTRUCTIVE: Force DNS NOTIFY. Why this is destructive: Cloudflare's own description is 'Notifies the secondary nameserver(s) and clears IXFR backlog of primary zone'. Clearing the backlog is the destructive half: the incremental history the secondaries would have used is discarded, so each one has to pull the whole zone again, and a secondary that cannot complete a full AXFR keeps serving its old copy. The NOTIFY itself reaches the customer's own nameservers immediately. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/outgoing/force_notify. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_secondary_dns_acl details
cf_delete_secondary_dns_acl details
[Cloudflare] DESTRUCTIVE: Delete ACL. Why this is destructive: The account stops accepting zone-transfer traffic from that IP range. Every secondary zone relying on it for NOTIFY, and every primary zone relying on it to permit AXFR/IXFR, stops transferring - and because a stalled transfer keeps serving the last copy, the symptom is a zone that silently goes stale rather than an error. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. DELETE /accounts//secondary_dns/acls/. Path parameters: acl_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_secondary_dns_peer details
cf_delete_secondary_dns_peer details
[Cloudflare] DESTRUCTIVE: Delete Peer. Why this is destructive: The peer is removed from the account and every zone whose peers array names it loses that transfer relationship: a secondary zone stops pulling from that primary, and a primary zone stops notifying that secondary. The zones keep serving the records they last had, so the failure shows up as stale data rather than an error. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. DELETE /accounts//secondary_dns/peers/. Path parameters: peer_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_secondary_dns_tsig details
cf_delete_secondary_dns_tsig details
[Cloudflare] DESTRUCTIVE: Delete TSIG. Why this is destructive: The shared secret is removed from the account. Any peer still naming this key as its tsig_id can no longer authenticate a transfer, so the zones behind it stop transferring and quietly go stale. Cloudflare never returns a deleted secret again, so a key removed by mistake has to be regenerated and reconfigured on BOTH sides. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. DELETE /accounts//secondary_dns/tsigs/. Path parameters: tsig_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_secondary_dns_incoming details
cf_delete_zones_secondary_dns_incoming details
[Cloudflare] DESTRUCTIVE: Delete Secondary Zone Configuration. Why this is destructive: The zone stops being a secondary: Cloudflare no longer pulls from the primary, the peers list goes and the refresh schedule with it. The records already transferred stay, so the visible symptom is a zone frozen at its last transfer rather than a zone that disappears. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. DELETE /zones//secondary_dns/incoming. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_secondary_dns_outgoing details
cf_delete_zones_secondary_dns_outgoing details
[Cloudflare] DESTRUCTIVE: Delete Primary Zone Configuration. Why this is destructive: The zone stops being a transfer source: every secondary loses its NOTIFY and its permission to pull, and each one keeps serving the copy it already holds. Because those secondaries usually answer for the domain alongside Cloudflare, the internet keeps getting the stale copy rather than an error. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. DELETE /zones//secondary_dns/outgoing. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_disable_zones_secondary_dns_outgoing details
cf_disable_zones_secondary_dns_outgoing details
[Cloudflare] DESTRUCTIVE: Disable Outgoing Zone Transfers. Why this is destructive: Cloudflare's own description is 'Disable outgoing zone transfers for primary zone and clears IXFR backlog of primary zone'. Two things happen: the secondaries stop being served, and the IXFR backlog is discarded - so when transfers are enabled again the secondaries cannot pick up incrementally and need a full AXFR. Until they manage one, each keeps answering from the copy it already holds. cf_enable_zones_secondary_dns_outgoing turns it back on; the configuration and its peers are left alone by both. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/outgoing/disable. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_enable_zones_secondary_dns_outgoing details
cf_enable_zones_secondary_dns_outgoing details
[Cloudflare] Enable Outgoing Zone Transfers. Turns outgoing zone transfers back on for the zone. It is the reverse of cf_disable_zones_secondary_dns_outgoing and adds nothing to the configuration - the peers the zone already names start being notified and allowed to transfer again. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. POST /zones//secondary_dns/outgoing/enable. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_secondary_dns_acl details
cf_get_secondary_dns_acl details
[Cloudflare] ACL Details. Reads one ACL's name and ip_range. Worth doing before cf_set_secondary_dns_acl, which replaces the whole entry. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/acls/. Path parameters: acl_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_secondary_dns_peer details
cf_get_secondary_dns_peer details
[Cloudflare] Peer Details. Reads one peer's address, port, IXFR setting and the TSIG key id bound to it. Read it before cf_set_secondary_dns_peer, which replaces the peer wholesale. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/peers/. Path parameters: peer_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_secondary_dns_tsig details
cf_get_secondary_dns_tsig details
[Cloudflare] TSIG Details. Reads one TSIG key. The response includes the secret in full, so treat the result as credential material and do not persist it. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/tsigs/. Path parameters: tsig_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_secondary_dns_incomings details
cf_get_zones_secondary_dns_incomings details
[Cloudflare] Secondary Zone Configuration Details. The INCOMING side: this zone as a SECONDARY that Cloudflare pulls from the customer's own primary nameservers. Returns the zone's auto_refresh_seconds and the peer tags it transfers from. cf_get_zones_secondary_dns_outgoing_config is the other direction. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Read or DNS Read on this zone. GET /zones//secondary_dns/incoming. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_secondary_dns_outgoing_config details
cf_get_zones_secondary_dns_outgoing_config details
[Cloudflare] Primary Zone Configuration Details. The OUTGOING side: this zone as a PRIMARY that Cloudflare transfers out to the customer's own secondary nameservers. Returns the zone name and the peer tags Cloudflare NOTIFYs and answers AXFR/IXFR for. Mind the near-identical sibling - cf_get_zones_secondary_dns_outgoing_status, singular, reads the transfer STATUS at /outgoing/status, while this one reads the CONFIGURATION at /outgoing. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Read or DNS Read on this zone. GET /zones//secondary_dns/outgoing. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_secondary_dns_outgoing_status details
cf_get_zones_secondary_dns_outgoing_status details
[Cloudflare] Get Outgoing Zone Transfer Status. The transfer STATUS for this zone as a primary - not its configuration. Cloudflare serves it at /outgoing/status, while cf_get_zones_secondary_dns_outgoing_config (plural) serves the configuration at /outgoing; the two tool names differ by one character, so check which one you want. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Read or DNS Read on this zone. GET /zones//secondary_dns/outgoing/status. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_secondary_dns_acls details
cf_list_secondary_dns_acls details
[Cloudflare] List ACLs. A Secondary DNS ACL is an account-wide IP range Cloudflare will accept zone-transfer traffic from: the extra NOTIFY sources allowed for secondary zones, and the addresses AXFR/IXFR requests may arrive from for primary zones. Start here - each entry's id is what the get, update and delete tools take. Cloudflare paginates nothing here: the whole collection comes back in one response. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/acls. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_secondary_dns_peers details
cf_list_secondary_dns_peers details
[Cloudflare] List Peers. A Secondary DNS peer is the other nameserver in a transfer relationship: for a zone Cloudflare is SECONDARY for, the peer is the customer's primary that Cloudflare pulls AXFR/IXFR from; for a zone Cloudflare is PRIMARY for, it is the secondary Cloudflare NOTIFYs. Start here - each peer's id is the tag that goes into a zone's peers array. Cloudflare paginates nothing here: the whole collection comes back in one response. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/peers. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_secondary_dns_tsigs details
cf_list_secondary_dns_tsigs details
[Cloudflare] List TSIGs. A TSIG key is the shared secret that authenticates a zone transfer between Cloudflare and a peer. Start here - each entry's id is what cf_set_secondary_dns_peer takes as tsig_id. Every entry includes its secret in full, so treat the result as credential material and do not persist it. Cloudflare paginates nothing here: the whole collection comes back in one response. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Read permission group rather than DNS - a DNS-scoped token gets a 403 here. GET /accounts//secondary_dns/tsigs. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_secondary_dns_acl details
cf_set_secondary_dns_acl details
[Cloudflare] DESTRUCTIVE: Update ACL. Why this is destructive: A PUT replaces the ACL outright and Cloudflare requires id, name and ip_range together, so every call rewrites the allowed range for the whole account. Narrowing or mistyping ip_range stops zone transfers from the addresses it used to permit, and those zones go stale rather than failing loudly. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. PUT /accounts//secondary_dns/acls/. Path parameters: acl_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_secondary_dns_peer details
cf_set_secondary_dns_peer details
[Cloudflare] DESTRUCTIVE: Update Peer. Why this is destructive: A PUT replaces the peer from the body and Cloudflare requires only id and name, so leaving ip, port, ixfr_enable or tsig_id out CLEARS them. Dropping tsig_id is the one that bites: the transfer stops being TSIG-authenticated. Dropping ip leaves a peer that cannot transfer at all. Read cf_get_secondary_dns_peer first and send every field back. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. PUT /accounts//secondary_dns/peers/. Path parameters: peer_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_secondary_dns_tsig details
cf_set_secondary_dns_tsig details
[Cloudflare] DESTRUCTIVE: Update TSIG. Why this is destructive: A PUT replaces the TSIG key and Cloudflare requires id, name, secret and algo together, so every call rewrites the shared secret. The moment it changes, every peer still configured with the old secret fails authentication and stops transferring - change it on the peer nameserver in the same maintenance window. The response echoes the new secret back. Secondary DNS is Enterprise-only, and this account-level call sits under the Account Settings Write permission group rather than DNS - a DNS-scoped token gets a 403 here. PUT /accounts//secondary_dns/tsigs/. Path parameters: tsig_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_secondary_dns_incoming details
cf_set_zones_secondary_dns_incoming details
[Cloudflare] DESTRUCTIVE: Update Secondary Zone Configuration. Why this is destructive: A PUT rewrites the zone's whole incoming transfer configuration, and peers is an ARRAY - a peer left out of it stops being a source for this zone. Drop them all and the zone stops refreshing entirely: it keeps serving the records it last pulled and silently goes stale rather than failing. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. PUT /zones//secondary_dns/incoming. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_secondary_dns_outgoing details
cf_set_zones_secondary_dns_outgoing details
[Cloudflare] DESTRUCTIVE: Update Primary Zone Configuration. Why this is destructive: A PUT rewrites the zone's whole outgoing transfer configuration, and peers is an ARRAY - a secondary left out of it stops being notified and stops being allowed to transfer, so it freezes at the copy it already holds while the zone keeps changing at Cloudflare. Since those secondaries usually answer for the domain alongside Cloudflare, the internet keeps getting the stale copy. Secondary DNS is Enterprise-only, and the API token needs Zone Settings Write plus DNS Write on this zone. PUT /zones//secondary_dns/outgoing. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Account Analytics
cf_get_user_analytics_dashboards details
cf_get_user_analytics_dashboards details
[Cloudflare] Get user analytics dashboard. Cloudflare's named replacement is the GraphQL Analytics API (developers.cloudflare.com/analytics/graphql-api), which is where new work should go. Totals and time series aggregated across EVERY zone the token owner owns rather than one account, and only zones the user can read analytics for are counted. Omit since and until for the last seven days. GET /user/analytics/dashboard. Optional filters: since, until, continuous. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
Account Billable
cf_get_account_billable_usage details
cf_get_account_billable_usage details
[Cloudflare] Get Account Usage (Version 2, Alpha, Restricted). Cost and usage for ONE account in the FinOps FOCUS v1.3 shape: one record per billable metric per account per day, including metered usage that falls inside a free allowance and costs nothing. Cloudflare has NOT yet populated the cost and pricing fields, so they are absent from the response until its billing integration lands. Omit from and to for the current month to date; the widest range Cloudflare accepts is 31 days. The surface is Alpha and restricted, so an account that has not been enabled for it is refused. Use cf_query_account_billable_usage to filter or group the same data. GET /accounts//billable/usage. Path parameters: account_id. Optional filters: from, to. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_query_account_billable_usage details
cf_query_account_billable_usage details
[Cloudflare] Query Account Usage (Version 2, Alpha, Restricted). The filterable counterpart of cf_get_account_billable_usage on the same path. Cloudflare documents it as a READ-ONLY operation that needs only the billing:read permission - POST is used purely so the filter criteria can travel in a body - which is why StackJack ships it as a read. POST /accounts//billable/usage. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Account Firewall
cf_create_user_firewall_access_rule details
cf_create_user_firewall_access_rule details
[Cloudflare] DESTRUCTIVE: Create an IP Access rule. Why this is destructive: The rule takes effect on EVERY zone the token owner owns, immediately. A block or challenge rule aimed at the wrong address can shut real visitors - or the customer's own office - out of all of those domains at once, and a zone-level rule is the narrower tool when only one domain is meant. POST /user/firewall/access_rules/rules. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_user_firewall_access_rule details
cf_delete_user_firewall_access_rule details
[Cloudflare] DESTRUCTIVE: Delete an IP Access rule. Why this is destructive: Removing a user-level rule lifts it from EVERY zone the token owner owns at once, so traffic the rule was blocking or challenging is served normally from the next request. Cloudflare keeps no copy - restoring it means creating it again. DELETE /user/firewall/access_rules/rules/. Path parameters: rule_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_user_firewall_access_rule details
cf_get_user_firewall_access_rule details
[Cloudflare] Get an IP Access rule. One user-level rule by id: the action it applies, what it matches and its notes. This is a USER-SCOPE endpoint: it answers for the token owner's own Cloudflare user, not for one account, and a token created under Manage Account cannot call it. GET /user/firewall/access_rules/rules/. Path parameters: rule_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_user_firewall_access_rules details
cf_list_user_firewall_access_rules details
[Cloudflare] List IP Access rules. USER-LEVEL IP Access rules, which is what makes this surface different from a zone's own firewall: one rule here applies to EVERY zone the token owner owns. Start here - the rule id the get, update and delete tools take comes from these rows. Each rule pairs a mode (the action) with a configuration (what it matches: an IP, a CIDR range, an AS number or a country code). This is a USER-SCOPE endpoint: it answers for the token owner's own Cloudflare user, not for one account, and a token created under Manage Account cannot call it. GET /user/firewall/access_rules/rules. Optional filters: mode, configuration.target, configuration.value, notes, match, page, per_page, order, direction. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_user_firewall_access_rule details
cf_update_user_firewall_access_rule details
[Cloudflare] DESTRUCTIVE: Update an IP Access rule. Why this is destructive: Cloudflare accepts only two changes here - the action (mode) and the notes - and the new action applies to every zone the token owner owns from the next request. PATCH /user/firewall/access_rules/rules/. Path parameters: rule_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Account Load Balancers
cf_create_user_lb_monitor details
cf_create_user_lb_monitor details
[Cloudflare] Create Monitor. Additive: it creates one new health check and changes no pool. Nothing is probed until a pool references the monitor, but from that moment the check runs against that pool's origins on the interval you set. POST /user/load_balancers/monitors. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_user_lb_pool details
cf_create_user_lb_pool details
[Cloudflare] Create Pool. Additive: it creates one new pool and changes no existing one. No traffic reaches it until a load balancer references the pool, but its health checks begin as soon as it exists. POST /user/load_balancers/pools. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_user_lb_monitor details
cf_delete_user_lb_monitor details
[Cloudflare] DESTRUCTIVE: Delete Monitor. Why this is destructive: Any pool still pointing at this monitor loses its health check, so those origins stop being probed and stay at their last known state. Call cf_list_user_lb_monitors_references first to see what depends on it. DELETE /user/load_balancers/monitors/. Path parameters: monitor_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_user_lb_pool details
cf_delete_user_lb_pool details
[Cloudflare] DESTRUCTIVE: Delete Pool. Why this is destructive: Any load balancer still steering to this pool loses those origins, so traffic fails over to its remaining pools - or to nothing, if this was the last one. Call cf_list_user_lb_pools_references first to see what depends on it. DELETE /user/load_balancers/pools/. Path parameters: pool_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_user_lb_monitor details
cf_get_user_lb_monitor details
[Cloudflare] Monitor Details. One user-scope monitor by id, with the probe type, target and timing that decide when an origin counts as down. These are USER-SCOPE load balancing objects, owned by the token owner rather than by one account; the account-scope equivalents are cf_list_lb_monitors and cf_list_lb_pools. GET /user/load_balancers/monitors/. Path parameters: monitor_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_user_lb_pool details
cf_get_user_lb_pool details
[Cloudflare] Pool Details. One user-scope pool by id, with its origins, the monitor that probes them and the address alerted when its health changes. These are USER-SCOPE load balancing objects, owned by the token owner rather than by one account; the account-scope equivalents are cf_list_lb_monitors and cf_list_lb_pools. GET /user/load_balancers/pools/. Path parameters: pool_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_user_lb_pool_health details
cf_get_user_lb_pool_health details
[Cloudflare] Pool Health Details. The latest health of ONE pool: the per-origin and per-region results of the pool's monitor. This is the read that answers "why is traffic failing over?". GET /user/load_balancers/pools//health. Path parameters: pool_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_user_lb_preview details
cf_get_user_lb_preview details
[Cloudflare] Preview Result. Collects the result of a preview started by cf_preview_user_lb_monitors or cf_preview_user_lb_pools, using the preview_id that call returned. The probes run asynchronously, so an immediate read can come back incomplete. GET /user/load_balancers/preview/. Path parameters: preview_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_user_lb_regions details
cf_get_user_lb_regions details
[Cloudflare] List Regions. The region map Cloudflare steers load balancing by - which countries and subdivisions sit in which region code (WNAM, ENAM, WEU, SEAS and the rest). It is reference data, the same for every customer, and it is what a pool's check_regions and a load balancer's region rules expect. Filter by country_code or subdivision_code to find the region one place belongs to. GET /user/load_balancers/regions. Optional filters: subdivision_code, country_code. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_user_lb_monitors details
cf_list_user_lb_monitors details
[Cloudflare] List Monitors. Start here for user-scope load balancing: a monitor is the health check a pool runs against its origins, and each row's id is the monitor_id every other monitor tool takes. These are USER-SCOPE load balancing objects, owned by the token owner rather than by one account; the account-scope equivalents are cf_list_lb_monitors and cf_list_lb_pools. This endpoint takes no paging parameters - the whole collection comes back in one response. GET /user/load_balancers/monitors. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_user_lb_monitors_references details
cf_list_user_lb_monitors_references details
[Cloudflare] List Monitor References. Everything that points at this monitor - the pools whose health checking would change if you edited or deleted it. Call it before either. GET /user/load_balancers/monitors//references. Path parameters: monitor_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_user_lb_pools details
cf_list_user_lb_pools details
[Cloudflare] List Pools. Start here for user-scope pools: a pool is a named set of origins with a health check, and each row's id is the pool_id the other pool tools take. These are USER-SCOPE load balancing objects, owned by the token owner rather than by one account; the account-scope equivalents are cf_list_lb_monitors and cf_list_lb_pools. Filter by monitor to find the pools one health check governs. This endpoint takes no paging parameters - the whole collection comes back in one response. GET /user/load_balancers/pools. Optional filters: monitor. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_user_lb_pools_references details
cf_list_user_lb_pools_references details
[Cloudflare] List Pool References. Everything that points at this pool - the load balancers whose steering would change if you edited or deleted it. Call it before either. GET /user/load_balancers/pools//references. Path parameters: pool_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_preview_user_lb_monitors details
cf_preview_user_lb_monitors details
[Cloudflare] Preview Monitor. A simulation, not a change: Cloudflare runs the monitor settings in the body against the pools that use this monitor and hands back a preview_id. Nothing about the monitor or its pools is modified, which is why this POST ships as a read. Pass the preview_id to cf_get_user_lb_preview to collect the result. POST /user/load_balancers/monitors//preview. Path parameters: monitor_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_preview_user_lb_pools details
cf_preview_user_lb_pools details
[Cloudflare] Preview Pool. A simulation, not a change: Cloudflare probes this pool's origins with the monitor settings in the body and hands back a preview_id, leaving the pool and its real monitor untouched - which is why this POST ships as a read. Pass the preview_id to cf_get_user_lb_preview. POST /user/load_balancers/pools//preview. Path parameters: pool_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_user_lb_monitor details
cf_set_user_lb_monitor details
[Cloudflare] DESTRUCTIVE: Update Monitor. Why this is destructive: A PUT replaces the whole monitor from the body, so any field you leave out reverts to Cloudflare's default rather than keeping its current value - an omitted expected_codes or interval can silently change when the pools using this monitor call an origin down. Read cf_get_user_lb_monitor first and send the complete object, or use cf_update_user_lb_monitor to change one field. PUT /user/load_balancers/monitors/. Path parameters: monitor_id. Send the request body as JSON; Cloudflare documents these fields: allow_insecure, consecutive_down, consecutive_up, description, expected_body, expected_codes, follow_redirects, header, interval, method, path, port. Cloudflare documents 4 more fields; see its API docs. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_user_lb_pool details
cf_set_user_lb_pool details
[Cloudflare] DESTRUCTIVE: Update Pool. Why this is destructive: A PUT replaces the whole pool from the body: an origin you leave out of origins is REMOVED from the pool and stops receiving traffic, and every omitted setting reverts to its default. Read cf_get_user_lb_pool first and send the complete object, or use cf_update_user_lb_pool_by_pool_id for one field. PUT /user/load_balancers/pools/. Path parameters: pool_id. Send the request body as JSON; Cloudflare documents these fields: check_regions, description, disabled_at, enabled, health_sources, latitude, load_shedding, longitude, minimum_origins, monitor, monitor_group, name. Cloudflare documents 5 more fields; see its API docs. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_user_lb_monitor details
cf_update_user_lb_monitor details
[Cloudflare] Patch Monitor. Partial update: Cloudflare applies only the fields you send and leaves the rest alone. The new probe settings are live on the next interval for every pool that references this monitor. PATCH /user/load_balancers/monitors/. Path parameters: monitor_id. Send the request body as JSON; Cloudflare documents these fields: allow_insecure, consecutive_down, consecutive_up, description, expected_body, expected_codes, follow_redirects, header, interval, method, path, port. Cloudflare documents 4 more fields; see its API docs. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_user_lb_pool_by_pool_id details
cf_update_user_lb_pool_by_pool_id details
[Cloudflare] DESTRUCTIVE: Patch Pool. Why this is destructive: Partial update of ONE pool, but origins is a list: sending it at all REPLACES the whole origin list rather than merging into it, so an origin you leave out stops receiving traffic immediately. Read cf_get_user_lb_pool first and send the complete list. PATCH /user/load_balancers/pools/. Path parameters: pool_id. Send the request body as JSON; Cloudflare documents these fields: check_regions, description, disabled_at, enabled, health_sources, latitude, load_shedding, longitude, minimum_origins, monitor, monitor_group, name. Cloudflare documents 4 more fields; see its API docs. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_user_lb_pools details
cf_update_user_lb_pools details
[Cloudflare] Patch Pools. This is the BATCH form and it carries no pool id: Cloudflare applies the body to EVERY pool the token owner owns and answers with the list it changed. Sending notification_email here rewrites who is alerted for all of them; cf_update_user_lb_pool_by_pool_id is the one-pool tool. PATCH /user/load_balancers/pools. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Account Members
cf_add_account_member details
cf_add_account_member details
[Cloudflare] DESTRUCTIVE: Add Member. Why this is destructive: Grants a person access to the account with the roles you name. Cloudflare accepts one of TWO body shapes here and refuses a body that satisfies both: send email plus roles (a list of role ids from cf_list_account_roles), or email plus policies. Pick one and omit the other. status is optional and defaults to pending, which sends the invitation. POST /accounts//members. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: email, roles, status, policies. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_account_member details
cf_get_account_member details
[Cloudflare] Member Details. GET /accounts//members/. Path parameters: member_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_account_members details
cf_list_account_members details
[Cloudflare] List Members. Who can reach this Cloudflare account and with which roles. The member id this returns is what the update and remove tools take, and it is NOT the user id. GET /accounts//members. Path parameters: account_id. Optional filters: order, status, page, per_page, direction. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_remove_account_member details
cf_remove_account_member details
[Cloudflare] DESTRUCTIVE: Remove Member. Why this is destructive: Removes the person from the account. DELETE /accounts//members/. Path parameters: member_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_account_member details
cf_update_account_member details
[Cloudflare] DESTRUCTIVE: Update Member. Why this is destructive: Replaces the member role list wholesale, so this both grants and revokes privilege. Two body shapes, as on the add: send roles for a role-based member, or policies for a policy-based one, never both. This is a wholesale replace either way - whatever you send becomes the complete list, so read cf_get_account_member first and send the full set you want the member to end up with. PUT /accounts//members/. Path parameters: member_id, account_id. Send the request body as JSON; Cloudflare documents these fields: id, roles, status, user, policies. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Account Memberships
cf_get_user_membership details
cf_get_user_membership details
[Cloudflare] Get User Membership. One membership of the token owner - the link between this user and an account, with the roles it carries and whether the invitation is accepted or still pending. This is a USER-SCOPE endpoint: it answers for the token owner's own Cloudflare user, not for one account, and a token created under Manage Account cannot call it. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Memberships Write or Memberships Read permission rather than that the call is unsupported. GET /user/memberships/. Path parameters: membership_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Account Organizations
cf_delete_user_organization details
cf_delete_user_organization details
[Cloudflare] DESTRUCTIVE: Leave Organization. Why this is destructive: This is LEAVE ORGANIZATION: the token owner's own membership is removed, so that user loses everything the organization granted them and only an administrator who is still a member can invite them back. It does not delete the organization itself. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. DELETE /user/organizations/. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_get_user_organization details
cf_get_user_organization details
[Cloudflare] Organization Details. One organization the token owner belongs to, with the membership status and permissions it carries. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /user/organizations/. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_list_user_organizations details
cf_list_user_organizations details
[Cloudflare] List Organizations. Organizations are Cloudflare's older Enterprise-only account grouping; accounts are the current model, so cf_list_accounts is almost always the read you want. Cloudflare caps per_page at 50 here and StackJack clamps to that ceiling. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Memberships Write or Memberships Read permission rather than that the call is unsupported. GET /user/organizations. Optional filters: name, page, per_page, order, direction, match, status. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
Account Profile
cf_get_profiles details
cf_get_profiles details
[Cloudflare] Get account profile. The account's business profile - legal name, business address, business email and phone, plus the organization metadata Cloudflare holds against the account. It is also the cheapest read for confirming the token really reaches the account you think it does. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Trust and Safety Write or Trust and Safety Read or DNS View Write or DNS View Read or SCIM Provisioning or Load Balancers Account Write or Load Balancers Account Read or Zero Trust: PII Read or DDoS Botnet Feed Write or DDoS Botnet Feed Read or Workers R2 Storage Write or Workers R2 Storage Read or DDoS Protection Write or DDoS Protection Read or Workers Tail Read or Workers KV Storage Write or Workers KV Storage Read or Workers Scripts Write or Workers Scripts Read or Load Balancing: Monitors and Pools Write or Load Balancing: Monitors and Pools Read or Account Firewall Access Rules Write or Account Firewall Access Rules Read or DNS Firewall Write or DNS Firewall Read or Billing Write or Billing Read or Account Settings Write or Account Settings Read permission rather than that the call is unsupported. GET /accounts//profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_profile details
cf_set_profile details
[Cloudflare] DESTRUCTIVE: Modify account profile. Why this is destructive: A PUT replaces the whole profile and Cloudflare requires ALL of business_address, business_email, business_name, business_phone and external_metadata in the body, so anything you omit is not kept. The business email is where Cloudflare sends this account's correspondence, so a wrong value here sends the customer's account mail somewhere else. Read cf_get_profiles first and send every value back. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Account Settings Write permission rather than that the call is unsupported. PUT /accounts//profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Account Settings
cf_get_settings_ut_billings details
cf_get_settings_ut_billings details
[Cloudflare] Get Unique Transformations billing setting. Whether this account's image transformations are billed through the Unique Transformations pipeline. Read it before cf_update_settings_ut_billing, because that switch is one-way. GET /accounts//settings/ut-billing. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_settings_transformations details
cf_list_settings_transformations details
[Cloudflare] List Image Resizing configurations for account. The Image Resizing (transformations) state of EVERY zone in the account in one response, which is the quick way to find the zones where it is switched on. Changing it for one zone is a zone-settings call, not this one. GET /accounts//settings/transformations. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_settings_ut_billing details
cf_update_settings_ut_billing details
[Cloudflare] DESTRUCTIVE: Change Unique Transformations billing setting. Why this is destructive: It changes how Cloudflare BILLS this account for image transformations, and Cloudflare does not permit the value to be set back to off once it has been enabled - so switching it on is a one-way change to the customer's invoice. Confirm the customer wants the Unique Transformations pricing model before sending it. PATCH /accounts//settings/ut-billing. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Account Tokens
cf_create_user_token details
cf_create_user_token details
[Cloudflare] DESTRUCTIVE: Create Token. Why this is destructive: It mints a live Cloudflare API credential that can act on everything its policies allow, from the moment it is created until it expires or is deleted. The value comes back exactly once - treat the response as a secret and keep it out of anything durable. The response carries the new token VALUE once and Cloudflare never shows it again, so capture it at that moment or roll the token later. Build policies from the permission group ids cf_list_user_tokens_permission_groups returns. POST /user/tokens. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_user_token details
cf_delete_user_token details
[Cloudflare] DESTRUCTIVE: Delete Token. Why this is destructive: The token stops authenticating immediately, so anything still using it - a script, a CI job, another integration - starts failing with 401 at once. Cloudflare cannot restore a deleted token; a replacement is a new token with a new value. DELETE /user/tokens/. Path parameters: token_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_user_token details
cf_get_user_token details
[Cloudflare] Token Details. One token's policies, status, expiry and last-used time by id. It never returns the token value - Cloudflare shows that only when the token is created or rolled. GET /user/tokens/. Path parameters: token_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_user_tokens details
cf_list_user_tokens details
[Cloudflare] List Tokens. The API tokens the token owner created, with their policies, status and expiry but never the token value itself. Each row's id is the token_id the get, update, roll and delete tools take. Set include_expired to include recently-expired tokens. Cloudflare caps per_page at 50 here and StackJack clamps to that ceiling. This is a USER-SCOPE endpoint: it answers for the token owner's own Cloudflare user, not for one account, and a token created under Manage Account cannot call it. GET /user/tokens. Optional filters: page, per_page, direction, include_expired. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_user_tokens_permission_groups details
cf_list_user_tokens_permission_groups details
[Cloudflare] List Token Permission Groups. The catalog of permission groups a token policy can name - the id, name and scope of each. This is the read you make BEFORE cf_create_user_token, because a policy has to carry these ids. It returns names and identifiers only, never key material. GET /user/tokens/permission_groups. Optional filters: name, scope. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_roll_user_token details
cf_roll_user_token details
[Cloudflare] DESTRUCTIVE: Roll Token. Why this is destructive: Rolling replaces the token's secret: the OLD value stops authenticating the moment Cloudflare answers, so every script, pipeline or integration still holding it fails with 401 until it is given the new value. That new value appears only in this response. The response body IS the new secret: result is the token string itself, and Cloudflare will never show it again. Capture it, store it, and update whatever was using the old value. PUT /user/tokens//value. Path parameters: token_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_user_token details
cf_set_user_token details
[Cloudflare] DESTRUCTIVE: Update Token. Why this is destructive: A PUT replaces the token's whole definition, and policies is the part that bites: the array you send BECOMES what the token may do, so a policy left out is revoked the moment Cloudflare accepts the call and anything relying on it starts failing. Read cf_get_user_token first and send the complete set. Setting status to disabled switches the credential off without deleting it. PUT /user/tokens/. Path parameters: token_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Account Zones
cf_get_zones_v1_images_flows details
cf_get_zones_v1_images_flows details
[Cloudflare] Get transformation flows. The zone's image transformation flows - the named pipelines that decide which resizing and format transformations are allowed. Read it before writing: the write is a whole-document replace and it needs the version and etag this returns. GET /accounts//zones//v1/images/flows. Path parameters: accountId, zoneId. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_v1_images_flow details
cf_set_zones_v1_images_flow details
[Cloudflare] DESTRUCTIVE: Update transformation flows. Why this is destructive: It replaces the zone's ENTIRE transformation flow configuration: a flow you leave out of the body is deleted, and image URLs that relied on it stop transforming. Read cf_get_zones_v1_images_flows first and send the full document back with your change, using the etag it returned so a concurrent edit by someone else is refused rather than overwritten. PUT /accounts//zones//v1/images/flows. Path parameters: accountId, zoneId. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Accounts
cf_create_account details
cf_create_account details
[Cloudflare] DESTRUCTIVE: Create an account. Why this is destructive: Provisions a new billable Cloudflare account under the partner tenant. POST /accounts. Send the request body as JSON; Cloudflare documents these fields: name, type, unit. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_account details
cf_delete_account details
[Cloudflare] DESTRUCTIVE: Delete a specific account. Why this is destructive: Deletes the whole account and everything in it. DELETE /accounts/. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_account details
cf_get_account details
[Cloudflare] Account Details. GET /accounts/. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_accounts details
cf_list_accounts details
[Cloudflare] List Accounts. Start here: this is how an agent learns which Cloudflare accounts the stored API token can see, and the id each of the account-scoped tools needs. A token scoped to one account returns exactly that one. GET /accounts. Optional filters: name, page, per_page, direction. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_account details
cf_update_account details
[Cloudflare] DESTRUCTIVE: Update Account. Why this is destructive: Wholesale replace: the account settings block is rewritten from the body, so an omitted setting reverts to its default. PUT /accounts/. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: created_on, id, managed_by, name, settings, type. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Activation Check
cf_set_zones_activation_check details
cf_set_zones_activation_check details
[Cloudflare] DESTRUCTIVE: Rerun the Activation Check. Why this is destructive: It re-runs Cloudflare's own nameserver check against a PENDING zone, and a zone that passes goes active - which is the moment Cloudflare starts serving the domain, with whatever configuration is on the zone at that time. It changes nothing you authored and can be repeated, but Cloudflare rate-limits it to once every five minutes on paid zones and once an hour on Free ones. Only useful on a zone whose status is still pending: read cf_get_zone first. If the customer's registrar has not yet been pointed at the Cloudflare nameservers the check simply fails again. PUT /zones//activation_check. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Address Validation
cf_create_address_validation details
cf_create_address_validation details
[Cloudflare] Validate Billing Address. A validation lookup, not a change: Cloudflare checks the address in the body against its address provider and answers with corrected suggestions, storing nothing - which is why this POST ships as a read. Cloudflare does not enforce authentication on it, so it also works before an account exists. Use it to clean an address before sending it to cf_create_billing_profile. POST /billing/address-validation. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
API Tokens
cf_verify_account_token details
cf_verify_account_token details
[Cloudflare] Verify Token. The account-owned equivalent of the personal token check. Use it when the token was created under Manage Account rather than My Profile; a personal token is refused here. GET /accounts//tokens/verify. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_verify_user_token details
cf_verify_user_token details
[Cloudflare] Verify Token. The cheapest way to answer "is this credential alive?" for a personal token. It reports the token status and, when one was set, its expiry. An ACCOUNT-OWNED token is refused here: use the account-scoped verify instead. GET /user/tokens/verify. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Audit Logs
cf_list_audit_logs details
cf_list_audit_logs details
[Cloudflare] Get account audit logs. Who changed what on this account and when - the first read for "why did this break?". Filter by actor.email or actor.ip for one person, by action.type for one kind of change, by zone.name for one domain, and by since/before for the window. hide_user_logs drops user-level entries. Cloudflare accepts up to 1000 entries a page here. GET /accounts//audit_logs. Path parameters: account_id. Optional filters: id, export, action.type, actor.ip, actor.email, since, before, zone.name, direction, per_page, page, hide_user_logs. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_user_audit_logs details
cf_list_user_audit_logs details
[Cloudflare] Get user audit logs. The same audit feed as cf_list_audit_logs, but for the TOKEN OWNER's own user rather than an account: it covers the user's actions across every account they belong to. Use the account-scoped tool when you are investigating one customer account. GET /user/audit_logs. Optional filters: id, export, action.type, actor.ip, actor.email, since, before, zone.name, direction, per_page, page, hide_user_logs. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Billable Usage
cf_get_billable_usage_info details
cf_get_billable_usage_info details
[Cloudflare] Get Account Billable Usage Info (Version 1, Alpha). The header facts behind the usage feed: which period is covered, how complete the data is and the subscription metadata it is measured against. Read it first to learn whether cf_list_billable_usages will answer for the window you care about. GET /accounts//billable-usage/info. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_billable_usages details
cf_list_billable_usages details
[Cloudflare] Get Account Billable Usage (Version 1, Alpha). Version 1 of the billable-usage feed, which Cloudflare marks Alpha. With no from/to it returns the CURRENT billing period. cf_get_account_billable_usage is the newer FOCUS v1.3 dataset on a different path; read both before trusting either for an invoice reconciliation. GET /accounts//billable-usage. Path parameters: account_id. Optional filters: from, to. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Billing
cf_create_billing_profile details
cf_create_billing_profile details
[Cloudflare] Create Billing Profile. Additive: it gives an account that has none a billing identity. The fields decide who is invoiced and at what tax treatment, so an error here reaches the customer's invoice rather than their configuration. POST /accounts//billing/profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_billing_profile_payment_method details
cf_create_billing_profile_payment_method details
[Cloudflare] Create Payment Intent for Billing Profile. Additive: it mints a Stripe payment intent and attaches no payment method on its own. The client_secret in the response can complete a card attachment in a browser, so treat it as short-lived secret material and do not put it anywhere durable. It starts Stripe's payment-method flow: Cloudflare creates a Stripe payment intent and answers with intent_type and a client_secret that a browser checkout page needs to confirm the card. Nothing is charged and no payment method is attached until that flow finishes somewhere else, so an agent calling this alone achieves nothing - and the client_secret it hands back is live Stripe material, not a Cloudflare credential. POST /accounts//billing/profile/payment-method. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_billing_profile details
cf_delete_billing_profile details
[Cloudflare] DESTRUCTIVE: Delete Billing Profile. Why this is destructive: The account's billing identity goes with it - the billing email Cloudflare invoices, the business address and the tax details - so invoicing and any renewal that needs them start failing. Read cf_get_billing_profiles first and keep the values; re-creating the profile means entering them all again. DELETE /accounts//billing/profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_account_billing_history details
cf_get_account_billing_history details
[Cloudflare] Get Account Billing History. The account's billing history - the charges and payments Cloudflare has recorded, newest first, filterable by status. This is the account-scope history; cf_get_user_billing_history is the deprecated user-scope one. GET /accounts//billing/history. Path parameters: account_id. Optional filters: page, per_page, status. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_account_billing_usage details
cf_get_account_billing_usage details
[Cloudflare] Get account billing usage. DEPRECATED by Cloudflare in its API document: billing usage analytics as a time series across the billable products (Stream, Images, Rate Limiting, Load Balancing, Argo, Workers, Workers KV, Image Resizing and Spectrum). Cloudflare accepts limit up to 10000 data points but StackJack clamps it to 1000 per call; narrow the window with since/until instead. Needs an API token with Billing Read. GET /accounts//billing/usage. Path parameters: account_id. Optional filters: metrics, since, until, time_delta, limit, filters. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_billing_bad_debts details
cf_get_billing_bad_debts details
[Cloudflare] Get Account Bad Debt. What the account owes that Cloudflare has written to bad debt: the outstanding invoices and the total. An account in bad debt can have services suspended, so this is worth reading before debugging "why did this stop working". GET /accounts//billing/bad-debt. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_billing_credits details
cf_get_billing_credits details
[Cloudflare] Get Account Credits. The account's credit balance and whether it is eligible for credit. Credits are applied before a payment method is charged. GET /accounts//billing/credits. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_billing_profiles details
cf_get_billing_profiles details
[Cloudflare] Get Billing Profile. The account's billing profile: who is invoiced (billing_email plus secondary_billing_email), the business name and address behind the invoice, the tax id and the preferred locale. Read it before any billing write - both the PUT and the profile creates want these values back. GET /accounts//billing/profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_billing_unpaid_invoices details
cf_get_billing_unpaid_invoices details
[Cloudflare] Get Unpaid Invoices. The invoices Cloudflare is still waiting to be paid for this account, with the amounts. Pair it with cf_create_pay_invoice, which takes an invoice_id from here. GET /accounts//billing/unpaid-invoice. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_user_billing_history details
cf_get_user_billing_history details
[Cloudflare] Billing History Details. The TOKEN OWNER's own billing history rather than an account's. Cloudflare caps per_page at 50 here and StackJack clamps to that ceiling; cf_get_account_billing_history is the account-scope read that replaces it. GET /user/billing/history. Optional filters: page, per_page, order, occurred_at, type, action. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_get_user_billing_profiles details
cf_get_user_billing_profiles details
[Cloudflare] Billing Profile Details. The TOKEN OWNER's own billing profile rather than an account's. cf_get_billing_profiles is the account-scope read that replaces it. GET /user/billing/profile. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_set_billing_profile details
cf_set_billing_profile details
[Cloudflare] DESTRUCTIVE: Update Billing Profile. Why this is destructive: A PUT replaces the WHOLE billing profile: an omitted billing_email, address or tax id is cleared rather than kept, which lands directly on the customer's next invoice. Read cf_get_billing_profiles first and send the full object back, or use cf_update_billing_profile when the change is only the billing email or locale. PUT /accounts//billing/profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_billing_profile details
cf_update_billing_profile details
[Cloudflare] Update Billing Email. This is the narrow, safe billing write: Cloudflare changes only the billing email addresses and the preferred locale, and leaves the rest of the profile alone. It does change WHERE the customer's invoices are sent, so confirm the address. PATCH /accounts//billing/profile. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Communication Preferences
cf_get_user_communication_preferences details
cf_get_user_communication_preferences details
[Cloudflare] Get communication preferences. What the token owner has agreed to receive from Cloudflare: whether the email address is verified, the marketing opt-in state and the language locale. Read it before writing - the write is a replace. GET /user/communication_preferences. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_user_communication_preference details
cf_set_user_communication_preference details
[Cloudflare] DESTRUCTIVE: Update communication preferences. Why this is destructive: A PUT replaces the preference set from the body, so a preference you leave out reverts to Cloudflare's default rather than keeping the person's current choice - and these are a person's marketing and language consents. Read cf_get_user_communication_preferences first and send the full set back. PUT /user/communication_preferences. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Diagnostics
cf_create_diagnostics_endpoint_healthcheck details
cf_create_diagnostics_endpoint_healthcheck details
[Cloudflare] Endpoint Health Check. Additive: it creates one new probe and changes no existing check. Cloudflare begins probing the endpoint you name as soon as it exists, so point it at an address the customer owns. POST /accounts//diagnostics/endpoint-healthchecks. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_diagnostics_traceroute details
cf_create_diagnostics_traceroute details
[Cloudflare] Traceroute. It dispatches live traceroutes from the Cloudflare data centres you name toward the targets in the body and answers with the hops. Nothing in the customer's configuration changes, but real probe packets leave Cloudflare's network toward whatever you put in targets - so only name hosts the customer owns or is entitled to probe. Cloudflare gates this endpoint to Enterprise accounts and asks for an API token with Magic Transit Write; on any other plan it is refused. POST /accounts//diagnostics/traceroute. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_diagnostics_endpoint_healthcheck details
cf_delete_diagnostics_endpoint_healthcheck details
[Cloudflare] DESTRUCTIVE: Delete Endpoint Health Check. Why this is destructive: Cloudflare stops probing that endpoint, so the health signal anything downstream was reading simply stops. There is no undo; re-create the check to restore it. DELETE /accounts//diagnostics/endpoint-healthchecks/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_diagnostics_endpoint_healthcheck details
cf_get_diagnostics_endpoint_healthcheck details
[Cloudflare] Get Endpoint Health Check. One endpoint health check by id, with the probe type and the address it targets. Cloudflare gates this endpoint to Enterprise accounts and asks for an API token with Magic Transit Write; on any other plan it is refused. GET /accounts//diagnostics/endpoint-healthchecks/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_diagnostics_endpoint_healthchecks details
cf_get_diagnostics_endpoint_healthchecks details
[Cloudflare] List Endpoint Health Checks. The account's endpoint health checks - Cloudflare-run probes of a customer endpoint, used with Magic Transit and Magic WAN. Each row's id is what the get, update and delete tools take. Cloudflare gates this endpoint to Enterprise accounts and asks for an API token with Magic Transit Write; on any other plan it is refused. This endpoint takes no paging parameters - the whole collection comes back in one response. GET /accounts//diagnostics/endpoint-healthchecks. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_diagnostics_endpoint_healthcheck details
cf_set_diagnostics_endpoint_healthcheck details
[Cloudflare] DESTRUCTIVE: Update Endpoint Health Check. Why this is destructive: A PUT replaces the whole check from the body, so an omitted name is cleared and an omitted check_type or endpoint is refused. Read the check first and send it back complete. PUT /accounts//diagnostics/endpoint-healthchecks/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Entitlements
cf_list_entitlements details
cf_list_entitlements details
[Cloudflare] Get Account Entitlements. What this account is actually entitled to use: one row per product feature with the allocation that governs it (a boolean, a count, a range, an enum or a string). It is the read that explains a 403 on some other tool - if the feature is not entitled here, the call will not work whatever the token allows. GET /accounts//entitlements. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones_entitlements details
cf_list_zones_entitlements details
[Cloudflare] Get Zone Entitlements. The same entitlement list as cf_list_entitlements, resolved for ONE zone: the features and allocations that zone may use. Read it when a zone-scoped call is refused and you want to know whether it is the plan rather than the token. GET /zones//entitlements. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Flagship
cf_create_flagship_app details
cf_create_flagship_app details
[Cloudflare] Create app. Additive: it creates one new flag container and changes nothing that exists. The id it returns is what every other Flagship tool takes. POST /accounts//flagship/apps. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_flagship_apps_evaluate details
cf_create_flagship_apps_evaluate details
[Cloudflare] Evaluate flag (POST). The POST form of the flag evaluation: same answer as cf_list_flagship_apps_evaluates, but the context travels as an OFREP-shaped JSON body, so its values keep their types instead of being flattened to strings. It evaluates and returns - no flag, app or rollout is changed - which is why it ships as a read. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. POST /accounts//flagship/apps//evaluate. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_flagship_apps_flag details
cf_create_flagship_apps_flag details
[Cloudflare] Create flag. Additive: it adds one flag to the app and changes no existing flag. The flag is live for evaluation as soon as Cloudflare stores it, so an enabled flag with a rollout rule starts serving its variations immediately. Cloudflare answers 409 if the key already exists. POST /accounts//flagship/apps//flags. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_flagship_app details
cf_delete_flagship_app details
[Cloudflare] DESTRUCTIVE: Delete app. Why this is destructive: It deletes the app AND every flag in it AND the whole changelog history, and Cloudflare refuses with 409 only while a Worker still binds to the app - so once the binding is gone the flags go with it and SDKs fall back to their caller-supplied defaults. There is no undo. DELETE /accounts//flagship/apps/. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_flagship_apps_flag details
cf_delete_flagship_apps_flag details
[Cloudflare] DESTRUCTIVE: Delete flag. Why this is destructive: Cloudflare deletes the flag permanently and says so: every later evaluation falls back to the default the CALLING code supplies, which is usually the off state, so any behaviour behind the flag changes at once. It cannot be undone. DELETE /accounts//flagship/apps//flags/. Path parameters: account_id, app_id, flag_key. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_flagship_app details
cf_get_flagship_app details
[Cloudflare] Get app. One app's name and audit fields by id. Flag definitions are not included. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps/. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_flagship_apps_flag details
cf_get_flagship_apps_flag details
[Cloudflare] Get flag. The full definition of one flag - variations, default_variation, the ordered rules and the audit fields. Read it before cf_set_flagship_apps_flag, which replaces the lot. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps//flags/. Path parameters: account_id, app_id, flag_key. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_flagship_apps details
cf_list_flagship_apps details
[Cloudflare] List apps. Start here for Flagship: an app is the container a set of feature flags live in, and each row's id is the app_id every flag, changelog and evaluation tool takes. Identity and audit fields only - the flags themselves come from cf_list_flagship_apps_flags. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_flagship_apps_definitions details
cf_list_flagship_apps_definitions details
[Cloudflare] Get flag definitions. The evaluation-only copy of the app's flag definitions, the shape an SDK that evaluates locally consumes. Send the ETag from a previous response in ifNoneMatch and Cloudflare answers 304 when nothing has changed instead of re-sending the document. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps//definitions. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_flagship_apps_evaluates details
cf_list_flagship_apps_evaluates details
[Cloudflare] Evaluate flag. Evaluates ONE flag for one context and answers with the variation that flag would serve. flagKey is REQUIRED even though the argument is optional in this tool's signature, and targetingKey is the identity a percentage rollout buckets on. Cloudflare forwards every context value as a string here; cf_create_flagship_apps_evaluate takes a typed JSON context instead. For in-Worker evaluation Cloudflare recommends the Flagship binding over either. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps//evaluate. Path parameters: account_id, app_id. Cloudflare REQUIRES this query parameter and answers 400 without it: flagKey. Optional filters: targetingKey. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_flagship_apps_flags details
cf_list_flagship_apps_flags details
[Cloudflare] List flags. The app's flags, ordered by key, with their variations and rules. Paging is CURSOR-based: take cursor from result_info and pass it back for the next page; a null cursor means the last page. limit is a string Cloudflare accepts from 1 to 200 and StackJack passes it through unchanged, so the generic page-size sentence below does not apply here. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps//flags. Path parameters: account_id, app_id. Optional filters: limit, cursor. Cloudflare declares this endpoint's page size as a string, so StackJack sends the value verbatim and applies no ceiling of its own. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_flagship_apps_flags_changelogs details
cf_list_flagship_apps_flags_changelogs details
[Cloudflare] Get flag changelog. Who changed this flag and how, newest first: each entry carries the event type and the full flag state after the change, and an update entry also carries a field-level diff. Cloudflare keeps at most 200 entries per flag. Paging is CURSOR-based - pass cursor from result_info - and limit is a string from 1 to 200 that StackJack passes through unchanged, so the generic page-size sentence below does not apply. Flagship is Cloudflare's feature-flag product and this operation is BETA - the contract can change. It needs an API token with a Flagship permission group. GET /accounts//flagship/apps//flags//changelog. Path parameters: account_id, app_id, flag_key. Optional filters: limit, cursor. Cloudflare declares this endpoint's page size as a string, so StackJack sends the value verbatim and applies no ceiling of its own. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_flagship_app details
cf_set_flagship_app details
[Cloudflare] DESTRUCTIVE: Update app. Why this is destructive: Cloudflare treats only name as mutable here, so this is a rename - the flags in the app are not touched. It is still a PUT, so send the object rather than a fragment. PUT /accounts//flagship/apps/. Path parameters: account_id, app_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_flagship_apps_flag details
cf_set_flagship_apps_flag details
[Cloudflare] DESTRUCTIVE: Update flag. Why this is destructive: It replaces the ENTIRE flag definition and Cloudflare is explicit that omitted fields are dropped rather than preserved: a rule or a variation you leave out disappears, and the next evaluation serves something else. Read cf_get_flagship_apps_flag first and send the complete object back. Each write appends a changelog entry. PUT /accounts//flagship/apps//flags/. Path parameters: account_id, app_id, flag_key. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Hold
cf_create_zones_hold details
cf_create_zones_hold details
[Cloudflare] Create Zone Hold. Additive and reversible: it turns the hold on, blocking the creation or activation of any zone with this hostname anywhere in Cloudflare - including in the customer's own other accounts, which is the usual surprise. Cloudflare refuses a hold on a CDN-only zone. cf_delete_zones_hold lifts it. POST /zones//hold. Path parameters: zone_id. Optional filters: include_subdomains. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_hold details
cf_delete_zones_hold details
[Cloudflare] DESTRUCTIVE: Remove Zone Hold. Why this is destructive: It stops enforcing the hold, so from that moment ANY Cloudflare account can add or activate a zone with this hostname - including someone outside the customer's organization. Pass hold_after to suspend it until a time instead, which is the safer form when you only need a window to move the domain. DELETE /zones//hold. Path parameters: zone_id. Optional filters: hold_after. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_hold details
cf_get_zones_hold details
[Cloudflare] Get Zone Hold by Zone Name. Whether a given HOSTNAME is blocked by a hold, including a hold on an ancestor domain that was created with include_subdomains - which is what makes it different from cf_get_zones_holds, the read for the zone itself. Cloudflare uses this call internally during zone activation, so it is the read that explains "this domain cannot be added". GET /zones//hold/. Path parameters: zone_id, zone_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_holds details
cf_get_zones_holds details
[Cloudflare] Get Zone Hold. Whether THIS zone is held, and the hold's metadata (when it was created and whether it covers subdomains). A zone hold is the lock that stops anyone else adding this hostname to Cloudflare - the protection against a domain being claimed in another account. cf_get_zones_hold is the other read: it answers for a HOSTNAME, following ancestor domains. GET /zones//hold. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_zones_hold details
cf_update_zones_hold details
[Cloudflare] Update Zone Hold. Partial update of an existing hold: hold_after schedules when enforcement resumes and include_subdomains widens or narrows what it covers. Setting hold_after to a time in the PAST means the hold is enforced now, and setting it to null on a CDN-only zone removes the hold entirely. PATCH /zones//hold. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Invites
cf_get_user_invite details
cf_get_user_invite details
[Cloudflare] Invitation Details. One invitation by id: which account and organization sent it, the roles it carries and whether it is still pending. Account invitations are Enterprise-gated in Cloudflare's own plan availability and need an API token with a Memberships permission group. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Memberships Write or Memberships Read permission rather than that the call is unsupported. GET /user/invites/. Path parameters: invite_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_user_invites details
cf_list_user_invites details
[Cloudflare] List Invitations. The account invitations waiting for the TOKEN OWNER - the accounts this user has been asked to join, with each invitation's id and status. It is the token owner's own inbox, not an account's outgoing invitation list; cf_list_account_members shows an account's members and their pending state. Account invitations are Enterprise-gated in Cloudflare's own plan availability and need an API token with a Memberships permission group. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Memberships Write or Memberships Read permission rather than that the call is unsupported. GET /user/invites. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_user_invite details
cf_update_user_invite details
[Cloudflare] DESTRUCTIVE: Respond to Invitation. Why this is destructive: This is how an invitation is ACCEPTED or REJECTED, and it decides account access: accepting makes the token owner a member of that account with the roles the invitation carries, rejecting closes it and only a new invitation from an administrator can reopen it. It acts for the token owner, not for a person you name. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the Memberships Write permission rather than that the call is unsupported. PATCH /user/invites/. Path parameters: invite_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Invoices
cf_update_invoice details
cf_update_invoice details
[Cloudflare] Toggle PDF Invoices. A reversible account preference: it switches PDF invoice generation on or off for this account. It changes what Cloudflare sends the customer, not what they are charged. PATCH /accounts//invoices. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
IPs
cf_get_ips details
cf_get_ips details
[Cloudflare] Cloudflare/JD Cloud IP Details. Cloudflare's own published edge IP ranges - the addresses customer origins should allow. Public reference data, identical for every customer and not tied to the account the token belongs to. Pass networks=jdcloud for the JD Cloud ranges used by the China network. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /ips. Optional filters: networks. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Live
cf_check_liveness details
cf_check_liveness details
[Cloudflare] Run liveness checks. Cloudflare's own liveness probe for the API: it answers a success message and says nothing about the customer's account, so it is only useful for telling an API outage apart from a permissions problem. cf_verify_account_token is the right read for "is our credential alive?". GET /live. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Load Balancing Analytics
cf_list_user_lb_analytics_events details
cf_list_user_lb_analytics_events details
[Cloudflare] List Healthcheck Events. Origin and pool health CHANGES over a window - when an origin went down, when a pool recovered - for the token owner's user-scope load balancing. This is the history behind cf_get_user_lb_pool_health, which only shows the latest state. Filter by pool_id or pool_name, by origin_name, and by origin_healthy / pool_healthy to see only the failures. GET /user/load_balancing_analytics/events. Optional filters: until, pool_name, origin_healthy, pool_id, since, origin_name, pool_healthy. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Move
cf_move_account details
cf_move_account details
[Cloudflare] DESTRUCTIVE: Move account. Why this is destructive: It re-parents ONE account under a different organization, and the account takes its zones, its members' access and its billing with it - so the customer's live domains end up administered somewhere else. Moving it back is another call with the original organization id, which you should read and keep before sending this. Cloudflare marks this operation BETA. The same call moves an account OUT of an organization hierarchy as well as within one. cf_move_accounts_batch is the batch form. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. POST /accounts//move. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_move_accounts_batch details
cf_move_accounts_batch details
[Cloudflare] DESTRUCTIVE: Batch move accounts. Why this is destructive: It re-parents a whole COLLECTION of accounts under a different organization in one call, and an account carries its zones, its members' access and its billing with it - so a wrong destination_organization_id moves the customer's live domains under administration they did not choose. There is no batch undo: each account has to be moved back individually. Cloudflare marks this operation ALPHA and its own API document says "Not implemented", so expect it to be refused; cf_move_account is the one-account form that does work. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. POST /accounts/move. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
One
cf_create_one_integration details
cf_create_one_integration details
[Cloudflare] Create integration. Additive: it adds one new SaaS connection and changes no existing one. Cloudflare begins crawling the customer's tenant with the credentials you supply as soon as it is created, so the permissions those credentials carry decide what Cloudflare can see. Cloudflare does not support creating an OAuth-based integration through the API - the other auth methods work. POST /accounts//one/integrations. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_one_integration details
cf_delete_one_integration details
[Cloudflare] DESTRUCTIVE: Delete integration. Why this is destructive: Cloudflare soft-deletes the integration: crawling stops and the connection disappears from the customer's Cloudflare One posture, so CASB findings and any DLP scanning that depended on it stop being produced. The API offers no undo here - re-connecting means creating the integration again with fresh credentials. DELETE /accounts//one/integrations/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_one_application details
cf_get_one_application details
[Cloudflare] Get application details. One catalog application in full: the auth methods it supports, its use cases and the permissions an integration will ask for. Cloudflare One integrations are the SaaS connections CASB and the email/data scanners read through - a customer's Google Workspace or Microsoft 365 tenant, for example. GET /accounts//one/applications/. Path parameters: account_id, application_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_one_integration details
cf_get_one_integration details
[Cloudflare] Get integration details. One integration in full: its application, status, use cases, DLP profiles and permissions, plus credentials_expiry - the date the stored credential stops working, which is the usual cause of an integration that has quietly stopped crawling. GET /accounts//one/integrations/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_one_applications details
cf_list_one_applications details
[Cloudflare] List applications. The CATALOG of applications Cloudflare One can integrate with - vendors, their use cases and the permissions each needs - not the customer's own connections. Each row's id is the application_id the auth-method and setup-flow reads take, and the value you put in a new integration's application field. Cloudflare One integrations are the SaaS connections CASB and the email/data scanners read through - a customer's Google Workspace or Microsoft 365 tenant, for example. Use cf_list_one_integrations for what the customer has actually connected. GET /accounts//one/applications. Path parameters: account_id. Optional filters: environment, page, page_size. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_one_applications_auth_methods details
cf_list_one_applications_auth_methods details
[Cloudflare] Get auth methods. How this vendor can be authenticated: each auth method with its CREDENTIAL SCHEMA, setup instructions and an example payload. Read it before cf_create_one_integration - the credentials object that call needs has the shape described here. It returns the schema and the field names, never a customer's own secret. GET /accounts//one/applications//auth-methods. Path parameters: account_id, application_id. Optional filters: page, page_size. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_one_applications_setup_flows details
cf_list_one_applications_setup_flows details
[Cloudflare] Get application setup flows. The setup flows Cloudflare publishes for this application, one per auth method: the ordered steps a person follows in the vendor's console before the integration can be created. Filter by auth_method or environment. GET /accounts//one/applications//setup-flows. Path parameters: account_id, application_id. Optional filters: auth_method, environment, page, page_size. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_one_integrations details
cf_list_one_integrations details
[Cloudflare] List integrations. Start here for what the customer has actually CONNECTED: one row per Cloudflare One integration, with its application, status, use cases and whether DLP is on. Each row's id is what the get, update, pause, resume and delete tools take. Cloudflare One integrations are the SaaS connections CASB and the email/data scanners read through - a customer's Google Workspace or Microsoft 365 tenant, for example. Filter by application (GOOGLE_WORKSPACE, MICROSOFT_INTERNAL and so on), by status, or by use_cases such as casb or ces. GET /accounts//one/integrations. Path parameters: account_id. Optional filters: application, direction, dlp_enabled, order, page, page_size, search, status, use_cases. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_pause_one_integrations details
cf_pause_one_integrations details
[Cloudflare] Pause integration. Reversible: it pauses the integration and stops every crawler on it, so Cloudflare stops discovering new findings for that tenant until cf_resume_one_integrations is called. Nothing already discovered is deleted. POST /accounts//one/integrations//pause. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_resume_one_integrations details
cf_resume_one_integrations details
[Cloudflare] Resume integration. Reversible: it resumes a paused integration and restarts its crawlers, so Cloudflare begins reading the customer's tenant again with the stored credentials. POST /accounts//one/integrations//resume. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_one_integration details
cf_update_one_integration details
[Cloudflare] Update integration. Partial update: Cloudflare applies only the members you send. Sending credentials REPLACES the stored secret for the vendor tenant, which is how an expired credential is rotated - and how a wrong value silently stops the crawl. Changing use_cases or dlp_profiles changes what Cloudflare scans from the next crawl. PATCH /accounts//one/integrations/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Pay Bad Debt
cf_create_pay_bad_debt details
cf_create_pay_bad_debt details
[Cloudflare] DESTRUCTIVE: Pay Bad Debt. Why this is destructive: It CHARGES the customer: Cloudflare discovers every outstanding bad debt on the account and takes payment for it from the payment method you name, or the default one. Money moves as soon as Cloudflare accepts the call and the API offers no reversal - a refund is a support matter. Read cf_get_billing_bad_debts first so you know the amount. POST /accounts//pay-bad-debt. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Pay Invoice
cf_create_pay_invoice details
cf_create_pay_invoice details
[Cloudflare] DESTRUCTIVE: Pay Invoice. Why this is destructive: It CHARGES the customer: Cloudflare takes payment for the invoice you name from the payment method you name, or the default one. Money moves as soon as Cloudflare accepts the call and the API offers no reversal. Read cf_get_billing_unpaid_invoices first and confirm the invoice_id and the amount. When the card issuer demands Strong Customer Authentication, Cloudflare answers with a Stripe client secret instead of a completed payment: the charge is NOT done, and a person has to finish the challenge in a browser. POST /accounts//pay-invoice. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Payment Methods
cf_create_payment_method details
cf_create_payment_method details
[Cloudflare] Create Payment Method. Additive: it stores one new payment method on the account and does not make it the default - cf_create_payment_method_set_as_default does that. Nothing is charged by this call, but the method becomes chargeable by the pay tools and by renewals. POST /accounts//payment-methods. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_payment_method_set_as_default details
cf_create_payment_method_set_as_default details
[Cloudflare] Set Default Payment Method. It changes WHICH stored method Cloudflare charges for this account's renewals and invoices. Reversible - set another method as default to move it back - but until you do, every automatic charge lands on the method you just named. POST /accounts//payment-methods//set-as-default. Path parameters: account_id, payment_method_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_payment_method details
cf_delete_payment_method details
[Cloudflare] DESTRUCTIVE: Delete Payment Method. Why this is destructive: The stored method is removed, so any renewal or invoice that would have been charged to it fails from then on - and if it was the account default, Cloudflare has nothing to charge until another method is made default. Check cf_list_payment_methods for a second method first. DELETE /accounts//payment-methods/. Path parameters: account_id, payment_method_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_payment_method details
cf_get_payment_method details
[Cloudflare] Get Payment Method. One stored payment method by id: its type, last_four, gateway and whether it is the account default. Cloudflare never returns a full card number. GET /accounts//payment-methods/. Path parameters: account_id, payment_method_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_payment_methods details
cf_list_payment_methods details
[Cloudflare] List Payment Methods. The payment methods stored on the account - type, last_four, the gateway and which one is the default. Each row's id is the payment_method_id the get, update, delete, set-as-default and the two pay tools take. Cloudflare returns the card's last four digits, never a full card number. GET /accounts//payment-methods. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_payment_method details
cf_set_payment_method details
[Cloudflare] DESTRUCTIVE: Update Payment Method. Why this is destructive: A PUT replaces the stored payment method from the body, so an omitted billing name, address or bank detail is cleared rather than kept - and the method is what Cloudflare charges for renewals and invoices. Read cf_get_payment_method first and send the complete object back. PUT /accounts//payment-methods/. Path parameters: account_id, payment_method_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Rate Plans
cf_get_rate_plan details
cf_get_rate_plan details
[Cloudflare] Get Rate Plan by Public Key. A public price-catalog read: the details of one Cloudflare rate plan by its public key, such as teams_free or cf_pro_20_20. Cloudflare does not enforce authentication on it and the answer is the same for every customer - it is the plan definition, not what this account is on. Use cf_list_subscriptions for the account's own plans. GET /billing/rate_plans/. Path parameters: public_key. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Ready
cf_check_readiness details
cf_check_readiness details
[Cloudflare] Run readiness checks. Cloudflare's own readiness probe for the API - the sibling of the liveness probe on /live. It reports the API's own state, never the customer's account. GET /ready. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Receipts
cf_download_receipt_pdf details
cf_download_receipt_pdf details
[Cloudflare] Get Receipt PDF. The customer-facing PDF for one receipt. StackJack uploads the bytes and answers with a short-lived download link rather than the file itself, which is why this read is Pro tier rather than Free: it spends blob storage and mints a bearer URL. Fetch the link promptly - it expires in about fifteen minutes and nothing keeps a copy afterwards. GET /accounts//receipts//pdf. Path parameters: account_id, receipt_id. Optional filters: doctype. This Cloudflare endpoint answers a file rather than JSON, so instead of the bytes you get a JSON envelope with sasUrl (a short-lived read-only download link, valid for about 15 minutes), contentType, suggestedFileName, sizeBytes and expiresAt. Fetch the link before it expires; nothing else in StackJack keeps a copy.
Signed URL
cf_list_signed_urls details
cf_list_signed_urls details
[Cloudflare] Internal route for testing signed URLs. Cloudflare's own internal route for TESTING signed URLs, published in the API document but not a customer feature: it returns nothing about the account and is only useful for probing the API itself. GET /signed-url. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Spectrum Analytics
cf_list_user_spectrum_analytics_zones_reports details
cf_list_user_spectrum_analytics_zones_reports details
[Cloudflare] Get zones bandwidth report. Total bandwidth by zone over a window for the TOKEN OWNER's zones, the Spectrum (TCP/UDP proxy) view. cdn_traffic defaults to true and folds ordinary CDN traffic into the totals - set it false for Spectrum bandwidth alone. GET /user/spectrum_analytics/zones/report. Optional filters: since, until, cdn_traffic. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Submit
cf_submit_root details
cf_submit_root details
[Cloudflare] Internal route for testing URL submissions. Cloudflare's own internal route for TESTING URL submissions. It takes no body and no parameters, changes nothing in the customer's account, and is published in the API document without a documented effect - there is no customer reason to call it. POST /internal/submit. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Subscription
cf_create_zones_subscription details
cf_create_zones_subscription details
[Cloudflare] DESTRUCTIVE: Create Zone Subscription. Why this is destructive: It puts the zone onto a paid plan or adds a paid add-on, so Cloudflare starts billing for it and keeps billing at the renewal frequency you set. It changes what this customer is CHARGED: the subscription renews on its own at the frequency and rate plan it carries, so the next invoice reflects whatever you send. Read cf_get_zones_subscriptions and cf_get_rate_plan first, and confirm the plan and the amount with whoever pays the invoice. POST /zones//subscription. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_subscription details
cf_delete_zones_subscription details
[Cloudflare] DESTRUCTIVE: Delete Zone Subscription. Why this is destructive: It cancels the zone's paid plan: the domain drops to what its account's free entitlement covers, so paid features stop applying to live traffic. Billing changes with it. Read cf_get_zones_subscriptions first and keep the rate_plan id - re-subscribing is a new subscription at whatever the plan costs today. DELETE /zones//subscription. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_subscriptions details
cf_get_zones_subscriptions details
[Cloudflare] Zone Subscription Details. The subscription attached to ONE zone - the plan the domain is on, its rate plan, price, renewal frequency and current period. Read it before any subscription write so you know what the customer is paying today. Cloudflare exposes the same zone subscription on two paths: this singular /subscription one, which its own document prefers, and the plural /subscriptions alias. GET /zones//subscription. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_subscription details
cf_set_zones_subscription details
[Cloudflare] DESTRUCTIVE: Update Zone Subscription. Why this is destructive: A PUT replaces the zone's whole subscription from the body, so an omitted rate_plan or frequency does not keep its current value - and this is the customer's bill. Upgrading, downgrading or changing the renewal frequency all land on the next invoice, and a downgrade takes features away from a live domain. Read cf_get_zones_subscriptions first and send the complete object back. PUT /zones//subscription. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Subscriptions
cf_create_subscription details
cf_create_subscription details
[Cloudflare] DESTRUCTIVE: Create Subscription. Why this is destructive: It starts a new PAID subscription on the account, so Cloudflare bills for it and keeps billing at the renewal frequency you set. It changes what this customer is CHARGED: the subscription renews on its own at the frequency and rate plan it carries, so the next invoice reflects whatever you send. Read cf_list_subscriptions and cf_get_rate_plan first, and confirm the plan and the amount with whoever pays the invoice. POST /accounts//subscriptions. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_subscriptions_action_append details
cf_create_subscriptions_action_append details
[Cloudflare] DESTRUCTIVE: Append Subscription Action. Why this is destructive: Cloudflare calls this "smartly applies the incoming subscription into the lifecycle of the subscription": it folds the subscription in the body into the existing one, which can change the rate plan, the component quantities or the renewal, so the customer's next invoice changes and the exact outcome is decided by Cloudflare rather than stated by you. Read cf_get_subscription before and after. POST /accounts//subscriptions//action/append. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_subscriptions_cancel_downgrade details
cf_create_subscriptions_cancel_downgrade details
[Cloudflare] DESTRUCTIVE: Cancel Delayed Downgrade. Why this is destructive: It CANCELS pending downgrades, which means the subscriptions you name stay on their current (higher) plan and keep being billed at that price instead of dropping at the period end. That is the opposite of what "cancel" reads like at a glance, so confirm which outcome the customer wants before sending it. POST /accounts//subscriptions/cancel-downgrade. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_subscriptions_cancel_reason details
cf_create_subscriptions_cancel_reason details
[Cloudflare] DESTRUCTIVE: Create Cancel Reason. Why this is destructive: It records WHY a subscription was cancelled against the subscription's own record, where Cloudflare's billing and account teams read it. It does not cancel anything itself - cf_delete_subscription does that - but the note it leaves is on the customer's account permanently. POST /accounts//subscriptions//cancel-reason. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_user_subscription details
cf_create_user_subscription details
[Cloudflare] DESTRUCTIVE: Create User Subscription. Why this is destructive: It starts a new PAID subscription billed to the token owner's own user, so Cloudflare bills that user and keeps billing at the renewal frequency you set. It changes what this customer is CHARGED: the subscription renews on its own at the frequency and rate plan it carries, so the next invoice reflects whatever you send. Most customers want the account-scope cf_create_subscription instead. POST /user/subscriptions. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_subscription_by_zone_id details
cf_create_zones_subscription_by_zone_id details
[Cloudflare] DESTRUCTIVE: Create Zone Subscription. Why this is destructive: It puts the zone onto a paid plan or adds a paid add-on, so Cloudflare starts billing for it and keeps billing at the renewal frequency you set. It changes what this customer is CHARGED: the subscription renews on its own at the frequency and rate plan it carries, so the next invoice reflects whatever you send. This is Cloudflare's PLURAL /subscriptions alias, retained for audit-log coverage; its own document says to use the singular path instead, which is cf_create_zones_subscription. POST /zones//subscriptions. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_subscription details
cf_delete_subscription details
[Cloudflare] DESTRUCTIVE: Delete Subscription. Why this is destructive: It cancels a paid subscription on the account: the products it covered drop to the free entitlement, which can switch off protections or features on live traffic, and the billing stops with them. Read cf_get_subscription first and keep the rate_plan id - re-subscribing is a new subscription at today's price. DELETE /accounts//subscriptions/. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_user_subscription details
cf_delete_user_subscription details
[Cloudflare] DESTRUCTIVE: Delete User Subscription. Why this is destructive: It cancels a subscription billed to the token owner's own user: whatever it paid for drops to the free entitlement and the billing stops. Read cf_list_user_subscriptions first and keep the rate_plan id - re-subscribing is a new subscription at today's price. DELETE /user/subscriptions/. Path parameters: identifier. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_subscriptions details
cf_delete_zones_subscriptions details
[Cloudflare] DESTRUCTIVE: Delete Zone Subscription. Why this is destructive: It cancels the zone's paid plan: the domain drops to what its account's free entitlement covers, so paid features stop applying to live traffic, and the billing stops with them. This is Cloudflare's PLURAL /subscriptions alias, retained for audit-log coverage; its own document says to use the singular path instead, which is cf_delete_zones_subscription. DELETE /zones//subscriptions. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_subscription details
cf_get_subscription details
[Cloudflare] Get Subscription. One account subscription by its identifier: rate plan, price, renewal frequency, state and the current billing period. Read it before any write to this subscription. GET /accounts//subscriptions/. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_subscriptions_cancel_reasons details
cf_get_subscriptions_cancel_reasons details
[Cloudflare] Get Cancel Reason. The cancellation reason recorded against one subscription, if any - what the customer said when they cancelled. It reads the record; cf_create_subscriptions_cancel_reason writes one. GET /accounts//subscriptions//cancel-reason. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_subscriptions details
cf_list_subscriptions details
[Cloudflare] List Subscriptions. Start here for what the customer is PAYING FOR: every subscription on the account, each with its rate plan, price, renewal frequency, state and current period. The id on each row is the subscription_identifier the get, update, delete and cancel tools take. This endpoint takes no paging parameters - the whole collection comes back in one response. GET /accounts//subscriptions. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_user_subscriptions details
cf_list_user_subscriptions details
[Cloudflare] Get User Subscriptions. The subscriptions billed to the TOKEN OWNER's own user rather than to an account - the older user-scope billing model. cf_list_subscriptions is the account-scope read most customers need. This endpoint takes no paging parameters - the whole collection comes back. GET /user/subscriptions. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_subscription details
cf_set_subscription details
[Cloudflare] DESTRUCTIVE: Update Subscription. Why this is destructive: A PUT replaces the account subscription from the body, so an omitted rate_plan or frequency does not keep its current value - and this is the customer's bill. An upgrade, a downgrade or a change of renewal frequency all reach the next invoice, and a downgrade removes whatever the higher plan was providing. Read cf_get_subscription first and send the complete object back. PUT /accounts//subscriptions/. Path parameters: subscription_identifier, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_user_subscription details
cf_set_user_subscription details
[Cloudflare] DESTRUCTIVE: Update User Subscription. Why this is destructive: A PUT replaces a user-scope subscription from the body, so an omitted rate_plan or frequency does not keep its current value and the change lands on the token owner's next invoice. Read cf_list_user_subscriptions first and send the complete object back. PUT /user/subscriptions/. Path parameters: identifier. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_subscription_by_zone_id details
cf_set_zones_subscription_by_zone_id details
[Cloudflare] DESTRUCTIVE: Update Zone Subscription. Why this is destructive: A PUT replaces the zone's whole subscription from the body, so an omitted rate_plan or frequency does not keep its current value and the change reaches the customer's next invoice; a downgrade also takes features away from a live domain. This is Cloudflare's PLURAL /subscriptions alias, retained for audit-log coverage; its own document says to use the singular path instead, which is cf_set_zones_subscription. PUT /zones//subscriptions. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Tags
cf_delete_tags details
cf_delete_tags details
[Cloudflare] DESTRUCTIVE: Delete tags from an account-level resource. Why this is destructive: It removes ALL tags from the resource in one call, not the one tag you might have in mind: cost allocation, saved filters and any automation keyed off those tags stop matching it. Read cf_get_tags first if you want to put them back, and use cf_set_tag with the reduced set when you only mean to drop one. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. DELETE /accounts//tags. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_tags details
cf_delete_zones_tags details
[Cloudflare] DESTRUCTIVE: Delete tags from a zone-level resource. Why this is destructive: It removes ALL tags from that zone-level resource in one call, not one tag: cost allocation, saved filters and any automation keyed off them stop matching. Use cf_set_zones_tag with the reduced set when you only mean to drop one. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. DELETE /zones//tags. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_tags details
cf_get_tags details
[Cloudflare] Get tags for an account-level resource. The tags on ONE account-level resource. resource_id and resource_type are REQUIRED by Cloudflare even though both arguments are optional in this tool's signature - the call is refused without them. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. Use cf_list_tags_resources to find tagged resources and cf_get_zones_tags for a zone-level one. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /accounts//tags. Path parameters: account_id. Cloudflare REQUIRES these query parameters and answers 400 without it: resource_id, resource_type. Optional filters: worker_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_tags_summary details
cf_get_tags_summary details
[Cloudflare] List tag key summary. Tag keys AND their distinct values across the account in one response - the summary view of the whole tagging vocabulary, where cf_list_tags_keys returns only the keys. Paging is cursor-based. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /accounts//tags/summary. Path parameters: account_id. Optional filters: cursor. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_tags details
cf_get_zones_tags details
[Cloudflare] Get tags for a zone-level resource. The tags on ONE zone-level resource. resource_id and resource_type are REQUIRED by Cloudflare even though both arguments are optional in this tool's signature - the call is refused without them. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. cf_get_tags is the account-level equivalent. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /zones//tags. Path parameters: zone_id. Cloudflare REQUIRES these query parameters and answers 400 without it: resource_id, resource_type. Optional filters: access_application_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tag_values details
cf_list_tag_values details
[Cloudflare] List tag values. Every distinct value in use for ONE tag key, optionally narrowed to a resource type. Use it to discover what a key's values actually are before filtering cf_list_tags_resources by them. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /accounts//tags/values/. Path parameters: account_id, tag_key. Optional filters: type, cursor. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tags_keys details
cf_list_tags_keys details
[Cloudflare] List tag keys. Every distinct tag KEY in use across the account's resources - the vocabulary someone has actually applied. Start here, then cf_list_tag_values for one key's values or cf_get_tags_summary for keys and values together. Paging is cursor-based. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /accounts//tags/keys. Path parameters: account_id. Optional filters: cursor. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tags_resources details
cf_list_tags_resources details
[Cloudflare] List tagged resources. The account's TAGGED resources, filterable by tag criteria, resource type, name or id - the read that answers "what belongs to this project or cost centre?". case_insensitive matches keys and values without regard to case. Paging is cursor-based. Resource tagging is BETA and Cloudflare gates it to Enterprise accounts, so it is refused on every other plan. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. GET /accounts//tags/resources. Path parameters: account_id. Optional filters: type, name, id, case_insensitive, tag, cursor. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_tag details
cf_set_tag details
[Cloudflare] DESTRUCTIVE: Set tags for an account-level resource. Why this is destructive: It REPLACES the full tag set on that resource: a tag missing from the body is removed, so anything keyed off it - cost allocation, a saved filter, another team's automation - stops matching. Read cf_get_tags first and send the complete set. Pass the ETag in ifMatch so a concurrent edit is refused instead of silently overwritten. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. PUT /accounts//tags. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_tag details
cf_set_zones_tag details
[Cloudflare] DESTRUCTIVE: Set tags for a zone-level resource. Why this is destructive: Cloudflare replaces ALL existing tags on that zone-level resource with the set you send, so a tag missing from the body is removed and anything keyed off it stops matching. Read cf_get_zones_tags first and send the complete set, and pass the ETag in ifMatch so a concurrent edit is refused rather than overwritten. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the permission this operation needs - Cloudflare names no permission group for it - rather than that the call is unsupported. PUT /zones//tags. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
User
cf_get_users details
cf_get_users details
[Cloudflare] User Details. The identity behind the credential: the token owner's email, name, country and two-factor state, plus the accounts they belong to. It is the read that answers "whose token is this?" when a call is refused. The path is /user - one user, the authenticated one. Cloudflare's API document lists only the legacy email plus Global API Key pair for this operation. StackJack always authenticates with an API token, so a refusal here means the token is missing the User Details Write or User Details Read permission rather than that the call is unsupported. GET /user. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_user details
cf_update_user details
[Cloudflare] Edit User. It edits the real person's own Cloudflare profile - first_name, last_name, telephone, country and zipcode - for the user the token belongs to, not for a member you name. Partial: omitted fields keep their value. The email address cannot be changed here. PATCH /user. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
v4
cf_check_api_health details
cf_check_api_health details
[Cloudflare] API health check. Cloudflare describes this as an INTERNAL infrastructure health check for its API monolith, not intended for customer use and excluded from its own SDKs and public docs. It tells you nothing about the customer's account; prefer cf_verify_account_token or the /live probe. GET /api/v4/health. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Zones
cf_create_zone details
cf_create_zone details
[Cloudflare] Create Zone. Additive: adds a zone and changes no existing one. POST /zones. Send the request body as JSON; Cloudflare documents these fields: account, name, type. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zone details
cf_delete_zone details
[Cloudflare] DESTRUCTIVE: Delete Zone. Why this is destructive: Deletes the zone; Cloudflare stops answering for the domain. DELETE /zones/. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zone details
cf_get_zone details
[Cloudflare] Zone Details. Returns the zone record, including its status (active, pending, moved), its plan, its nameservers and the account it belongs to. A pending zone means the domain is not yet delegated to Cloudflare, which explains most "the change had no effect" reports. GET /zones/. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones details
cf_list_zones details
[Cloudflare] List Zones. Start here for anything zone-scoped: it returns every zone the token can see, with the zone id the DNS, firewall and cache tools take. Filter by name for one domain, or by account.id to list the zones of one account. GET /zones. Optional filters: name, status, type, account.id, account.name, page, per_page, order, direction, match. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_zone details
cf_update_zone details
[Cloudflare] Edit Zone. Partial update: omitted fields keep their value. PATCH /zones/. Path parameters: zone_id. Send the request body as JSON; Cloudflare documents these fields: paused, plan, type, vanity_name_servers. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
R2
cf_get_r2_object details
cf_get_r2_object details
[Cloudflare] Get Object. The object's BYTES, handed back as a short-lived download link rather than inline: R2 objects are arbitrary files and base64 in a tool result would spend the whole result budget on one of them. Use cf_get_r2_object_metadata when you only need the size, etag or content type. GET /accounts//r2/buckets//objects/. Path parameters: account_id, bucket_name, object_key. This Cloudflare endpoint answers a file rather than JSON, so instead of the bytes you get a JSON envelope with sasUrl (a short-lived read-only download link, valid for about 15 minutes), contentType, suggestedFileName, sizeBytes and expiresAt. Fetch the link before it expires; nothing else in StackJack keeps a copy.
cf_upload_r2_object details
cf_upload_r2_object details
[Cloudflare] DESTRUCTIVE: Upload Object. Why this is destructive: The whole request body is the file, so this writes the object at this path in full - anything already stored there is replaced. Supply the file EITHER as base64 in contentBase64 OR as a public https URL in sourceUrl, never both. StackJack fetches an https URL server-side, refuses plain http, refuses a redirect to a different host and caps the transfer at 25 MB. PUT /accounts//r2/buckets//objects/. Path parameters: account_id, bucket_name, object_key. The whole request body is the file's bytes. Supply it EITHER as base64 in contentBase64 OR as a public https URL in sourceUrl - exactly one of the two. StackJack downloads an https URL server-side and refuses a non-https URL, a redirect to a different host, or anything over 25 MB. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
R2 Bucket Settings
cf_delete_r2_bucket_cors details
cf_delete_r2_bucket_cors details
[Cloudflare] DESTRUCTIVE: Delete Bucket CORS Policy. Why this is destructive: Removes the CORS policy; browser callers start failing pre-flight. DELETE /accounts//r2/buckets//cors. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_disable_r2_bucket_sippy details
cf_disable_r2_bucket_sippy details
[Cloudflare] DESTRUCTIVE: Disable Sippy. Why this is destructive: Turns migration off and discards the stored source credentials. DELETE /accounts//r2/buckets//sippy. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_enable_r2_bucket_sippy details
cf_enable_r2_bucket_sippy details
[Cloudflare] Enable Sippy. Turns on incremental migration from the source bucket; it copies in and deletes nothing. PUT /accounts//r2/buckets//sippy. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: destination, source. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_bucket_cors details
cf_get_r2_bucket_cors details
[Cloudflare] Get Bucket CORS Policy. GET /accounts//r2/buckets//cors. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_bucket_lifecycle details
cf_get_r2_bucket_lifecycle details
[Cloudflare] Get Object Lifecycle Rules. GET /accounts//r2/buckets//lifecycle. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_bucket_local_uploads details
cf_get_r2_bucket_local_uploads details
[Cloudflare] Get Local Uploads Configuration. GET /accounts//r2/buckets//local-uploads. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_bucket_lock details
cf_get_r2_bucket_lock details
[Cloudflare] Get Bucket Lock Rules. GET /accounts//r2/buckets//lock. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_bucket_sippy details
cf_get_r2_bucket_sippy details
[Cloudflare] Get Sippy Configuration. GET /accounts//r2/buckets//sippy. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_r2_bucket_cors details
cf_set_r2_bucket_cors details
[Cloudflare] DESTRUCTIVE: Put Bucket CORS Policy. Why this is destructive: Wholesale replace: the whole CORS rule list is rewritten, so a rule you omit is removed. PUT /accounts//r2/buckets//cors. Path parameters: bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: rules. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_r2_bucket_lifecycle details
cf_set_r2_bucket_lifecycle details
[Cloudflare] DESTRUCTIVE: Put Object Lifecycle Rules. Why this is destructive: Wholesale replace, and lifecycle rules delete stored objects on the schedule they name. PUT /accounts//r2/buckets//lifecycle. Path parameters: bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: rules. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_r2_bucket_local_uploads details
cf_set_r2_bucket_local_uploads details
[Cloudflare] Put Local Uploads Configuration. A single reversible on/off toggle; nothing stored is changed. PUT /accounts//r2/buckets//local-uploads. Path parameters: bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: enabled. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_r2_bucket_lock details
cf_set_r2_bucket_lock details
[Cloudflare] DESTRUCTIVE: Put Bucket Lock Rules. Why this is destructive: Wholesale replace of the retention rule list, and a lock rule cannot be shortened once it applies. PUT /accounts//r2/buckets//lock. Path parameters: bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: rules. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
R2 Buckets
cf_create_r2_bucket details
cf_create_r2_bucket details
[Cloudflare] Create Bucket. Additive, and the plan task rules R2 bucket create false. POST /accounts//r2/buckets. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: locationHint, name, storageClass. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_r2_bucket_by_name details
cf_create_r2_bucket_by_name details
[Cloudflare] Create Bucket (by name). Creates the bucket at the name in the path; it creates and never replaces, so the plan task R2 bucket create false applies. PUT /accounts//r2/buckets/. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_r2_bucket details
cf_delete_r2_bucket details
[Cloudflare] DESTRUCTIVE: Delete Bucket. Why this is destructive: Deletes the bucket. DELETE /accounts//r2/buckets/. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_bucket details
cf_get_r2_bucket details
[Cloudflare] Get Bucket. Reads one bucket by name — R2 addresses buckets by name, not by an id. Returns its creation date, location hint and default storage class. GET /accounts//r2/buckets/. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_metrics details
cf_get_r2_metrics details
[Cloudflare] Get Account-Level Metrics. Account-level R2 storage and object counts, split by standard and infrequent-access class — the read behind a storage-cost question. GET /accounts//r2/metrics. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_r2_buckets details
cf_list_r2_buckets details
[Cloudflare] List Buckets. The first call for anything R2. Returns every bucket in the account with its location and storage class. Paging here is cursor-based rather than page-numbered. GET /accounts//r2/buckets. Path parameters: account_id. Optional filters: name_contains, start_after, per_page, order, direction, cursor. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_r2_bucket_storage_class details
cf_update_r2_bucket_storage_class details
[Cloudflare] Patch Bucket. Changes the default storage class for objects written from now on; existing objects are untouched. PATCH /accounts//r2/buckets/. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
R2 Data Catalog
cf_delete_r2_catalog_metadata details
cf_delete_r2_catalog_metadata details
[Cloudflare] DESTRUCTIVE: Delete R2 catalog metadata. Why this is destructive: Deletes the catalog metadata for the bucket. POST /accounts//r2-catalog//delete. Path parameters: account_id, bucket_name. Optional filters: force. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_disable_r2_catalog details
cf_disable_r2_catalog details
[Cloudflare] DESTRUCTIVE: Disable R2 catalog. Why this is destructive: Turns the catalog off; every Iceberg client reading it loses access. POST /accounts//r2-catalog//disable. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_enable_r2_catalog details
cf_enable_r2_catalog details
[Cloudflare] Enable R2 bucket as a catalog. Additive: turns the catalog on for the bucket. POST /accounts//r2-catalog//enable. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_catalog details
cf_get_r2_catalog details
[Cloudflare] Get R2 catalog details. GET /accounts//r2-catalog/. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_catalog_maintenance_config details
cf_get_r2_catalog_maintenance_config details
[Cloudflare] Get catalog maintenance configuration. GET /accounts//r2-catalog//maintenance-configs. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_catalog_table details
cf_get_r2_catalog_table details
[Cloudflare] Get table details. GET /accounts//r2-catalog//namespaces//tables/. Path parameters: account_id, bucket_name, namespace, table_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_catalog_table_maintenance details
cf_get_r2_catalog_table_maintenance details
[Cloudflare] Get table maintenance configuration. GET /accounts//r2-catalog//namespaces//tables//maintenance-configs. Path parameters: account_id, bucket_name, namespace, table_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_r2_catalog_maintenance_runs details
cf_list_r2_catalog_maintenance_runs details
[Cloudflare] List table maintenance runs. GET /accounts//r2-catalog//namespaces//tables//maintenance-runs. Path parameters: account_id, bucket_name, namespace, table_name. Optional filters: page_size, page_token. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_r2_catalog_namespaces details
cf_list_r2_catalog_namespaces details
[Cloudflare] List namespaces in catalog. GET /accounts//r2-catalog//namespaces. Path parameters: account_id, bucket_name. Optional filters: page_token, page_size, parent, return_uuids, return_details. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_r2_catalog_tables details
cf_list_r2_catalog_tables details
[Cloudflare] List tables in namespace. GET /accounts//r2-catalog//namespaces//tables. Path parameters: account_id, bucket_name, namespace. Optional filters: page_token, page_size, return_uuids, return_details. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_r2_catalogs details
cf_list_r2_catalogs details
[Cloudflare] List R2 catalogs. R2 Data Catalog turns a bucket into an Apache Iceberg catalog. This lists the buckets on which it is enabled; the namespace and table tools walk what is inside one. GET /accounts//r2-catalog. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_queue_r2_catalog_table_maintenance details
cf_queue_r2_catalog_table_maintenance details
[Cloudflare] DESTRUCTIVE: Queue table maintenance. Why this is destructive: Runs compaction or snapshot expiration against the table; expiring a snapshot drops the history it held. POST /accounts//r2-catalog//namespaces//tables//maintenance-configs//queue. Path parameters: account_id, bucket_name, namespace, table_name, configuration_type. Send the request body as JSON; Cloudflare documents these fields: request_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_store_r2_catalog_credential details
cf_store_r2_catalog_credential details
[Cloudflare] DESTRUCTIVE: Store catalog credentials. Why this is destructive: Stores an API token on the catalog for it to act with; it replaces whatever token was stored before. POST /accounts//r2-catalog//credential. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: token. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_r2_catalog_maintenance details
cf_update_r2_catalog_maintenance details
[Cloudflare] Update catalog maintenance configuration. Changes the maintenance schedule only; no maintenance is run by this call. POST /accounts//r2-catalog//maintenance-configs. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: compaction, snapshot_expiration. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_r2_catalog_table_maintenance details
cf_update_r2_catalog_table_maintenance details
[Cloudflare] Update table maintenance configuration. Changes the table maintenance schedule only; no maintenance is run by this call. POST /accounts//r2-catalog//namespaces//tables//maintenance-configs. Path parameters: account_id, bucket_name, namespace, table_name. Send the request body as JSON; Cloudflare documents these fields: compaction, snapshot_expiration. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
R2 Domains
cf_attach_r2_bucket_custom_domain details
cf_attach_r2_bucket_custom_domain details
[Cloudflare] Attach Custom Domain To Bucket. Additive: attaches a domain and changes no existing one. POST /accounts//r2/buckets//domains/custom. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: ciphers, domain, enabled, minTLS, zoneId. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_bucket_custom_domain details
cf_get_r2_bucket_custom_domain details
[Cloudflare] Get Custom Domain Settings. GET /accounts//r2/buckets//domains/custom/. Path parameters: account_id, bucket_name, domain. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_bucket_managed_domain details
cf_get_r2_bucket_managed_domain details
[Cloudflare] Get r2.dev Domain of Bucket. GET /accounts//r2/buckets//domains/managed. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_r2_bucket_custom_domains details
cf_list_r2_bucket_custom_domains details
[Cloudflare] List Custom Domains of Bucket. GET /accounts//r2/buckets//domains/custom. Path parameters: account_id, bucket_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_remove_r2_bucket_custom_domain details
cf_remove_r2_bucket_custom_domain details
[Cloudflare] DESTRUCTIVE: Remove Custom Domain From Bucket. Why this is destructive: Detaches the domain; anything served from that hostname stops resolving. DELETE /accounts//r2/buckets//domains/custom/. Path parameters: bucket_name, account_id, domain. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_r2_bucket_custom_domain details
cf_set_r2_bucket_custom_domain details
[Cloudflare] DESTRUCTIVE: Configure Custom Domain Settings. Why this is destructive: Wholesale replace of the domain settings; an omitted field reverts to its default and can take the domain offline. PUT /accounts//r2/buckets//domains/custom/. Path parameters: account_id, bucket_name, domain. Send the request body as JSON; Cloudflare documents these fields: ciphers, enabled, minTLS. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_r2_bucket_managed_domain details
cf_set_r2_bucket_managed_domain details
[Cloudflare] Update r2.dev Domain of Bucket. A single reversible on/off toggle for the r2.dev domain. PUT /accounts//r2/buckets//domains/managed. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: enabled. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
R2 Event Notifications
cf_delete_r2_event_notification_rules details
cf_delete_r2_event_notification_rules details
[Cloudflare] DESTRUCTIVE: Delete Event Notification Rules. Why this is destructive: Deletes notification rules; downstream consumers stop receiving events. DELETE /accounts//event_notifications/r2//configuration/queues/. Path parameters: queue_id, bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: ruleIds. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_event_notification_rule details
cf_get_r2_event_notification_rule details
[Cloudflare] Get Event Notification Rule. GET /accounts//event_notifications/r2//configuration/queues/. Path parameters: queue_id, bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_r2_event_notification_rules details
cf_list_r2_event_notification_rules details
[Cloudflare] List Event Notification Rules. GET /accounts//event_notifications/r2//configuration. Path parameters: bucket_name, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_r2_event_notification_rule details
cf_set_r2_event_notification_rule details
[Cloudflare] DESTRUCTIVE: Create Event Notification Rule. Why this is destructive: Wholesale replace: the queue rule list is rewritten, so a rule you omit stops firing. PUT /accounts//event_notifications/r2//configuration/queues/. Path parameters: queue_id, bucket_name, account_id. Send the request body as JSON; Cloudflare documents these fields: rules. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
R2 Migration Jobs
cf_create_r2_migration_job details
cf_create_r2_migration_job details
[Cloudflare] DESTRUCTIVE: Create a Storage Class Migration Job. Why this is destructive: Rewrites the storage class of every matching object in the bucket and changes what the customer is billed for storage. POST /accounts//r2/buckets//storage-class-migration-jobs. Path parameters: account_id, bucket_name. Send the request body as JSON; Cloudflare documents these fields: destinationStorageClass, jobType, sourceStorageClass. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_bucket_job details
cf_get_r2_bucket_job details
[Cloudflare] Get Bucket Job. GET /accounts//r2/buckets//jobs/. Path parameters: account_id, bucket_name, job_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_r2_migration_job details
cf_get_r2_migration_job details
[Cloudflare] Get Storage Class Migration Job. GET /accounts//r2/buckets//storage-class-migration-jobs/. Path parameters: account_id, bucket_name, job_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_r2_bucket_jobs details
cf_list_r2_bucket_jobs details
[Cloudflare] List Bucket Jobs. GET /accounts//r2/buckets//jobs. Path parameters: account_id, bucket_name. Optional filters: jobType, status, maxKeys, continuationToken. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_r2_migration_jobs details
cf_list_r2_migration_jobs details
[Cloudflare] List Storage Class Migration Jobs. GET /accounts//r2/buckets//storage-class-migration-jobs. Path parameters: account_id, bucket_name. Optional filters: status, maxKeys, continuationToken. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
R2 Objects
cf_create_r2_temp_credentials details
cf_create_r2_temp_credentials details
[Cloudflare] DESTRUCTIVE: Create Temporary Access Credentials. Why this is destructive: Mints an S3 access key pair for the bucket: a credential mint, which the wiring manifest rules destructive. POST /accounts//r2/temp-access-credentials. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: bucket, objects, parentAccessKeyId, permission, prefixes, ttlSeconds. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_r2_object details
cf_delete_r2_object details
[Cloudflare] DESTRUCTIVE: Delete Object. Why this is destructive: Deletes one object. Deleted R2 objects are not recoverable. DELETE /accounts//r2/buckets//objects/. Path parameters: account_id, bucket_name, object_key. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_r2_objects details
cf_delete_r2_objects details
[Cloudflare] DESTRUCTIVE: Delete Objects or Empty a Bucket. Why this is destructive: Deletes many objects in one call - every key in the list you send, every key under the prefix you name, or EVERY object in the bucket when the prefix is sent as an empty string. Deleted R2 objects are not recoverable. Three modes, chosen by the prefix argument alone, and they are exclusive. OMIT prefix and send a JSON array of object keys as the body: exactly those objects are deleted. Send a NON-EMPTY prefix and no body: every key beginning with it goes. Send prefix as an EMPTY STRING: the whole bucket is emptied - so never pass an empty string meaning "no prefix". Both prefix modes answer with a job descriptor that cf_get_r2_bucket_job polls, and a bucket that still has event notification rules configured refuses with a 409 until they are removed. DELETE /accounts//r2/buckets//objects. Path parameters: account_id, bucket_name. Optional filters: prefix. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_r2_objects details
cf_list_r2_objects details
[Cloudflare] List Objects. Lists object keys and sizes, filtered by prefix and walked with a cursor. It returns metadata only: the object bytes themselves are not available through this connector. GET /accounts//r2/buckets//objects. Path parameters: account_id, bucket_name. Optional filters: per_page, prefix, delimiter, cursor, start_after. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Cloudflare Tunnels
cf_cleanup_tunnel_connections details
cf_cleanup_tunnel_connections details
[Cloudflare] DESTRUCTIVE: Clean up Cloudflare Tunnel connections. Why this is destructive: Disconnects live connector sessions; traffic on them drops until the connector reconnects. DELETE /accounts//cfd_tunnel//connections. Path parameters: account_id, tunnel_id. Optional filters: client_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_tunnel details
cf_create_tunnel details
[Cloudflare] Create a Cloudflare Tunnel. Additive: creates a tunnel and changes no existing one. POST /accounts//cfd_tunnel. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: config_src, name, tunnel_secret. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_tunnel_management_token details
cf_create_tunnel_management_token details
[Cloudflare] DESTRUCTIVE: Get a Cloudflare Tunnel management token. Why this is destructive: Mints a scoped management JWT for the tunnel: a credential mint, which the wiring manifest rules destructive whatever the verb reads like. POST /accounts//cfd_tunnel//management. Path parameters: account_id, tunnel_id. Send the request body as JSON; Cloudflare documents these fields: resources. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_tunnel details
cf_delete_tunnel details
[Cloudflare] DESTRUCTIVE: Delete a Cloudflare Tunnel. Why this is destructive: Deletes the tunnel; every hostname routed through it stops resolving and the connector loses its credential. DELETE /accounts//cfd_tunnel/. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_tunnel details
cf_get_tunnel details
[Cloudflare] Get a Cloudflare Tunnel. Reads one tunnel with its status and active connections. A tunnel showing healthy with no connections means cloudflared is not running where you think it is. GET /accounts//cfd_tunnel/. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_tunnel_configuration details
cf_get_tunnel_configuration details
[Cloudflare] Get Tunnel configuration. Returns the ingress rule list — which hostname maps to which internal service. Read it before setting a configuration, because that write replaces the whole list. GET /accounts//cfd_tunnel//configurations. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_tunnel_connector details
cf_get_tunnel_connector details
[Cloudflare] Get Cloudflare Tunnel connector. GET /accounts//cfd_tunnel//connectors/. Path parameters: account_id, tunnel_id, connector_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_tunnel_token details
cf_get_tunnel_token details
[Cloudflare] Get a Cloudflare Tunnel token. Returns the tunnel run token, the value cloudflared authenticates with. Treat the response as a credential: anyone holding it can run a connector for this tunnel. GET /accounts//cfd_tunnel//token. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tunnel_connections details
cf_list_tunnel_connections details
[Cloudflare] List Cloudflare Tunnel connections. GET /accounts//cfd_tunnel//connections. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tunnels details
cf_list_tunnels details
[Cloudflare] List Cloudflare Tunnels. The first call for Cloudflare Tunnel. Returns each tunnel with its status and connector count; is_deleted=false hides tunnels that were removed but still appear in history. GET /accounts//cfd_tunnel. Path parameters: account_id. Optional filters: name, is_deleted, existed_at, uuid, was_active_at, was_inactive_at, include_prefix, exclude_prefix, status, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_tunnel_configuration details
cf_set_tunnel_configuration details
[Cloudflare] DESTRUCTIVE: Update Tunnel configuration. Why this is destructive: Wholesale replace: the whole ingress rule list is rewritten, so any rule you omit is deleted and its hostname stops routing. PUT /accounts//cfd_tunnel//configurations. Path parameters: account_id, tunnel_id. Send the request body as JSON; Cloudflare documents these fields: config. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_tunnel details
cf_update_tunnel details
[Cloudflare] Update a Cloudflare Tunnel. Partial update of the tunnel name or secret; omitted fields keep their value. PATCH /accounts//cfd_tunnel/. Path parameters: tunnel_id, account_id. Send the request body as JSON; Cloudflare documents these fields: name, tunnel_secret. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Tunnel Routes
cf_create_tunnel_route details
cf_create_tunnel_route details
[Cloudflare] Create a tunnel route. Additive: adds a route and changes no existing one. POST /accounts//teamnet/routes. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: comment, network, tunnel_id, virtual_network_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_tunnel_route_by_cidr details
cf_create_tunnel_route_by_cidr details
[Cloudflare] Create a tunnel route (CIDR Endpoint). Additive: adds a route for the CIDR you name. POST /accounts//teamnet/routes/network/. Path parameters: ip_network_encoded, account_id. Send the request body as JSON; Cloudflare documents these fields: comment, tunnel_id, virtual_network_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_delete_tunnel_route details
cf_delete_tunnel_route details
[Cloudflare] DESTRUCTIVE: Delete a tunnel route. Why this is destructive: Deletes the route; the private network behind it stops being reachable. DELETE /accounts//teamnet/routes/. Path parameters: route_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_tunnel_route_by_cidr details
cf_delete_tunnel_route_by_cidr details
[Cloudflare] DESTRUCTIVE: Delete a tunnel route (CIDR Endpoint). Why this is destructive: Deletes the route for that CIDR; the private network behind it stops being reachable. DELETE /accounts//teamnet/routes/network/. Path parameters: ip_network_encoded, account_id. Optional filters: virtual_network_id, tun_type, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_get_tunnel_route details
cf_get_tunnel_route details
[Cloudflare] Get tunnel route. GET /accounts//teamnet/routes/. Path parameters: account_id, route_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_tunnel_route_by_ip details
cf_get_tunnel_route_by_ip details
[Cloudflare] Get tunnel route by IP. GET /accounts//teamnet/routes/ip/. Path parameters: ip, account_id. Optional filters: virtual_network_id, default_virtual_network_fallback. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tunnel_routes details
cf_list_tunnel_routes details
[Cloudflare] List tunnel routes. The private IP ranges reachable through the tunnels on this account, each bound to a tunnel and a virtual network. This is the read behind "why can this site not reach that subnet?". GET /accounts//teamnet/routes. Path parameters: account_id. Optional filters: comment, is_deleted, network_subset, network_superset, existed_at, tunnel_id, route_id, tun_types, virtual_network_id, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_tunnel_route details
cf_update_tunnel_route details
[Cloudflare] Update a tunnel route. Partial update; omitted fields keep their value. PATCH /accounts//teamnet/routes/. Path parameters: route_id, account_id. Send the request body as JSON; Cloudflare documents these fields: comment, network, tunnel_id, virtual_network_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Tunnels
cf_list_account_tunnels details
cf_list_account_tunnels details
[Cloudflare] List All Tunnels. The account-wide tunnel inventory across every tunnel TYPE. cf_list_tunnels is narrower and older: it lists Cloudflare Tunnel (cfd_tunnel) only, which is what most tunnel tools take an id from. GET /accounts//tunnels. Path parameters: account_id. Optional filters: name, is_deleted, existed_at, uuid, was_active_at, was_inactive_at, include_prefix, exclude_prefix, tun_types, status, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Virtual Networks
cf_create_virtual_network details
cf_create_virtual_network details
[Cloudflare] Create a virtual network. Additive: creates a virtual network and changes no existing one. POST /accounts//teamnet/virtual_networks. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: comment, is_default, is_default_network, name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_virtual_network details
cf_delete_virtual_network details
[Cloudflare] DESTRUCTIVE: Delete a virtual network. Why this is destructive: Deletes the virtual network and every route scoped to it. DELETE /accounts//teamnet/virtual_networks/. Path parameters: virtual_network_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_virtual_network details
cf_get_virtual_network details
[Cloudflare] Get a virtual network. GET /accounts//teamnet/virtual_networks/. Path parameters: account_id, virtual_network_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_virtual_networks details
cf_list_virtual_networks details
[Cloudflare] List virtual networks. GET /accounts//teamnet/virtual_networks. Path parameters: account_id. Optional filters: id, name, is_default, is_default_network, is_deleted. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_virtual_network details
cf_update_virtual_network details
[Cloudflare] Update a virtual network. Partial update; omitted fields keep their value. PATCH /accounts//teamnet/virtual_networks/. Path parameters: account_id, virtual_network_id. Send the request body as JSON; Cloudflare documents these fields: comment, is_default_network, name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
WARP Connector
cf_create_warp_connector details
cf_create_warp_connector details
[Cloudflare] Create a Warp Connector Tunnel. Additive: creates a WARP Connector tunnel and changes no existing one. POST /accounts//warp_connector. Path parameters: account_id. Send the request body as JSON; Cloudflare documents these fields: ha, name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_warp_connector details
cf_delete_warp_connector details
[Cloudflare] DESTRUCTIVE: Delete a Warp Connector Tunnel. Why this is destructive: Deletes the WARP Connector tunnel; the site behind it loses connectivity. DELETE /accounts//warp_connector/. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_warp_connector details
cf_get_warp_connector details
[Cloudflare] Get a Warp Connector Tunnel. GET /accounts//warp_connector/. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_warp_connector_configuration details
cf_get_warp_connector_configuration details
[Cloudflare] Get WARP Connector HA configuration. GET /accounts//warp_connector//configurations. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_warp_connector_connector details
cf_get_warp_connector_connector details
[Cloudflare] Get WARP Connector Tunnel connector. GET /accounts//warp_connector//connectors/. Path parameters: account_id, tunnel_id, connector_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_warp_connector_token details
cf_get_warp_connector_token details
[Cloudflare] Get a Warp Connector Tunnel token. Returns the WARP Connector run token. Treat the response as a credential: anyone holding it can attach a connector to this tunnel. GET /accounts//warp_connector//token. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_warp_connector_connections details
cf_list_warp_connector_connections details
[Cloudflare] List WARP Connector Tunnel connections. GET /accounts//warp_connector//connections. Path parameters: account_id, tunnel_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_warp_connectors details
cf_list_warp_connectors details
[Cloudflare] List Warp Connector Tunnels. WARP Connector tunnels are the site-to-site half of Cloudflare Tunnel: a whole network behind one connector rather than a published hostname. GET /accounts//warp_connector. Path parameters: account_id. Optional filters: name, is_deleted, existed_at, uuid, was_active_at, was_inactive_at, include_prefix, exclude_prefix, status, per_page, page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_warp_connector_configuration details
cf_set_warp_connector_configuration details
[Cloudflare] DESTRUCTIVE: Update WARP Connector HA configuration. Why this is destructive: Wholesale replace of the high-availability configuration; anything you omit is reset. PUT /accounts//warp_connector//configurations. Path parameters: account_id, tunnel_id. Send the request body as JSON; Cloudflare documents these fields: config, ha_mode. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_trigger_warp_connector_failover details
cf_trigger_warp_connector_failover details
[Cloudflare] DESTRUCTIVE: Trigger a manual failover for a WARP Connector Tunnel. Why this is destructive: Dispatches a live failover: traffic moves to another connector and sessions on the current one break. PUT /accounts//warp_connector//failover. Path parameters: account_id, tunnel_id. Send the request body as JSON; Cloudflare documents these fields: client_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_warp_connector details
cf_update_warp_connector details
[Cloudflare] Update a Warp Connector Tunnel. Partial update of the name or secret; omitted fields keep their value. PATCH /accounts//warp_connector/. Path parameters: account_id, tunnel_id. Send the request body as JSON; Cloudflare documents these fields: name, tunnel_secret. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Members
cf_create_organizations_member details
cf_create_organizations_member details
[Cloudflare] DESTRUCTIVE: Create organization member. Why this is destructive: Changes a membership, role, policy or permission - who or what may reach the resource, or what they may do with it. It takes effect immediately. POST /organizations//members. Path parameters: organization_id. Send the request body as JSON; Cloudflare documents these fields: member. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_organizations_member details
cf_delete_organizations_member details
[Cloudflare] DESTRUCTIVE: Delete organization member. Why this is destructive: Deletes the resource this path names. Cloudflare removes it on success and the API offers no undo for it here. DELETE /organizations//members/. Path parameters: organization_id, member_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_organizations_member details
cf_get_organizations_member details
[Cloudflare] Get organization member. GET /organizations//members/. Path parameters: organization_id, member_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_organizations_members details
cf_list_organizations_members details
[Cloudflare] List organization members. Start here before any member write: the member id every other member tool takes is only returned by this list. The user.email filters (exact, contains, startsWith, endsWith) are how you find one person without paging the whole organization. GET /organizations//members. Path parameters: organization_id. Optional filters: status, user.email, user.email.contains, user.email.startsWith, user.email.endsWith, page_token, page_size. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Members:batchCreate
cf_create_organizations_members_batch details
cf_create_organizations_members_batch details
[Cloudflare] Batch create organization members. Additive: creates a new record and changes no existing one. One call adds many members. Cloudflare applies the batch as a unit and answers with the created members; there is no partial-success mode to inspect, so send a batch you are willing to have applied whole. POST /organizations//members:batchCreate. Path parameters: organization_id. Send the request body as JSON; Cloudflare documents these fields: members. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Tenant Accounts
cf_list_organizations_accounts details
cf_list_organizations_accounts details
[Cloudflare] Get organization accounts. GET /organizations//accounts. Path parameters: organization_id. Optional filters: account_pubname, account_pubname.startsWith, account_pubname.endsWith, account_pubname.contains, name, name.startsWith, name.endsWith, name.contains, order_by, direction, include_tags, include_total, page_token, page_size. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Tenant Billable
cf_get_organization_billable_usage details
cf_get_organization_billable_usage details
[Cloudflare] Get Organization Usage (Version 2, Alpha, Restricted). Cloudflare labels this endpoint Version 2, ALPHA and RESTRICTED in its own document: the contract may change without notice and the call 403s unless the tenant contract enables it. from/to bound the usage window. GET /organizations//billable/usage. Path parameters: organization_id. Optional filters: from, to. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Tenant Logs
cf_get_organization_audit_log_entry_history details
cf_get_organization_audit_log_entry_history details
[Cloudflare] Get resource change history from an organization audit log entry (Version 2). GET /organizations//logs/audit//history. Path parameters: organization_id, id. Cloudflare REQUIRES these query parameters and answers 400 without it: action_time, since, before. Optional filters: direction, limit, cursor. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_organizations_logs_audits details
cf_list_organizations_logs_audits details
[Cloudflare] Get organization audit logs (Version 2). GET /organizations//logs/audit. Path parameters: organization_id. Cloudflare REQUIRES these query parameters and answers 400 without it: since, before. Optional filters: action_result, action_type, actor_context, actor_email, actor_id, actor_ip_address, actor_token_id, actor_token_name, actor_type, id, raw_cf_ray_id, raw_method, raw_status_code, raw_uri, resource_id, resource_product, resource_type, resource_scope, action_result.not, action_type.not, actor_context.not, actor_email.not, actor_id.not, actor_ip_address.not, actor_token_id.not, actor_token_name.not, actor_type.not, id.not, raw_cf_ray_id.not, raw_method.not, raw_status_code.not, raw_uri.not, resource_id.not, resource_product.not, resource_type.not, resource_scope.not, direction, limit, cursor. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Tenant Organizations
cf_create_organization details
cf_create_organization details
[Cloudflare] Create organization. Additive: creates a new record and changes no existing one. POST /organizations. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_organization details
cf_delete_organization details
[Cloudflare] DESTRUCTIVE: Delete organization. Why this is destructive: Deletes the organization itself. Every account, member and share under it goes with it and the API offers no undo; a tenant provider does this only after the accounts have been moved or closed. DELETE /organizations/. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_organization details
cf_get_organization details
[Cloudflare] Get organization. GET /organizations/. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tenant_organizations details
cf_list_tenant_organizations details
[Cloudflare] List organizations the user has access to. The Tenant API root list: every organization this API token can see, which is where a tenant-provisioning session starts. The account-scoped twin cf_list_organizations answers the organizations INSIDE one account and takes an account id. GET /organizations. Optional filters: id, name, name.startsWith, name.endsWith, name.contains, containing.account, containing.user, containing.organization, parent.id, page_token, page_size. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_organization details
cf_set_organization details
[Cloudflare] DESTRUCTIVE: Modify organization. Why this is destructive: Wholesale replace: the organization record is rewritten from the body, so a field you omit reverts to its default rather than keeping its current value. Read it with cf_get_organization first and send the whole object back. PUT /organizations/. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Tenant Profile
cf_get_organizations_profiles details
cf_get_organizations_profiles details
[Cloudflare] Get organization profile. GET /organizations//profile. Path parameters: organization_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_organizations_profile details
cf_set_organizations_profile details
[Cloudflare] DESTRUCTIVE: Modify organization profile. Why this is destructive: Wholesale replace of the organization profile; omitted fields revert. Read cf_get_organizations_profiles first. PUT /organizations//profile. Path parameters: organization_id. Send the request body as JSON; Cloudflare documents these fields: business_address, business_email, business_name, business_phone, external_metadata. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Tenant Provisioning
cf_add_tenant_custom_nameserver details
cf_add_tenant_custom_nameserver details
[Cloudflare] Add Tenant Custom Nameserver. Additive: adds a nameserver to the tenant set. POST /tenants//custom_ns. Path parameters: tenant_tag. Send the request body as JSON; Cloudflare documents these fields: ns_name, ns_set. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_tenant_custom_nameserver details
cf_delete_tenant_custom_nameserver details
[Cloudflare] DESTRUCTIVE: Delete Tenant Custom Nameserver. Why this is destructive: Removes a custom nameserver; zones delegated to it stop resolving. DELETE /tenants//custom_ns/. Path parameters: custom_ns_id, tenant_tag. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_tenant details
cf_get_tenant details
[Cloudflare] Get tenant. GET /tenants/. Path parameters: tenant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tenant_account_types details
cf_list_tenant_account_types details
[Cloudflare] Get tenant account types. GET /tenants//account_types. Path parameters: tenant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tenant_accounts details
cf_list_tenant_accounts details
[Cloudflare] List tenant accounts. The customer accounts provisioned under a partner tenant. Use it to walk a partner estate; the account id it returns is the one every account-scoped tool takes. GET /tenants//accounts. Path parameters: tenant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tenant_custom_nameservers details
cf_list_tenant_custom_nameservers details
[Cloudflare] List Tenant Custom Nameservers. GET /tenants//custom_ns. Path parameters: tenant_tag. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tenant_entitlements details
cf_list_tenant_entitlements details
[Cloudflare] List tenant entitlements. GET /tenants//entitlements. Path parameters: tenant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_tenant_memberships details
cf_list_tenant_memberships details
[Cloudflare] List tenant memberships. GET /tenants//memberships. Path parameters: tenant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_user_tenants details
cf_list_user_tenants details
[Cloudflare] List user tenants. Tells you immediately whether the stored token has partner Tenant access at all. An empty result means it does not, which is the ordinary case — the tenant surface is a Channel and Alliance partner mechanism. GET /user/tenants. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Tenant Shares
cf_list_organizations_shares details
cf_list_organizations_shares details
Access Apps
cf_create_access_app details
cf_create_access_app details
[Cloudflare] Add an Access application. Additive: it creates one new application and changes no existing one. The application is live as soon as Cloudflare stores it, so a self_hosted app whose domain is already serving traffic starts requiring an Access login on the next request. The app type decides the whole body shape. POST /accounts//access/apps. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_access_apps_ca details
cf_create_access_apps_ca details
[Cloudflare] Create a short-lived certificate CA. Additive: it generates a new short-lived certificate CA and public key for this application. An application can hold one CA, so read cf_get_access_apps_cas first - and the new public key must be installed on every target host before browser SSH works. POST /accounts//access/apps//ca. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_access_apps_policy details
cf_create_access_apps_policy details
[Cloudflare] DESTRUCTIVE: Create an Access application policy. Why this is destructive: An Access policy is what decides who may reach the customer's internal application: change it and the next request from a real user is allowed or refused by the new rule, with no deploy step in between. This one creates a policy scoped exclusively to this application. Cloudflare itself recommends creating a REUSABLE policy with cf_create_access_policy and referencing its id from the application instead. POST /accounts//access/apps//policies. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_access_app details
cf_create_zones_access_app details
[Cloudflare] Add an Access application. Additive: it creates one application on this zone and changes no existing one. The application takes effect immediately, so a self_hosted app on a domain already serving traffic starts requiring an Access login on the next request. ZONE-scoped: this route reaches the Access applications of ONE zone, not the whole account. Use the account-level twin for an account-wide view. POST /zones//access/apps. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_access_apps_ca details
cf_create_zones_access_apps_ca details
[Cloudflare] Create a short-lived certificate CA. Additive: it generates a new short-lived certificate CA and public key for this application. The new public key must reach every target host before browser SSH works. POST /zones//access/apps//ca. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_access_apps_policy details
cf_create_zones_access_apps_policy details
[Cloudflare] DESTRUCTIVE: Create an Access policy. Why this is destructive: An Access policy is what decides who may reach the customer's internal application: change it and the next request from a real user is allowed or refused by the new rule, with no deploy step in between. This creates a policy on a zone-level application. POST /zones//access/apps//policies. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_app details
cf_delete_access_app details
[Cloudflare] DESTRUCTIVE: Delete an Access application. Why this is destructive: The application stops existing, and with it every policy scoped exclusively to it. Users who reach the domain are no longer challenged by Access at all, so whatever the origin serves is exposed to anyone who can route to it. There is no undo. DELETE /accounts//access/apps/. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_apps_ca details
cf_delete_access_apps_ca details
[Cloudflare] DESTRUCTIVE: Delete a short-lived certificate CA. Why this is destructive: The short-lived certificate CA for this application is destroyed. Every SSH certificate it signed stops validating, so users mid-session lose access to the target hosts, and the hosts keep trusting a CA public key that no longer signs anything until it is replaced. DELETE /accounts//access/apps//ca. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_apps_policy details
cf_delete_access_apps_policy details
[Cloudflare] DESTRUCTIVE: Delete an Access application policy. Why this is destructive: The policy is removed from the application. If it was the last policy allowing a group of users in, they lose access on their next request; if it was the only DENY, whoever it kept out is now allowed in by the remaining policies. A reusable policy is deleted with cf_delete_access_policy instead - this route only removes the app-scoped one. DELETE /accounts//access/apps//policies/. Path parameters: app_id, policy_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_access_app details
cf_delete_zones_access_app details
[Cloudflare] DESTRUCTIVE: Delete an Access application. Why this is destructive: The application stops existing, along with every policy scoped exclusively to it, and the domain it protected is no longer challenged by Access at all. There is no undo. DELETE /zones//access/apps/. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_access_apps_ca details
cf_delete_zones_access_apps_ca details
[Cloudflare] DESTRUCTIVE: Delete a short-lived certificate CA. Why this is destructive: The short-lived certificate CA for this application is destroyed, every SSH certificate it signed stops validating, and the target hosts keep trusting a CA public key that no longer signs anything until it is replaced. DELETE /zones//access/apps//ca. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_access_apps_policy details
cf_delete_zones_access_apps_policy details
[Cloudflare] DESTRUCTIVE: Delete an Access policy. Why this is destructive: The policy is removed from the application. Losing the last allow rule locks the application's users out; losing a deny rule lets whoever it excluded back in. DELETE /zones//access/apps//policies/. Path parameters: policy_id, app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_app details
cf_get_access_app details
[Cloudflare] Get an Access application. The single-application read behind cf_list_access_apps, including the app's inline policies, its allowed identity providers and (for a SaaS app) its saas_app block. GET /accounts//access/apps/. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_apps_cas details
cf_get_access_apps_cas details
[Cloudflare] Get a short-lived certificate CA. Returns the CA and its PUBLIC key for one application - the key an administrator pastes into the target host's trusted-user-CA configuration. GET /accounts//access/apps//ca. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_apps_policy details
cf_get_access_apps_policy details
[Cloudflare] Get an Access application policy. Fetches one policy of an application, whether it is owned exclusively by the app or a reusable policy the app references. GET /accounts//access/apps//policies/. Path parameters: app_id, policy_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_apps_user_policy_checks details
cf_get_access_apps_user_policy_checks details
[Cloudflare] Test Access policies. A DRY RUN, despite the vendor calling it a test: it evaluates this application's policies for the calling identity and reports which ones matched. It changes nothing and grants nothing. GET /accounts//access/apps//user_policy_checks. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_access_app details
cf_get_zones_access_app details
[Cloudflare] Get an Access application. The zone-scoped single-application read, including the app's inline policies and its saas_app block when it is a SaaS application. GET /zones//access/apps/. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_access_apps_cas details
cf_get_zones_access_apps_cas details
[Cloudflare] Get a short-lived certificate CA. Returns the CA and its PUBLIC key for one zone-level application - the key that goes into the target host's trusted-user-CA configuration. GET /zones//access/apps//ca. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_access_apps_policy details
cf_get_zones_access_apps_policy details
[Cloudflare] Get an Access policy. Fetches a single policy of a zone-level Access application. GET /zones//access/apps//policies/. Path parameters: policy_id, app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_access_apps_user_policy_checks details
cf_get_zones_access_apps_user_policy_checks details
[Cloudflare] Test Access policies. A DRY RUN: it evaluates the zone-level application's policies for the calling identity and reports which matched. It changes nothing and grants nothing. GET /zones//access/apps//user_policy_checks. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_apps details
cf_list_access_apps details
[Cloudflare] List Access applications. Account-scoped: Access applications live on the account, and this is the route Cloudflare's current documentation uses. This is the reach-first read of the whole Access surface: every other apps tool takes its app_id (the uid Cloudflare returns) from here, and each row carries the app type (self_hosted, saas, ssh, vnc, app_launcher, warp, biso, bookmark, infrastructure, rdp, mcp), its domain and its inline policies. The aud value is the application audience tag an Access JWT is issued for. GET /accounts//access/apps. Path parameters: account_id. Optional filters: name, domain, aud, target_attributes, exact, search, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_apps_cas details
cf_list_access_apps_cas details
[Cloudflare] List short-lived certificate CAs. A short-lived certificate CA is what signs the ephemeral SSH certificates Access issues for a browser-SSH application; the response is the CA's PUBLIC key, never a private key. Each row names the app_id whose CA it is. GET /accounts//access/apps/ca. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_apps_policies details
cf_list_access_apps_policies details
[Cloudflare] List Access application policies. Lists the policies attached to ONE application, both the policies owned exclusively by it and the reusable policies it references. Each row carries the decision (allow, deny, non_identity or bypass), its precedence and its include, exclude and require rules. GET /accounts//access/apps//policies. Path parameters: app_id, account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones_access_apps details
cf_list_zones_access_apps details
[Cloudflare] List Access Applications. ZONE-scoped: this route reaches the Access applications of ONE zone, not the whole account. Use the account-level twin for an account-wide view. The zone route offers a smaller application shape than the account one (eight types, no infrastructure or MCP applications) and no filters at all. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/apps. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones_access_apps_cas details
cf_list_zones_access_apps_cas details
[Cloudflare] List short-lived certificate CAs. The zone-scoped list of short-lived certificate CAs and their PUBLIC keys, one per browser-SSH application in this zone. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/apps/ca. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones_access_apps_policies details
cf_list_zones_access_apps_policies details
[Cloudflare] List Access policies. Lists the policies attached to one zone-level application, with each policy's decision, precedence and rule lists. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/apps//policies. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_make_reusable_access_apps_policies details
cf_make_reusable_access_apps_policies details
[Cloudflare] DESTRUCTIVE: Convert an Access application policy to a reusable policy. Why this is destructive: This conversion is ONE-WAY and Cloudflare documents no reverse. The policy stops being owned by this application and becomes an account-level reusable policy, so every later edit has to go through cf_set_access_policy - and an edit made there then changes every application that references it, not just this one. Takes no request body: the path alone names the policy to convert. PUT /accounts//access/apps//policies//make_reusable. Path parameters: app_id, policy_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_revoke_access_app_tokens details
cf_revoke_access_app_tokens details
[Cloudflare] DESTRUCTIVE: Revoke application tokens. Why this is destructive: It revokes ALL tokens issued for this application, and it mints nothing. Every user with a live Access session for the app is signed out immediately and has to authenticate again at the identity provider; service tokens presented afterwards are refused the same way. Use it when a session is believed compromised, not as routine maintenance. POST /accounts//access/apps//revoke_tokens. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_revoke_zones_access_app_tokens details
cf_revoke_zones_access_app_tokens details
[Cloudflare] DESTRUCTIVE: Revoke application tokens. Why this is destructive: It revokes ALL tokens issued for this application and mints nothing. Every live Access session for the app ends at once and each user has to authenticate again. POST /zones//access/apps//revoke_tokens. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_app details
cf_set_access_app details
[Cloudflare] DESTRUCTIVE: Update an Access application. Why this is destructive: A PUT replaces the WHOLE application from the body. A field you leave out is cleared, not kept - omitting policies detaches every policy from the app, and omitting allowed_idps drops the identity provider restriction. Read the app with cf_get_access_app first and send it back changed. PUT /accounts//access/apps/. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_apps_policy details
cf_set_access_apps_policy details
[Cloudflare] DESTRUCTIVE: Update an Access application policy. Why this is destructive: An Access policy is what decides who may reach the customer's internal application: change it and the next request from a real user is allowed or refused by the new rule, with no deploy step in between. A PUT replaces the whole policy from the body, so an include or exclude rule you leave out is deleted - omit the include array's service_token rule and every machine client using that token is locked out on the next call. PUT /accounts//access/apps//policies/. Path parameters: app_id, policy_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_apps_setting details
cf_set_access_apps_setting details
[Cloudflare] DESTRUCTIVE: Update Access application settings. Why this is destructive: A PUT replaces the whole settings object, so a field you omit falls back to Cloudflare's default rather than keeping its stored value. Use cf_update_access_apps_setting when you only mean to change one of them. PUT /accounts//access/apps//settings. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_access_app details
cf_set_zones_access_app details
[Cloudflare] DESTRUCTIVE: Update an Access application. Why this is destructive: A PUT replaces the WHOLE application from the body: omit policies and every policy detaches from the app, omit allowed_idps and the identity provider restriction is gone. Read it with cf_get_zones_access_app first and send it back changed. PUT /zones//access/apps/. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_access_apps_policy details
cf_set_zones_access_apps_policy details
[Cloudflare] DESTRUCTIVE: Update an Access policy. Why this is destructive: An Access policy is what decides who may reach the customer's internal application: change it and the next request from a real user is allowed or refused by the new rule, with no deploy step in between. A PUT replaces the whole policy from the body, so any include, exclude or require rule you leave out is deleted. PUT /zones//access/apps//policies/. Path parameters: policy_id, app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_access_apps_setting details
cf_set_zones_access_apps_setting details
[Cloudflare] DESTRUCTIVE: Update application settings. Why this is destructive: A PUT replaces the whole settings object, so a field you omit falls back to Cloudflare's default instead of keeping its stored value. PUT /zones//access/apps//settings. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_access_apps_setting details
cf_update_access_apps_setting details
[Cloudflare] Update Access application settings. Partial update: Cloudflare applies only the fields present in the body and leaves the rest alone. Both fields loosen browser protections - allow_iframe lets the app be framed and skip_interstitial removes the click-through Access shows before an identity redirect. PATCH /accounts//access/apps//settings. Path parameters: app_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_zones_access_apps_setting details
cf_update_zones_access_apps_setting details
[Cloudflare] Update application settings. Partial update: only the fields you send change. Both of them loosen browser protections - allow_iframe permits framing and skip_interstitial removes the click-through before an identity redirect. PATCH /zones//access/apps//settings. Path parameters: app_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Authenticator Device Aaguids
cf_list_access_authenticator_device_aaguids details
cf_list_access_authenticator_device_aaguids details
[Cloudflare] List authenticator device AAGUIDs. An AAGUID identifies a MODEL of hardware authenticator (a YubiKey 5, a Windows Hello platform key). This is the catalogue Cloudflare matches against when an Access MFA policy restricts sign-in to particular device models; it describes no customer's own keys and carries no key material. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/authenticator_device_aaguids. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Bookmarks
cf_create_access_bookmark details
cf_create_access_bookmark details
[Cloudflare] Create a Bookmark application. Additive: it publishes one new App Launcher tile and changes no existing one. Cloudflare replaced Bookmark applications with ordinary Access applications of type bookmark: create one with cf_create_access_app and list them with cf_list_access_apps. Note the unusual contract: the CALLER chooses the bookmark_id and sends it in the path, so a POST to an id that already exists overwrites that bookmark rather than creating a second one. POST /accounts//access/bookmarks/. Path parameters: bookmark_id, account_id. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_delete_access_bookmark details
cf_delete_access_bookmark details
[Cloudflare] DESTRUCTIVE: Delete a Bookmark application. Why this is destructive: The bookmark tile disappears from the App Launcher for everyone in the organization. Nothing behind the link changes - the link itself is simply no longer published. Cloudflare replaced Bookmark applications with ordinary Access applications of type bookmark: create one with cf_create_access_app and list them with cf_list_access_apps. Cloudflare declares an empty JSON body on this operation, so StackJack sends none. DELETE /accounts//access/bookmarks/. Path parameters: bookmark_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_get_access_bookmark details
cf_get_access_bookmark details
[Cloudflare] Get a Bookmark application. Cloudflare replaced Bookmark applications with ordinary Access applications of type bookmark: create one with cf_create_access_app and list them with cf_list_access_apps. GET /accounts//access/bookmarks/. Path parameters: bookmark_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_list_access_bookmarks details
cf_list_access_bookmarks details
[Cloudflare] List Bookmark applications. Cloudflare replaced Bookmark applications with ordinary Access applications of type bookmark: create one with cf_create_access_app and list them with cf_list_access_apps. A bookmark is a tile in the Access App Launcher that links out to a site Access does not itself protect. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/bookmarks. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_set_access_bookmark details
cf_set_access_bookmark details
[Cloudflare] DESTRUCTIVE: Update a Bookmark application. Why this is destructive: A PUT replaces the whole bookmark from the body, so a field you leave out is cleared rather than kept - and the tile it publishes changes for every user at once. Cloudflare replaced Bookmark applications with ordinary Access applications of type bookmark: create one with cf_create_access_app and list them with cf_list_access_apps. PUT /accounts//access/bookmarks/. Path parameters: bookmark_id, account_id. Send the request body as JSON, following Cloudflare's documented sample for this endpoint. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
Access Certificates
cf_create_access_certificate details
cf_create_access_certificate details
[Cloudflare] Add an mTLS certificate. Additive: it stores one new root certificate and changes no existing one. The certificate only starts being checked on the hostnames you list in associated_hostnames, so a create with none is inert until cf_set_access_certificate or cf_set_access_certificates_setting arms it. POST /accounts//access/certificates. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_access_certificate details
cf_create_zones_access_certificate details
[Cloudflare] Add an mTLS certificate. Additive: it stores one new root certificate on this zone and changes no existing one. It is inert until a hostname is associated with it. POST /zones//access/certificates. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_certificate details
cf_delete_access_certificate details
[Cloudflare] DESTRUCTIVE: Delete an mTLS certificate. Why this is destructive: The root certificate is removed from the account. Any policy rule that admitted users by a certificate signed by this CA stops matching, so those clients are refused on their next request. There is no undo and the PEM has to be re-uploaded to recover. DELETE /accounts//access/certificates/. Path parameters: certificate_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_access_certificate details
cf_delete_zones_access_certificate details
[Cloudflare] DESTRUCTIVE: Delete an mTLS certificate. Why this is destructive: The root certificate is removed from the zone, and any policy rule that admitted clients by a certificate from this CA stops matching. There is no undo. DELETE /zones//access/certificates/. Path parameters: certificate_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_certificate details
cf_get_access_certificate details
[Cloudflare] Get an mTLS certificate. An mTLS root certificate is the CA Access checks a client certificate against, so a policy rule of certificate or common_name can admit a device by the certificate it presents. Returns one certificate with its fingerprint, expiry and associated_hostnames. GET /accounts//access/certificates/. Path parameters: certificate_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_access_certificate details
cf_get_zones_access_certificate details
[Cloudflare] Get an mTLS certificate. An mTLS root certificate is the CA Access checks a client certificate against, so a policy rule of certificate or common_name can admit a device by the certificate it presents. The zone-scoped single-certificate read. GET /zones//access/certificates/. Path parameters: certificate_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_certificates details
cf_list_access_certificates details
[Cloudflare] List mTLS certificates. An mTLS root certificate is the CA Access checks a client certificate against, so a policy rule of certificate or common_name can admit a device by the certificate it presents. The reach-first read of the mTLS lane: every other certificate tool takes its certificate_id from here, and each row carries the fingerprint, the expiry and the associated_hostnames the certificate is armed on. GET /accounts//access/certificates. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_certificates_settings details
cf_list_access_certificates_settings details
[Cloudflare] List all mTLS hostname settings. The per-hostname half of the mTLS lane: for each hostname it reports whether a client certificate is requested at all (china_network, client_certificate_forwarding) rather than which CA is trusted. Certificates themselves are cf_list_access_certificates. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/certificates/settings. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones_access_certificates details
cf_list_zones_access_certificates details
[Cloudflare] List mTLS certificates. An mTLS root certificate is the CA Access checks a client certificate against, so a policy rule of certificate or common_name can admit a device by the certificate it presents. ZONE-scoped twin of cf_list_access_certificates: it reaches only the certificates held on this one zone. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/certificates. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones_access_certificates_settings details
cf_list_zones_access_certificates_settings details
[Cloudflare] List all mTLS hostname settings. The per-hostname client-certificate settings of ONE zone - whether a certificate is requested and whether it is forwarded to the origin. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/certificates/settings. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_certificate details
cf_set_access_certificate details
[Cloudflare] DESTRUCTIVE: Update an mTLS certificate. Why this is destructive: A PUT replaces the certificate record from the body, and associated_hostnames is required - send the full list, because a hostname you omit stops enforcing mTLS at once. The PEM itself cannot be changed here; upload a new certificate instead. PUT /accounts//access/certificates/. Path parameters: certificate_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_certificates_setting details
cf_set_access_certificates_setting details
[Cloudflare] DESTRUCTIVE: Update an mTLS certificate's hostname settings. Why this is destructive: The settings array REPLACES every stored hostname setting for the account, not just the hostnames you name. A hostname you leave out loses its client-certificate configuration, so devices that were being asked for a certificate silently stop being asked. Read cf_list_access_certificates_settings first and send the full set back. PUT /accounts//access/certificates/settings. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_access_certificate details
cf_set_zones_access_certificate details
[Cloudflare] DESTRUCTIVE: Update an mTLS certificate. Why this is destructive: A PUT replaces the certificate record from the body and associated_hostnames is required - a hostname you omit stops enforcing mTLS at once. PUT /zones//access/certificates/. Path parameters: certificate_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_access_certificates_setting details
cf_set_zones_access_certificates_setting details
[Cloudflare] DESTRUCTIVE: Update an mTLS certificate's hostname settings. Why this is destructive: The settings array REPLACES every stored hostname setting for this zone. A hostname you leave out loses its client-certificate configuration and stops being asked for one. Read cf_list_zones_access_certificates_settings first and send the full set back. PUT /zones//access/certificates/settings. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Custom Pages
cf_create_access_custom_page details
cf_create_access_custom_page details
[Cloudflare] Create a custom page. Additive: it stores one new page and changes no existing one. A stored page is not shown to anyone until an application or the organization points at it. POST /accounts//access/custom_pages. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_custom_page details
cf_delete_access_custom_page details
[Cloudflare] DESTRUCTIVE: Delete a custom page. Why this is destructive: The page is removed. Any application still pointing at it falls back to Cloudflare's default block screen, so the customer's branding and its own support instructions disappear from what a blocked user sees. The HTML is not recoverable from the API. DELETE /accounts//access/custom_pages/. Path parameters: custom_page_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_custom_page details
cf_get_access_custom_page details
[Cloudflare] Get a custom page. A custom page is the HTML Access serves in place of its own block or identity-denied screen. Unlike the list, this read returns the page's HTML as well as its metadata. GET /accounts//access/custom_pages/. Path parameters: custom_page_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_custom_pages details
cf_list_access_custom_pages details
[Cloudflare] List custom pages. A custom page is the HTML Access serves in place of its own block or identity-denied screen. The reach-first read: other custom-page tools take their custom_page_id from here. The list omits the HTML itself - cf_get_access_custom_page returns it. GET /accounts//access/custom_pages. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_custom_page details
cf_set_access_custom_page details
[Cloudflare] DESTRUCTIVE: Update a custom page. Why this is destructive: A PUT replaces the whole page, and custom_html, name and type are all required - there is no partial edit here, and the new HTML is what blocked users see from the next request on. Validate it first with cf_validate_access_custom_pages. PUT /accounts//access/custom_pages/. Path parameters: custom_page_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_validate_access_custom_pages details
cf_validate_access_custom_pages details
[Cloudflare] Validate a custom page template. A DRY RUN and the one POST in this family that changes nothing: Cloudflare states it returns the template's errors and warnings WITHOUT persisting it. Ruling R4 ships it read-only, Free and on the read permission for that reason. Run it before cf_create_access_custom_page or cf_set_access_custom_page. POST /accounts//access/custom_pages/validate. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Gateway Ca
cf_create_access_gateway_ca details
cf_create_access_gateway_ca details
[Cloudflare] Add a new SSH Certificate Authority (CA). Additive: it generates a new SSH Certificate Authority and returns its public key. It takes no request body. The new public key has to be installed on every SSH target before certificates it signs are accepted. POST /accounts//access/gateway_ca. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_gateway_ca details
cf_delete_access_gateway_ca details
[Cloudflare] DESTRUCTIVE: Delete an SSH Certificate Authority (CA). Why this is destructive: The SSH Certificate Authority is destroyed. Every certificate it signed stops being trusted, so users lose SSH access through Gateway until a new CA is generated and its public key is deployed to every target host. There is no undo. DELETE /accounts//access/gateway_ca/. Path parameters: certificate_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_gateway_cas details
cf_list_access_gateway_cas details
[Cloudflare] List SSH Certificate Authorities (CA). The Gateway SSH Certificate Authority is the account-wide CA that signs short-lived SSH certificates for Gateway's SSH proxy - it is not the per-application CA of cf_list_access_apps_cas. The response carries each CA's PUBLIC key, which is what goes into a target host's sshd configuration, and the certificate_id the delete tool takes. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/gateway_ca. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Groups
cf_create_access_group details
cf_create_access_group details
[Cloudflare] DESTRUCTIVE: Create an Access group. Why this is destructive: It creates a new group, and the group only matters once a policy references it - except when is_default is true, which applies it to new applications automatically. Marked destructive because a group is an access-control object: getting its include rules wrong widens who reaches every application that later references it. POST /accounts//access/groups. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_access_group details
cf_create_zones_access_group details
[Cloudflare] DESTRUCTIVE: Create an Access group. Why this is destructive: It creates a new group on this zone. Marked destructive because a group is an access-control object: its include rules decide who reaches every application whose policy later references it. POST /zones//access/groups. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_group details
cf_delete_access_group details
[Cloudflare] DESTRUCTIVE: Delete an Access group. Why this is destructive: The group is deleted. Every policy that referenced it loses that rule, so users who reached an application only through this group are refused on their next request - across every application at once. There is no undo and the rules have to be rebuilt by hand. DELETE /accounts//access/groups/. Path parameters: group_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_access_group details
cf_delete_zones_access_group details
[Cloudflare] DESTRUCTIVE: Delete an Access group. Why this is destructive: The group is deleted and every policy that referenced it loses that rule, so users who reached an application only through this group are refused on their next request. DELETE /zones//access/groups/. Path parameters: group_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_group details
cf_get_access_group details
[Cloudflare] Get an Access group. An Access group is a named, reusable set of identity rules - the same include, exclude and require vocabulary a policy uses - that policies then reference by id instead of repeating the rules. Returns one group with its full rule lists. GET /accounts//access/groups/. Path parameters: group_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_access_group details
cf_get_zones_access_group details
[Cloudflare] Get an Access group. An Access group is a named, reusable set of identity rules - the same include, exclude and require vocabulary a policy uses - that policies then reference by id instead of repeating the rules. The zone-scoped single-group read. GET /zones//access/groups/. Path parameters: group_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_groups details
cf_list_access_groups details
[Cloudflare] List Access groups. An Access group is a named, reusable set of identity rules - the same include, exclude and require vocabulary a policy uses - that policies then reference by id instead of repeating the rules. The reach-first read: a policy's group rule carries the group_id this list returns. is_default marks a group applied to new applications automatically. GET /accounts//access/groups. Path parameters: account_id. Optional filters: name, search, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones_access_groups details
cf_list_zones_access_groups details
[Cloudflare] List Access groups. An Access group is a named, reusable set of identity rules - the same include, exclude and require vocabulary a policy uses - that policies then reference by id instead of repeating the rules. ZONE-scoped twin of cf_list_access_groups. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/groups. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_group details
cf_set_access_group details
[Cloudflare] DESTRUCTIVE: Update an Access group. Why this is destructive: An Access group is referenced by policies, so this change propagates to EVERY application whose policy names the group, immediately and with no deploy step. A PUT replaces the whole group from the body: a rule you leave out of include is gone, and name and include are both required. PUT /accounts//access/groups/. Path parameters: group_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_access_group details
cf_set_zones_access_group details
[Cloudflare] DESTRUCTIVE: Update an Access group. Why this is destructive: An Access group is referenced by policies, so this change propagates to EVERY application whose policy names the group, immediately and with no deploy step. A PUT replaces the whole group from the body, so a rule you leave out of include is gone. PUT /zones//access/groups/. Path parameters: group_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Identity Providers
cf_create_access_identity_provider details
cf_create_access_identity_provider details
[Cloudflare] Add an Access identity provider. Additive: it adds one identity provider and changes no existing one. Nobody signs in through it until an application lists it in allowed_idps, but the OAuth client secret it carries is live from the moment Cloudflare stores it. POST /accounts//access/identity_providers. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_access_identity_providers_saml_certificate details
cf_create_access_identity_providers_saml_certificate details
[Cloudflare] Create SAML encryption certificate for Identity Provider. IDEMPOTENT by Cloudflare's own statement: if this provider already has a certificate set, the existing one comes back with a 200 and nothing is created. It takes no request body. Enabling encryption is a further step - set config.enable_encryption and saml_certificate_set_id on the provider with cf_set_access_identity_provider, then load the certificate's public key into the external SAML provider. Creates the SAML encryption certificate set used to decrypt SAML assertions and assigns it to this identity provider. The private key stays at Cloudflare; only the public certificate is ever returned. POST /accounts//access/identity_providers//saml_certificate. Path parameters: account_id, identity_provider_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_access_identity_provider details
cf_create_zones_access_identity_provider details
[Cloudflare] Add an Access identity provider. Additive: it adds one identity provider on this zone. The OAuth client secret it carries is live from the moment Cloudflare stores it. POST /zones//access/identity_providers. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_identity_provider details
cf_delete_access_identity_provider details
[Cloudflare] DESTRUCTIVE: Delete an Access identity provider. Why this is destructive: The identity provider is removed from the account. Every application that listed it in allowed_idps loses that login option, and if it was the only one those users cannot sign in at all. SCIM-provisioned users and groups from this provider stop being synced. The client secret is not recoverable - re-adding it means re-registering the application at the provider. DELETE /accounts//access/identity_providers/. Path parameters: identity_provider_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_access_identity_provider details
cf_delete_zones_access_identity_provider details
[Cloudflare] DESTRUCTIVE: Delete an Access identity provider. Why this is destructive: The identity provider is removed from the zone. Applications that listed it lose that login option, and if it was the only one those users cannot sign in at all. The client secret is not recoverable. DELETE /zones//access/identity_providers/. Path parameters: identity_provider_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_identity_provider details
cf_get_access_identity_provider details
[Cloudflare] Get an Access identity provider. An identity provider is the login source Access sends users to - Entra ID, Okta, Google Workspace, a generic SAML or OIDC provider, or Cloudflare's own one-time PIN. Returns one provider with its type and config block. GET /accounts//access/identity_providers/. Path parameters: identity_provider_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_access_identity_provider details
cf_get_zones_access_identity_provider details
[Cloudflare] Get an Access identity provider. An identity provider is the login source Access sends users to - Entra ID, Okta, Google Workspace, a generic SAML or OIDC provider, or Cloudflare's own one-time PIN. The zone-scoped single-provider read. GET /zones//access/identity_providers/. Path parameters: identity_provider_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_identity_providers details
cf_list_access_identity_providers details
[Cloudflare] List Access identity providers. An identity provider is the login source Access sends users to - Entra ID, Okta, Google Workspace, a generic SAML or OIDC provider, or Cloudflare's own one-time PIN. The reach-first read of the identity lane: an application's allowed_idps array and a policy's login_method rule both carry the identity_provider_id this list returns. Each row names its type (azureAD, okta, google-apps, saml, oidc, onetimepin and the rest) and whether SCIM provisioning is on. GET /accounts//access/identity_providers. Path parameters: account_id. Optional filters: scim_enabled, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_identity_providers_scim_groups details
cf_list_access_identity_providers_scim_groups details
[Cloudflare] List SCIM Group resources. The GROUPS an external identity provider has pushed into Cloudflare over SCIM. This is directory data synced from the provider, not Access groups - Access groups are cf_list_access_groups. cf_resource_id is Cloudflare's id for the synced group and idp_resource_id is the provider's own. GET /accounts//access/identity_providers//scim/groups. Path parameters: identity_provider_id, account_id. Optional filters: cf_resource_id, idp_resource_id, name, page, per_page. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_identity_providers_scim_users details
cf_list_access_identity_providers_scim_users details
[Cloudflare] List SCIM User resources. The USERS an external identity provider has pushed into Cloudflare over SCIM, with the provider's own resource id beside Cloudflare's. Zero Trust seats and Access users are separate reads (cf_list_access_users). GET /accounts//access/identity_providers//scim/users. Path parameters: identity_provider_id, account_id. Optional filters: cf_resource_id, idp_resource_id, username, email, name, page, per_page. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones_access_identity_providers details
cf_list_zones_access_identity_providers details
[Cloudflare] List Access identity providers. An identity provider is the login source Access sends users to - Entra ID, Okta, Google Workspace, a generic SAML or OIDC provider, or Cloudflare's own one-time PIN. ZONE-scoped twin of cf_list_access_identity_providers. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/identity_providers. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_identity_provider details
cf_set_access_identity_provider details
[Cloudflare] DESTRUCTIVE: Update an Access identity provider. Why this is destructive: A PUT replaces the WHOLE provider from the body, so a config field you leave out is cleared - and clearing client_secret breaks every sign-in through this provider until it is set again. Users are affected on their next authentication, not at their next session expiry. PUT /accounts//access/identity_providers/. Path parameters: identity_provider_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_access_identity_provider details
cf_set_zones_access_identity_provider details
[Cloudflare] DESTRUCTIVE: Update an Access identity provider. Why this is destructive: A PUT replaces the WHOLE provider from the body, so a config field you leave out is cleared - and clearing client_secret breaks every sign-in through this provider until it is set again. PUT /zones//access/identity_providers/. Path parameters: identity_provider_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Idp Federation Grants
cf_create_access_idp_federation_grant details
cf_create_access_idp_federation_grant details
[Cloudflare] DESTRUCTIVE: Create an IdP federation grant. Why this is destructive: It publishes one identity provider to every other account in the Cloudflare organization, which widens who can authenticate against the customer's own directory. Cloudflare's own limits: the account must belong to an organization, one-time PIN and Cloudflare-managed providers cannot be federated, and at most five providers may be federated at once. Marked destructive because it grants another account the use of this one's identity provider. POST /accounts//access/idp_federation_grants. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_idp_federation_grant details
cf_delete_access_idp_federation_grant details
[Cloudflare] DESTRUCTIVE: Delete an IdP federation grant. Why this is destructive: The identity provider stays in this account but stops being available to the other accounts in the organization, so any of them relying on it for sign-in loses that login source on the next authentication. DELETE /accounts//access/idp_federation_grants/. Path parameters: account_id, grant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_idp_federation_grant details
cf_get_access_idp_federation_grant details
[Cloudflare] Get an IdP federation grant. An IdP federation grant publishes ONE of this account's identity providers to the other accounts in the same Cloudflare organization, so they can authenticate users against it without re-registering it. Returns one grant by its uid. GET /accounts//access/idp_federation_grants/. Path parameters: account_id, grant_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_idp_federation_grants details
cf_list_access_idp_federation_grants details
[Cloudflare] List IdP federation grants. An IdP federation grant publishes ONE of this account's identity providers to the other accounts in the same Cloudflare organization, so they can authenticate users against it without re-registering it. The reach-first read: each row carries the grant_id the get and delete tools take and the idp_id it publishes. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/idp_federation_grants. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Keys
cf_get_access_keys details
cf_get_access_keys details
[Cloudflare] Get the Access key configuration. These are the keys Access signs its own application JWTs with - the ones an origin verifies through Cloudflare's public JWKS endpoint. They are not API tokens and not service tokens. The read returns the rotation SETTINGS and status only - the interval, the last rotation time and the days until the next one. No key material is in the response. GET /accounts//access/keys. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_rotate_access_keys details
cf_rotate_access_keys details
[Cloudflare] DESTRUCTIVE: Rotate Access keys. Why this is destructive: It rotates the Access JWT signing keys NOW, ahead of the configured schedule, and takes no request body. Any origin or middleware that caches Cloudflare's public keys rejects tokens signed with the new key until it refetches the JWKS, so users can see failures at an origin that caches aggressively. There is no un-rotate. POST /accounts//access/keys/rotate. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_key details
cf_set_access_key details
[Cloudflare] DESTRUCTIVE: Update the Access key configuration. Why this is destructive: It sets how often Access rotates its JWT signing keys; it mints nothing by itself. Shortening the interval means Cloudflare replaces the signing key sooner, and anything that caches Access's public keys rejects freshly signed tokens until it refetches the JWKS. Marked destructive because it governs the credential every Access-protected origin verifies against. PUT /accounts//access/keys. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Logs
cf_get_access_logs_jit_request details
cf_get_access_logs_jit_request details
[Cloudflare] Get an Access JIT request log. One JIT access request with its lifecycle events in chronological order - raised, approved or denied, by whom and when. The knock_request_id comes from cf_list_access_logs_jit_requests. GET /accounts//access/logs/jit_requests/. Path parameters: account_id, knock_request_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_logs_access_requests details
cf_list_access_logs_access_requests details
[Cloudflare] Get Access authentication logs. The Access authentication audit trail: one row per sign-in decision, with the user's email, the application, the identity provider, the country, the ray id and whether Access allowed the request. This is the read to reach for when a customer asks why somebody could or could not get in. Cloudflare's document declares the OPERATOR parameters (allowedOp, country_codeOp and the rest) but NOT the value parameters they modify, so email is the only filter whose value can be sent - StackJack mirrors the vendor document exactly and invents nothing. GET /accounts//access/logs/access_requests. Path parameters: account_id. Optional filters: limit, direction, since, until, page, per_page, email, email_exact, user_id, allowedOp, country_codeOp, app_typeOp, app_uidOp, ray_idOp, emailOp, idpOp, non_identityOp, user_idOp, fields. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_logs_jit_requests details
cf_list_access_logs_jit_requests details
[Cloudflare] List Access JIT request logs. JIT (just-in-time) requests are the access requests a user raises for an application that needs approval, reconstructed from their lifecycle events. Each row carries the knock_request_id cf_get_access_logs_jit_request takes. GET /accounts//access/logs/jit_requests. Path parameters: account_id. Optional filters: page, per_page, status, search, since, until. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_logs_scim_updates details
cf_list_access_logs_scim_updates details
[Cloudflare] List Access SCIM update logs. The audit trail of what an identity provider changed through SCIM: users and groups created, updated or deprovisioned in Cloudflare by the directory. idp_id is REQUIRED - this log is read one identity provider at a time, from cf_list_access_identity_providers. GET /accounts//access/logs/scim/updates. Path parameters: account_id. Cloudflare REQUIRES this query parameter and answers 400 without it: idp_id. Optional filters: limit, direction, since, until, status, resource_type, request_method, resource_user_email, resource_group_name, cf_resource_id, idp_resource_id, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Organizations
cf_create_access_organization details
cf_create_access_organization details
[Cloudflare] Create your Zero Trust organization. Additive: it sets up the account's Zero Trust organization, which exists once. auth_domain and name are required, and auth_domain becomes the team domain every user signs in at - Cloudflare does not let it be changed casually afterwards. POST /accounts//access/organizations. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_access_organization details
cf_create_zones_access_organization details
[Cloudflare] Create your Zero Trust organization. Additive: it sets up the Zero Trust organization from the zone route. auth_domain and name are required, and auth_domain becomes the team domain every user signs in at. POST /zones//access/organizations. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_organizations details
cf_get_access_organizations details
[Cloudflare] Get your Zero Trust organization. The Zero Trust organization is the account-wide Access configuration: the auth_domain (the team domain users see at sign-in, for example acme.cloudflareaccess.com), the global session duration, the login page design and the MFA requirements. There is exactly one per account. Read this before any organization write - the PUT replaces the whole object, so this response is the baseline you edit. GET /accounts//access/organizations. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_organizations_dohs details
cf_get_access_organizations_dohs details
[Cloudflare] Get your Zero Trust organization DoH settings. The organization's DNS-over-HTTPS settings: how long a DoH JWT lasts and which service token authenticates the DoH endpoint. Nothing in the response is the token itself - service_token_id is an identifier. GET /accounts//access/organizations/doh. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_access_organizations details
cf_get_zones_access_organizations details
[Cloudflare] Get your Zero Trust organization. The Zero Trust organization is the account-wide Access configuration: the auth_domain (the team domain users see at sign-in, for example acme.cloudflareaccess.com), the global session duration, the login page design and the MFA requirements. There is exactly one per account. ZONE-scoped twin of cf_get_access_organizations, with the smaller zone-level field set. GET /zones//access/organizations. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_revoke_access_organization_user_tokens details
cf_revoke_access_organization_user_tokens details
[Cloudflare] DESTRUCTIVE: Revoke all Access tokens for a user. Why this is destructive: It revokes the named user's Access across EVERY application at once: their live sessions end immediately and they must re-authenticate everywhere. With devices=true their WARP device registration goes too, so the device has to be re-enrolled, and warp_session_reauth forces WARP re-authentication. This is the offboarding and compromised-account lever, not a routine one. Note that devices appears BOTH as a query parameter and as a body field in Cloudflare's own document; the body form is the documented one. POST /accounts//access/organizations/revoke_user. Path parameters: account_id. Optional filters: devices. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_revoke_zones_access_org_user_tokens details
cf_revoke_zones_access_org_user_tokens details
[Cloudflare] DESTRUCTIVE: Revoke all Access tokens for a user. Why this is destructive: It revokes the named user's Access across EVERY application at once - their live sessions end immediately and they must re-authenticate everywhere. The zone route takes email only; use the account route when you also need to revoke WARP devices. POST /zones//access/organizations/revoke_user. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_organization details
cf_set_access_organization details
[Cloudflare] DESTRUCTIVE: Update your Zero Trust organization. Why this is destructive: A PUT replaces the WHOLE organization configuration from the body, and this is the highest-blast-radius write in the Access family: change auth_domain and every existing Access login URL, every bookmarked team domain and every SAML integration pointed at the old one stops working. A field you leave out is cleared, so read the organization first and send it back changed. is_ui_read_only locks the Zero Trust dashboard for everyone, and deny_unmatched_requests refuses traffic that matches no application. PUT /accounts//access/organizations. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_organizations_doh details
cf_set_access_organizations_doh details
[Cloudflare] DESTRUCTIVE: Update your Zero Trust organization DoH settings. Why this is destructive: A PUT replaces the whole DoH settings object, so an omitted field falls back to Cloudflare's default rather than keeping its stored value. Pointing service_token_id at a different token stops every DoH client still presenting the old one. PUT /accounts//access/organizations/doh. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_access_organization details
cf_set_zones_access_organization details
[Cloudflare] DESTRUCTIVE: Update your Zero Trust organization. Why this is destructive: A PUT replaces the WHOLE organization configuration from the body, and this is the highest-blast-radius write in the Access family: change auth_domain and every existing Access login URL, every bookmarked team domain and every SAML integration pointed at the old one stops working. A field you leave out is cleared, so read the organization first and send it back changed. The zone route carries a smaller field set than the account one but writes the same account-wide organization. PUT /zones//access/organizations. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Policies
cf_create_access_policy details
cf_create_access_policy details
[Cloudflare] DESTRUCTIVE: Create an Access reusable policy. Why this is destructive: It creates a reusable policy. The policy governs nothing until an application references its id - but it is an access-control object, and once referenced its include rules decide who reaches that application. POST /accounts//access/policies. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_policy details
cf_delete_access_policy details
[Cloudflare] DESTRUCTIVE: Delete an Access reusable policy. Why this is destructive: The reusable policy is deleted and every application that referenced it loses that rule at once. If it was an application's only allow policy its users are locked out on the next request; if it was the deny, whoever it kept out is let in. There is no undo, and the rules have to be rebuilt by hand. DELETE /accounts//access/policies/. Path parameters: account_id, policy_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_policy details
cf_get_access_policy details
[Cloudflare] Get an Access reusable policy. A reusable policy is defined once on the account and referenced by id from any number of applications, which is the shape Cloudflare recommends over app-scoped policies. Returns one reusable policy with its decision and full rule lists. GET /accounts//access/policies/. Path parameters: account_id, policy_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_policies details
cf_list_access_policies details
[Cloudflare] List Access reusable policies. A reusable policy is defined once on the account and referenced by id from any number of applications, which is the shape Cloudflare recommends over app-scoped policies. The reach-first read: an application's policies array carries the policy ids this list returns, and each row shows the decision, the rules and how many applications use it. GET /accounts//access/policies. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_policy details
cf_set_access_policy details
[Cloudflare] DESTRUCTIVE: Update an Access reusable policy. Why this is destructive: An Access policy decides who may reach the customer's internal applications, and a reusable policy is shared: this edit takes effect on EVERY application that references it, immediately. A PUT replaces the whole policy, so any include, exclude or require rule you leave out is deleted. PUT /accounts//access/policies/. Path parameters: account_id, policy_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Policy Tests
cf_create_access_policy_test details
cf_create_access_policy_test details
[Cloudflare] Start Access policy test. A SIMULATION: it evaluates the policies you send against the organization's users and reports who would be allowed. It grants nothing and changes no application. It is a write only because Cloudflare persists the run - it returns a policy_test_id that cf_get_access_policy_test and cf_list_access_policy_tests_users then read, and it costs an evaluation over every user in the organization. POST /accounts//access/policy-tests. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_policy_test details
cf_get_access_policy_test details
[Cloudflare] Get the current status of a given Access policy test. The status of a policy test started by cf_create_access_policy_test - whether the evaluation has finished and the headline counts. The per-user results are paged through cf_list_access_policy_tests_users. GET /accounts//access/policy-tests/. Path parameters: account_id, policy_test_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_policy_tests_users details
cf_list_access_policy_tests_users details
[Cloudflare] Get an Access policy test users page. One page of per-user results from a policy test: who the simulated policy would let in and who it would refuse. Filter by status to see only one outcome. GET /accounts//access/policy-tests//users. Path parameters: account_id, policy_test_id. Optional filters: page, per_page, status. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Saml Certificates
cf_download_access_saml_certificate_pem details
cf_download_access_saml_certificate_pem details
[Cloudflare] Download current certificate in PEM format. Downloads the CURRENT certificate's PUBLIC key as PEM text, which is what an administrator uploads to the external SAML identity provider so it can encrypt assertions. The response is the PEM itself (Cloudflare answers application/x-pem-file), not the usual JSON envelope, and it contains no private key. GET /accounts//access/saml_certificates//pem. Path parameters: account_id, saml_cert_set_id. Returns the response body as plain text exactly as Cloudflare sent it, not JSON.
cf_get_access_saml_certificate details
cf_get_access_saml_certificate details
[Cloudflare] Get SAML certificate set. A SAML certificate set holds the CURRENT and (after a rotation) the PREVIOUS encryption certificate an identity provider uses to encrypt SAML assertions to Cloudflare. Cloudflare keeps the private key; only public certificates are ever returned. Returns one set, current and previous certificate together. GET /accounts//access/saml_certificates/. Path parameters: account_id, saml_cert_set_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_saml_certificates details
cf_list_access_saml_certificates details
[Cloudflare] List SAML certificate sets. A SAML certificate set holds the CURRENT and (after a rotation) the PREVIOUS encryption certificate an identity provider uses to encrypt SAML assertions to Cloudflare. Cloudflare keeps the private key; only public certificates are ever returned. The reach-first read: each row carries the saml_cert_set_id the other three tools take, and both certificates with their expiry dates. GET /accounts//access/saml_certificates. Path parameters: account_id. Optional filters: page, per_page, id. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_rotate_access_saml_certificates details
cf_rotate_access_saml_certificates details
[Cloudflare] DESTRUCTIVE: Rotate SAML certificate. Why this is destructive: It generates a new certificate, moves the current one into the previous slot and - Cloudflare says this explicitly - DEACTIVATES AND REMOVES whatever was in the previous slot already. Both current and previous stay valid during the transition so there is no downtime, but an identity provider still encrypting with the certificate that just fell out of the set can no longer be decrypted: upload the new public key (from cf_download_access_saml_certificate_pem) to the provider before rotating twice. Cloudflare rotates automatically 30 days before expiry, so a manual rotation is rarely needed. POST /accounts//access/saml_certificates//rotate. Path parameters: account_id, saml_cert_set_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Seats
cf_update_access_seat details
cf_update_access_seat details
[Cloudflare] DESTRUCTIVE: Update a user seat. Why this is destructive: This is the REMOVE-A-SEAT call: Cloudflare's own description says setting both access_seat and gateway_seat to false removes the user from their Zero Trust seat. That user loses Access and Gateway entitlement, their sessions end and the seat returns to the customer's licence pool. Send the flags true to restore it. The body is an ARRAY, so several seats can be changed in one call. PATCH /accounts//access/seats. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Service Tokens
cf_create_access_service_token details
cf_create_access_service_token details
[Cloudflare] DESTRUCTIVE: Create a service token. Why this is destructive: It mints a live machine credential, and Cloudflare states this is the ONLY time the client secret is returned: if it is lost the token has to be rotated or replaced. The token reaches nothing until a policy admits it with a service_token or any_valid_service_token rule. POST /accounts//access/service_tokens. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_zones_access_service_token details
cf_create_zones_access_service_token details
[Cloudflare] DESTRUCTIVE: Create a service token. Why this is destructive: It mints a live machine credential, and Cloudflare states this is the ONLY time the client secret is returned - on the zone route the recovery is to create a new token outright. The token reaches nothing until a policy admits it. POST /zones//access/service_tokens. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_service_token details
cf_delete_access_service_token details
[Cloudflare] DESTRUCTIVE: Delete a service token. Why this is destructive: The token stops working immediately, and every script or service still presenting its client id and secret starts getting refused by Access. The secret cannot be recovered - recovery means creating a new token and redeploying it everywhere it was used. DELETE /accounts//access/service_tokens/. Path parameters: service_token_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_zones_access_service_token details
cf_delete_zones_access_service_token details
[Cloudflare] DESTRUCTIVE: Delete a service token. Why this is destructive: The token stops working immediately and every client still presenting its id and secret is refused. The secret cannot be recovered. DELETE /zones//access/service_tokens/. Path parameters: service_token_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_service_token details
cf_get_access_service_token details
[Cloudflare] Get a service token. A service token is a machine credential - a client_id and client_secret pair a script or service presents in CF-Access-Client-Id and CF-Access-Client-Secret headers instead of signing in - and an Access policy admits it through a service_token or any_valid_service_token rule. Returns one token's metadata - id, client_id, expiry, last seen. The secret is not in the response. GET /accounts//access/service_tokens/. Path parameters: service_token_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_zones_access_service_token details
cf_get_zones_access_service_token details
[Cloudflare] Get a service token. A service token is a machine credential - a client_id and client_secret pair a script or service presents in CF-Access-Client-Id and CF-Access-Client-Secret headers instead of signing in - and an Access policy admits it through a service_token or any_valid_service_token rule. The zone-scoped single-token read; metadata only, no secret. GET /zones//access/service_tokens/. Path parameters: service_token_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_service_tokens details
cf_list_access_service_tokens details
[Cloudflare] List service tokens. A service token is a machine credential - a client_id and client_secret pair a script or service presents in CF-Access-Client-Id and CF-Access-Client-Secret headers instead of signing in - and an Access policy admits it through a service_token or any_valid_service_token rule. The reach-first read: it returns each token's id, client_id, expiry and last-seen time. The client SECRET is never in this response - Cloudflare returns it only when the token is created or rotated. GET /accounts//access/service_tokens. Path parameters: account_id. Optional filters: name, search, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_zones_access_service_tokens details
cf_list_zones_access_service_tokens details
[Cloudflare] List service tokens. A service token is a machine credential - a client_id and client_secret pair a script or service presents in CF-Access-Client-Id and CF-Access-Client-Secret headers instead of signing in - and an Access policy admits it through a service_token or any_valid_service_token rule. ZONE-scoped twin of cf_list_access_service_tokens. The client secret is never in this response. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /zones//access/service_tokens. Path parameters: zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_refresh_access_service_tokens details
cf_refresh_access_service_tokens details
[Cloudflare] DESTRUCTIVE: Refresh a service token. Why this is destructive: It EXTENDS the token's expiration and mints nothing - the client id and secret are unchanged, so nothing that uses the token needs redeploying. Marked destructive because it keeps a machine credential alive that was about to expire, which is a security decision rather than a maintenance one. It takes no request body. POST /accounts//access/service_tokens//refresh. Path parameters: service_token_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_rotate_access_service_tokens details
cf_rotate_access_service_tokens details
[Cloudflare] DESTRUCTIVE: Rotate a service token. Why this is destructive: It generates a NEW client secret and revokes the old one, and the new secret is in the response - the only time Cloudflare returns it. Every client still using the old secret is refused as soon as it expires, so set previous_client_secret_expires_at to buy a window in which both work while the new secret is deployed. POST /accounts//access/service_tokens//rotate. Path parameters: service_token_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_service_token details
cf_set_access_service_token details
[Cloudflare] DESTRUCTIVE: Update a service token. Why this is destructive: It updates the token's settings and mints no new secret. A PUT replaces the record, so a field you omit falls back to its default rather than keeping its stored value - and enabled=false turns the token off, which refuses every client still presenting it. PUT /accounts//access/service_tokens/. Path parameters: service_token_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_zones_access_service_token details
cf_set_zones_access_service_token details
[Cloudflare] DESTRUCTIVE: Update a service token. Why this is destructive: It updates the token's settings and mints no new secret. A PUT replaces the record, so an omitted field falls back to its default - and enabled=false turns the token off for every client using it. PUT /zones//access/service_tokens/. Path parameters: service_token_id, zone_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Tags
cf_create_access_tag details
cf_create_access_tag details
[Cloudflare] Create a tag. Additive: it creates one label and changes no application. POST /accounts//access/tags. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_tag details
cf_delete_access_tag details
[Cloudflare] DESTRUCTIVE: Delete a tag. Why this is destructive: The tag is deleted and disappears from every application carrying it, so the App Launcher grouping the customer built is gone. No application is otherwise changed and no access is affected. DELETE /accounts//access/tags/. Path parameters: account_id, tag_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_tag details
cf_get_access_tag details
[Cloudflare] Get a tag. An Access tag is a label put on applications so the App Launcher can group them; it grants nothing and restricts nothing. Note that a tag is addressed by its NAME, not by a uid. GET /accounts//access/tags/. Path parameters: account_id, tag_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_tags details
cf_list_access_tags details
[Cloudflare] List tags. An Access tag is a label put on applications so the App Launcher can group them; it grants nothing and restricts nothing. Note that a tag is addressed by its NAME, not by a uid. Each row carries the tag name the other tools take and the number of applications carrying it. GET /accounts//access/tags. Path parameters: account_id. Optional filters: page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_tag details
cf_set_access_tag details
[Cloudflare] DESTRUCTIVE: Update a tag. Why this is destructive: A PUT replaces the tag record. Renaming it through the name field re-labels it for every application carrying it, and the old name stops resolving. PUT /accounts//access/tags/. Path parameters: account_id, tag_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
Access Users
cf_create_access_user details
cf_create_access_user details
[Cloudflare] Create a user. Additive: it creates one user record and changes no existing one. The record does not grant access by itself - what a user may reach is decided by the policies of each application. POST /accounts//access/users. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_user details
cf_delete_access_user details
[Cloudflare] DESTRUCTIVE: Delete a user. Why this is destructive: Cloudflare states that deleting the user ALSO revokes their active seats and tokens: every live Access session ends, their Zero Trust seat is released and the audit identity goes with the record. The person can authenticate again from scratch if a policy still admits them, but the history and the seat assignment are not recoverable. DELETE /accounts//access/users/. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_access_users_mfa_authenticator details
cf_delete_access_users_mfa_authenticator details
[Cloudflare] DESTRUCTIVE: Delete a user's MFA device. Why this is destructive: The user's enrolled MFA device - a PIV card, a FIDO2 security key or a TOTP authenticator - is de-enrolled, and Cloudflare returns a null result on success. If it was their only factor and the organization requires MFA, they cannot sign in until they enroll another one, so this is the deliberate step after a lost key rather than a cleanup action. Cloudflare only offers it while MFA is turned on for the organization. DELETE /accounts//access/users//mfa_authenticators/. Path parameters: user_id, account_id, authenticator_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_user details
cf_get_access_user details
[Cloudflare] Get a user. A Zero Trust user is a person who has authenticated to Access at least once or has been provisioned into the account; the user_id here is what the sessions, logins and MFA reads below take. Returns one user record. GET /accounts//access/users/. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_users_active_session details
cf_get_access_users_active_session details
[Cloudflare] Get single active session. One live Access session of a user, with the identity Access recorded for it. GET /accounts//access/users//active_sessions/. Path parameters: user_id, account_id, nonce. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_access_users_last_seen_identities details
cf_get_access_users_last_seen_identities details
[Cloudflare] Get last seen identity. The identity Access last saw for this user: the identity provider, the groups and the claims that came back at their most recent sign-in. This is what a policy's group and claim rules are actually matched against, so it is the read that explains an unexpected allow or deny. GET /accounts//access/users//last_seen_identity. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_users details
cf_list_access_users details
[Cloudflare] Get users. A Zero Trust user is a person who has authenticated to Access at least once or has been provisioned into the account; the user_id here is what the sessions, logins and MFA reads below take. The reach-first read of the user lane, filterable by name, email or free text, and the source of the seat_uid cf_update_access_seat takes. GET /accounts//access/users. Path parameters: account_id. Optional filters: name, email, search, page, per_page. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_users_active_sessions details
cf_list_access_users_active_sessions details
[Cloudflare] Get active sessions. The live Access sessions of one user, each with the nonce cf_get_access_users_active_session takes. To end them all, use cf_revoke_access_organization_user_tokens. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/users//active_sessions. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_access_users_failed_logins details
cf_list_access_users_failed_logins details
[Cloudflare] Get failed logins. Every failed sign-in attempt recorded for one user, with the reason Access refused it. The first read when a customer reports that somebody cannot get in. Cloudflare paginates nothing here: the whole collection comes back in one response, so there is no page argument to pass and a large account returns a large body. GET /accounts//access/users//failed_logins. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_set_access_user details
cf_set_access_user details
[Cloudflare] DESTRUCTIVE: Update a user. Why this is destructive: Cloudflare updates the user's NAME only and requires their current email in the body as confirmation - the email itself cannot be changed here. Sending a different email does not move the record, it fails. PUT /accounts//access/users/. Path parameters: user_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
AI
cf_create_ai_finetune details
cf_create_ai_finetune details
[Cloudflare] Create a new Finetune. Additive: creates a new record and changes no existing one. Creates the fine-tune record only. Its training data is uploaded separately with cf_create_ai_finetunes_finetune_asset against the id this call returns. POST /accounts//ai/finetunes. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_finetunes_finetune_asset details
cf_create_ai_finetunes_finetune_asset details
[Cloudflare] Upload a Finetune Asset. Additive: creates a new record and changes no existing one. Uploads the training data for a fine-tune created by cf_create_ai_finetune. StackJack takes the file either as base64 or as a public https URL it downloads server-side. POST /accounts//ai/finetunes//finetune-assets. Path parameters: account_id, finetune_id. Cloudflare takes this request as a multipart/form-data body with these parts: file, file_name. A file part is supplied EITHER as base64 in the call OR as a public https URL StackJack downloads server-side; give exactly one of the two per file, and StackJack refuses a non-https URL, a redirect to another host, or anything over 25 MB. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_run details
cf_create_ai_run details
[Cloudflare] Execute AI model. Runs a model on demand. Nothing the customer authored is changed, but the call is metered Workers AI usage and is charged to the account. Runs the Workers AI model named in the path. This is a metered inference call: every invocation consumes the account's Workers AI allowance and is billed beyond it. The body fields Cloudflare documents here are the union across model types, so only the ones in that model's own schema apply - read cf_get_ai_models_schemas first. POST /accounts//ai/run/. Path parameters: account_id, model_name. Send the request body as JSON; Cloudflare documents these fields: text, guidance, height, image, image_b64, mask, negative_prompt, num_steps, prompt, seed, strength, width. Cloudflare documents 5 more fields; see its API docs. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_tomarkdown details
cf_create_ai_tomarkdown details
[Cloudflare] Convert Files into Markdown. Converts a document and returns the Markdown. Nothing stored is changed, but a format that needs a model to read it is metered Workers AI usage. Converts an uploaded document to Markdown. cf_list_ai_tomarkdown_supporteds is the list of formats Cloudflare accepts; a format that needs a model to read it is a metered Workers AI call. POST /accounts//ai/tomarkdown. Path parameters: account_id. Cloudflare takes this request as a multipart/form-data body with these parts: files. A file part is supplied EITHER as base64 in the call OR as a public https URL StackJack downloads server-side; give exactly one of the two per file, and StackJack refuses a non-https URL, a redirect to another host, or anything over 25 MB. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_finetune details
cf_delete_ai_finetune details
[Cloudflare] DESTRUCTIVE: Delete a Finetune. Why this is destructive: Removes the fine-tune named by finetune_id. Any Workers AI call that names that fine-tune stops resolving from the moment it succeeds, and the API offers no undo; retraining is the only way back. DELETE /accounts//ai/finetunes/. Path parameters: account_id, finetune_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_finetunes details
cf_get_ai_finetunes details
[Cloudflare] List Finetunes. The reach-first read for fine-tuning: every fine-tune this account has created, with its status. The id on each row is the finetune_id that cf_create_ai_finetunes_finetune_asset, cf_get_ai_finetunes_finetune_asset and cf_delete_ai_finetune take. No page size is documented, so the whole list comes back at once. GET /accounts//ai/finetunes. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_finetunes_finetune_asset details
cf_get_ai_finetunes_finetune_asset details
[Cloudflare] Download a Finetune Asset. Despite the vendor title this does NOT return the file bytes: Cloudflare answers a pre-signed R2 URL for the asset, which you fetch separately and which expires. StackJack passes that JSON through unchanged and keeps no copy of the file. GET /accounts//ai/finetunes//finetune-assets/. Path parameters: account_id, finetune_id, file_name. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_models_schemas details
cf_get_ai_models_schemas details
[Cloudflare] Get Model Schema. The input and output JSON schema for ONE Workers AI model - what cf_run_ai and cf_create_ai_run expect in their request body. Read it before composing a model call. GET /accounts//ai/models/schema. Path parameters: account_id. Cloudflare REQUIRES this query parameter and answers 400 without it: model. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_ai_finetunes_publics details
cf_list_ai_finetunes_publics details
[Cloudflare] List Public Finetunes. Fine-tunes Cloudflare publishes for anyone to use, NOT this account's own fine-tunes - cf_get_ai_finetunes is that read. GET /accounts//ai/finetunes/public. Path parameters: account_id. Optional filters: limit, offset, orderBy. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_ai_tomarkdown_supporteds details
cf_list_ai_tomarkdown_supporteds details
[Cloudflare] Get all converted formats supported. The file formats cf_create_ai_tomarkdown accepts. It takes no arguments and the whole list comes back in one response. GET /accounts//ai/tomarkdown/supported. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_run_ai details
cf_run_ai details
[Cloudflare] Execute AI Model (Generic). Runs a model on demand. Nothing the customer authored is changed, but the call is metered Workers AI usage and is charged to the account. Runs a Workers AI model named in the request body rather than in the path. This is a metered inference call: every invocation consumes the account's Workers AI allowance and is billed beyond it. Read the model's own schema with cf_get_ai_models_schemas first - the input field shape differs per model. POST /accounts//ai/run. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_search_ai_authors details
cf_search_ai_authors details
[Cloudflare] Author Search. Cloudflare-wide catalogue data, not this account's: it answers the authors and organizations that publish Workers AI models. It takes no filter arguments and no page size, so the whole list comes back in one response, and the names in it are what the author filter on cf_search_ai_models matches. GET /accounts//ai/authors/search. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_search_ai_models details
cf_search_ai_models details
[Cloudflare] Model Search. The reach-first read for Workers AI: Cloudflare's whole model catalogue, filterable by task, author and free text. The model ids it returns are what cf_create_ai_run takes in its path and cf_run_ai takes in its body. Set include_deprecated only when you deliberately want models Cloudflare has retired. GET /accounts//ai/models/search. Path parameters: account_id. Optional filters: per_page, page, task, author, source, hide_experimental, search, include_deprecated, format. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_search_ai_tasks details
cf_search_ai_tasks details
[Cloudflare] Task Search. The task types Workers AI models are grouped under, for example text-generation or text-embeddings. These are the values the task filter on cf_search_ai_models accepts. It takes no arguments and the whole list comes back in one response. GET /accounts//ai/tasks/search. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
AI Gateway Billing
cf_create_ai_gateway_billing_spending_limit details
cf_create_ai_gateway_billing_spending_limit details
[Cloudflare] Set spending limit (deprecated). Cloudflare answers 403 to every call, so nothing changes - but it is a write and is tiered as one. DEPRECATED and inert: Cloudflare's own document says spending limits can no longer be created, enabled or modified and that this endpoint always responds 403. It is built so the surface is complete and so an agent gets the vendor's own refusal rather than a missing tool. There is no replacement write, and cf_delete_ai_gateway_billing_spending_limit is the only spending-limit change still accepted. POST /accounts//ai-gateway/billing/spending-limit. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info. DEPRECATED by Cloudflare: this operation still answers, but the vendor marks it deprecated in its own API document and may withdraw it - prefer a non-deprecated tool for the same resource where one exists.
cf_create_ai_gateway_billing_topup details
cf_create_ai_gateway_billing_topup details
[Cloudflare] DESTRUCTIVE: Create a top-up. Why this is destructive: SPENDS THE CUSTOMER'S MONEY. It charges the account's default payment method for the amount given, in cents, minimum 1000 (USD 10.00), and buys AI Gateway credit. A completed charge cannot be reversed through this API - a refund is a support matter. Confirm the amount with the customer first, and read cf_get_ai_gateway_billing_topup_limits and cf_get_ai_gateway_billing_credit_balances before calling it. Its response carries the Stripe PaymentIntent client_secret, and cf_get_ai_gateway_billing_topup_status takes the payment_intent_id it also returns to poll how the charge settled. POST /accounts//ai-gateway/billing/topup. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_gateway_billing_topup_config details
cf_create_ai_gateway_billing_topup_config details
[Cloudflare] DESTRUCTIVE: Set auto top-up configuration. Why this is destructive: ARMS AUTOMATIC CHARGES. From the moment it succeeds Cloudflare charges the account's default payment method the given amount, without asking again, every time the credit balance falls below the given threshold. Both values are in cents. cf_delete_ai_gateway_billing_topup_config is what disarms it. POST /accounts//ai-gateway/billing/topup/config. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_gateway_billing_topup_eligibility details
cf_create_ai_gateway_billing_topup_eligibility details
[Cloudflare] Get top-up eligibility. A POST that only ASKS: it reports whether the account can self-serve a credit top-up and, if not, why. It charges nothing and changes nothing, so it ships as a read. POST /accounts//ai-gateway/billing/topup/eligibility. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_gateway_billing_spending_limit details
cf_delete_ai_gateway_billing_spending_limit details
[Cloudflare] DESTRUCTIVE: Delete spending limit. Why this is destructive: Removes the spending cap on AI Gateway usage for the whole account. Afterwards nothing in AI Gateway stops spend at a threshold, and because cf_create_ai_gateway_billing_spending_limit is deprecated and answers 403, the limit cannot be put back through this API once it is gone. DELETE /accounts//ai-gateway/billing/spending-limit. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_gateway_billing_topup_config details
cf_delete_ai_gateway_billing_topup_config details
[Cloudflare] DESTRUCTIVE: Delete auto top-up configuration. Why this is destructive: Disarms automatic top-up for the account. Nothing charges the card automatically after this, so AI Gateway calls start failing on an empty balance instead of buying more credit - which may be exactly what the customer wants, or an outage. It reads back as absent on cf_get_ai_gateway_billing_topup_configs. DELETE /accounts//ai-gateway/billing/topup/config. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_billing_credit_balances details
cf_get_ai_gateway_billing_credit_balances details
[Cloudflare] Get credit balance. The reach-first read for AI Gateway Unified Billing: the current credit balance, the payment method on file and the auto top-up configuration in one response. Read it before any of the top-up tools, which spend real money. GET /accounts//ai-gateway/billing/credit-balance. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_billing_invoice_histories details
cf_get_ai_gateway_billing_invoice_histories details
[Cloudflare] Get invoice history. Past AI Gateway invoices for the account, newest first. GET /accounts//ai-gateway/billing/invoice-history. Path parameters: account_id. Optional filters: type. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_billing_invoice_previews details
cf_get_ai_gateway_billing_invoice_previews details
[Cloudflare] Get invoice preview. What the next AI Gateway invoice would look like today, with line items and tax. A preview only - it charges nothing. GET /accounts//ai-gateway/billing/invoice-preview. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_billing_spending_limits details
cf_get_ai_gateway_billing_spending_limits details
[Cloudflare] Get spending limit. The spending limit currently configured for the account. The matching write, cf_create_ai_gateway_billing_spending_limit, is deprecated and always refuses; cf_delete_ai_gateway_billing_spending_limit is the one change still accepted. GET /accounts//ai-gateway/billing/spending-limit. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_billing_topup_configs details
cf_get_ai_gateway_billing_topup_configs details
[Cloudflare] Get auto top-up configuration. The current auto top-up threshold and amount, plus any error state from the last automatic charge. Auto top-up charges the card without asking again, so read this before changing it. GET /accounts//ai-gateway/billing/topup/config. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_billing_topup_limits details
cf_get_ai_gateway_billing_topup_limits details
[Cloudflare] Get account top-up limits. The smallest and largest top-up this account may buy, in cents. Read it before cf_create_ai_gateway_billing_topup, which spends real money. GET /accounts//ai-gateway/billing/topup/limits. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_billing_topup_status details
cf_get_ai_gateway_billing_topup_status details
[Cloudflare] Check top-up status. A POST that only ASKS: how a top-up charge settled. It moves no money and changes nothing, so it ships as a read. POST /accounts//ai-gateway/billing/topup/status. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_billing_usage_histories details
cf_get_ai_gateway_billing_usage_histories details
[Cloudflare] Get usage history. Aggregated AI Gateway usage meters over a time window, which is what an invoice is built from. It is metering rather than per-request logs - cf_list_ai_gateway_logs is the request log. GET /accounts//ai-gateway/billing/usage-history. Path parameters: account_id. Cloudflare REQUIRES this query parameter and answers 400 without it: value_grouping_window. Optional filters: start_time, end_time. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
AI Gateway Custom Providers
cf_create_ai_gateway_custom_provider details
cf_create_ai_gateway_custom_provider details
[Cloudflare] Create a new Account Provider. Additive: creates a new record and changes no existing one. Adds an AI provider of the account's own to AI Gateway. The slug you choose is how the provider is named in a gateway provider config and in a dynamic route. POST /accounts//ai-gateway/custom-providers. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_gateway_custom_providers_cost details
cf_create_ai_gateway_custom_providers_cost details
[Cloudflare] Create a new Account Provider Cost. Additive: creates a new record and changes no existing one. Adds a price rule so AI Gateway can cost requests to a custom provider. It changes what usage REPORTS say; it does not change what any vendor charges. POST /accounts//ai-gateway/custom-providers/costs. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_gateway_custom_provider details
cf_delete_ai_gateway_custom_provider details
[Cloudflare] DESTRUCTIVE: Delete a Account Provider. Why this is destructive: Removes the custom provider from the account. Any gateway provider config or dynamic route that named it stops resolving to it, and its price rules go with it. The API offers no undo; putting it back means recreating the provider and its costs. DELETE /accounts//ai-gateway/custom-providers/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_gateway_custom_providers_cost details
cf_delete_ai_gateway_custom_providers_cost details
[Cloudflare] DESTRUCTIVE: Delete a Account Provider Cost. Why this is destructive: Removes one price rule from a custom provider. Requests AI Gateway logs afterwards are costed by whatever rule is left, or not costed at all, so usage reporting for that model changes. It does not change what the provider charges, and the API offers no undo. DELETE /accounts//ai-gateway/custom-providers/costs/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_custom_provider details
cf_get_ai_gateway_custom_provider details
[Cloudflare] Fetch a Account Provider. One custom provider by id. Cloudflare's own summary for this operation says dataset; the path and its schema are a provider. GET /accounts//ai-gateway/custom-providers/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_custom_providers_cost details
cf_get_ai_gateway_custom_providers_cost details
[Cloudflare] Fetch a Account Provider Cost. One price rule by id. Cloudflare's own summary for this operation says dataset; the path and its schema are a provider cost. GET /accounts//ai-gateway/custom-providers/costs/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_ai_gateway_custom_providers details
cf_list_ai_gateway_custom_providers details
[Cloudflare] List Account Providers. The reach-first read for custom providers: AI model providers the account has added to AI Gateway beyond the ones Cloudflare ships. The id on each row is what cf_get_ai_gateway_custom_provider, cf_update_ai_gateway_custom_provider and cf_delete_ai_gateway_custom_provider take, and the beta filter selects providers Cloudflare marks beta. Cloudflare's own summary for this operation says evaluator types; the path and its schema are providers. GET /accounts//ai-gateway/custom-providers. Path parameters: account_id. Optional filters: page, per_page, beta, enable, search. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_list_ai_gateway_custom_providers_costs details
cf_list_ai_gateway_custom_providers_costs details
[Cloudflare] List Account Provider Costs. Per-model price rules attached to the account's custom providers, which is what AI Gateway uses to put a cost on a logged request. Filter by account_provider_id to see one provider's rules. Cloudflare's own summary for this operation says evaluator types; the path and its schema are provider costs. GET /accounts//ai-gateway/custom-providers/costs. Path parameters: account_id. Optional filters: page, per_page, enable, account_provider_id, model_rule, cost_type, search. Page size defaults to 100, which is also the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_ai_gateway_custom_provider details
cf_update_ai_gateway_custom_provider details
[Cloudflare] Update a Account Provider. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//ai-gateway/custom-providers/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_update_ai_gateway_custom_providers_cost details
cf_update_ai_gateway_custom_providers_cost details
[Cloudflare] Update a Account Provider Cost. Partial update: Cloudflare applies only the fields present in the body and leaves the rest as they are. PATCH /accounts//ai-gateway/custom-providers/costs/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
AI Gateway Evaluation Types
cf_list_ai_gateway_evaluation_types details
cf_list_ai_gateway_evaluation_types details
[Cloudflare] List Evaluators. The evaluators AI Gateway can score logged responses with. The ids it returns are what cf_create_ai_gateway_gateways_evaluation takes in evaluation_type_ids. Account-wide, not per gateway. GET /accounts//ai-gateway/evaluation-types. Path parameters: account_id. Optional filters: page, per_page, order_by, order_by_direction. Page size defaults to 50, which is this endpoint's own maximum and the ceiling StackJack applies here. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
AI Gateway Gateways
cf_create_ai_gateway_gateway details
cf_create_ai_gateway_gateway details
[Cloudflare] Create a new Gateway. Additive: creates a new record and changes no existing one. Creates a gateway. The id you choose becomes part of the gateway's public URL, which cf_get_ai_gateway_gateways_url returns per provider. POST /accounts//ai-gateway/gateways. Path parameters: account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_gateway_gateways_custom_domain details
cf_create_ai_gateway_gateways_custom_domain details
[Cloudflare] Create a custom domain for a gateway. Provisions a new hostname and a certificate for it. Nothing existing is replaced, but the domain does not serve until the customer points DNS at the CNAME target this returns. Provisions a Cloudflare for SaaS custom hostname for the gateway and returns the CNAME target the customer's DNS has to point at. Nothing serves on the domain until that DNS record exists and the certificate is issued. POST /accounts//ai-gateway/gateways//custom-domains. Path parameters: account_id, gateway_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_gateway_gateways_dataset details
cf_create_ai_gateway_gateways_dataset details
[Cloudflare] Create a new Dataset. Additive: creates a new record and changes no existing one. POST /accounts//ai-gateway/gateways//datasets. Path parameters: gateway_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_gateway_gateways_evaluation details
cf_create_ai_gateway_gateways_evaluation details
[Cloudflare] Create a new Evaluation. Creates a new evaluation run and leaves existing ones alone. Scoring runs models, so the run is metered usage charged to the account. Starts an evaluation run. Scoring logged responses runs models, so an evaluation is metered usage on the account. POST /accounts//ai-gateway/gateways//evaluations. Path parameters: gateway_id, account_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_gateway_gateways_provider_config details
cf_create_ai_gateway_gateways_provider_config details
[Cloudflare] Create a new Provider Configs. Stores a live provider credential on the gateway. From the moment it succeeds the gateway authenticates to that provider with the key you sent, so a wrong value breaks every request routed to that provider until it is corrected. Stores the customer's own API key for one upstream provider on this gateway, which is what byok_only mode requires. Cloudflare returns secret_id and a preview, never the key. POST /accounts//ai-gateway/gateways//provider_configs. Path parameters: account_id, gateway_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_gateway_gateways_route details
cf_create_ai_gateway_gateways_route details
[Cloudflare] Create a new AI Gateway Dynamic Route. Additive: creates a new record and changes no existing one. Creates a dynamic route. It does not start serving until a version is deployed with cf_create_ai_gateway_gateways_routes_deployment. POST /accounts//ai-gateway/gateways//routes. Path parameters: account_id, gateway_id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_gateway_gateways_routes_deployment details
cf_create_ai_gateway_gateways_routes_deployment details
[Cloudflare] Create a new AI Gateway Dynamic Route Deployment. Puts a route version into service. Live gateway traffic is routed by the new version from the moment it succeeds and the previous one stops serving. Nothing is deleted - rolling back means deploying the previous version_id again. Makes one version of a dynamic route the live one. Read cf_list_ai_gateway_gateways_routes_deployments first so you know what is being replaced. POST /accounts//ai-gateway/gateways//routes//deployments. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_create_ai_gateway_gateways_routes_version details
cf_create_ai_gateway_gateways_routes_version details
[Cloudflare] Create a new AI Gateway Dynamic Route Version. Additive: creates a new record and changes no existing one. Saves a new definition of a dynamic route WITHOUT putting it into service. cf_create_ai_gateway_gateways_routes_deployment is what makes it live. POST /accounts//ai-gateway/gateways//routes//versions. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_gateway_gateway details
cf_delete_ai_gateway_gateway details
[Cloudflare] DESTRUCTIVE: Delete a Gateway. Why this is destructive: Deletes the WHOLE gateway named by id - its configuration, its custom domains, its datasets, its evaluations and its logs. Every application still pointing at that gateway URL starts failing. Mind the near-identical name: cf_delete_ai_gateway_logs, plural, deletes only LOG ENTRIES and leaves the gateway alone. The API offers no undo. Cloudflare's own summary for this operation says dataset; the path is the gateway itself. DELETE /accounts//ai-gateway/gateways/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_gateway_gateways_custom_domain details
cf_delete_ai_gateway_gateways_custom_domain details
[Cloudflare] DESTRUCTIVE: Delete a Custom Domain. Why this is destructive: Removes the custom hostname from the gateway. Anything calling the gateway on that hostname stops working immediately; the gateway's own cloudflare URL is unaffected. The API offers no undo, and adding it back provisions a new certificate. DELETE /accounts//ai-gateway/gateways//custom-domains/. Path parameters: account_id, gateway_id, hostname. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_gateway_gateways_dataset details
cf_delete_ai_gateway_gateways_dataset details
[Cloudflare] DESTRUCTIVE: Delete a Dataset. Why this is destructive: Removes the saved log filter. Evaluations that named this dataset lose their input, and scores already computed from it are no longer reproducible. The API offers no undo. DELETE /accounts//ai-gateway/gateways//datasets/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_gateway_gateways_evaluation details
cf_delete_ai_gateway_gateways_evaluation details
[Cloudflare] DESTRUCTIVE: Delete a Evaluation. Why this is destructive: Removes the evaluation run and the scores it produced. The logs it scored stay; the result does not, and re-running it costs another metered evaluation. DELETE /accounts//ai-gateway/gateways//evaluations/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_gateway_gateways_provider_config details
cf_delete_ai_gateway_gateways_provider_config details
[Cloudflare] DESTRUCTIVE: Delete a Provider Configs. Why this is destructive: Removes the stored credential and the routing entry for one upstream provider on this gateway. Every request the gateway routes to that provider starts failing authentication immediately, and the key itself is gone - putting it back means having the original value again. The API offers no undo. DELETE /accounts//ai-gateway/gateways//provider_configs/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_gateway_gateways_route details
cf_delete_ai_gateway_gateways_route details
[Cloudflare] DESTRUCTIVE: Delete an AI Gateway Dynamic Route. Why this is destructive: Removes the dynamic route, its versions and its deployments. Requests that matched it stop being routed by it from that moment, which for a gateway relying on it is an outage rather than a configuration change. The API offers no undo. DELETE /accounts//ai-gateway/gateways//routes/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_delete_ai_gateway_logs details
cf_delete_ai_gateway_logs details
[Cloudflare] DESTRUCTIVE: Delete Gateway Logs. Why this is destructive: Bulk-deletes the gateway request logs. CRITICAL: limit here is how MANY entries are DELETED, not a page size, and omitting it does not mean one - StackJack always sends an explicit limit and resolves an omitted one to 100, so a call with no arguments beyond the ids destroys up to 100 log entries. Ask for more and StackJack trims it to 1000. Narrow with filters and order_by first, read the same selection back with cf_list_ai_gateway_logs, and expect no undo: the logs are the only record of what was proxied and what it cost. This deletes LOG ENTRIES, not the gateway. cf_delete_ai_gateway_gateway, singular, is the one that deletes the gateway itself. DELETE /accounts//ai-gateway/gateways//logs. Path parameters: account_id, gateway_id. Optional filters: order_by, order_by_direction, filters, limit. Page size defaults to 100 and this endpoint accepts up to 1000. Cloudflare's request budget is counted per user and shared with the customer's own dashboard session, so prefer one larger page over many small calls. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_gateway details
cf_get_ai_gateway_gateway details
[Cloudflare] Fetch a Gateway. ONE gateway by id, the whole configuration. Mind the near-identical name: cf_list_ai_gateway_logs, plural, is the LOG list for a gateway, and cf_list_ai_gateway_gateways is the list of gateways. Cloudflare's own summary for this operation says dataset; the path and its schema are a gateway. GET /accounts//ai-gateway/gateways/. Path parameters: account_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_gateways_custom_domain details
cf_get_ai_gateway_gateways_custom_domain details
[Cloudflare] Fetch a Custom Domain. One custom hostname by name, with its provisioning status. Cloudflare's own summary for this operation says dataset; the path and its schema are a custom domain. GET /accounts//ai-gateway/gateways//custom-domains/. Path parameters: account_id, gateway_id, hostname. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_gateways_dataset details
cf_get_ai_gateway_gateways_dataset details
[Cloudflare] Fetch a Dataset. One dataset by id, with the filters that define it. Cloudflare's own summary for this operation says an AI Gateway dataset, and here that is accurate. GET /accounts//ai-gateway/gateways//datasets/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_gateways_evaluation details
cf_get_ai_gateway_gateways_evaluation details
[Cloudflare] Fetch a Evaluation. One evaluation run with its scores. Cloudflare's own summary for this operation says dataset; the path and its schema are an evaluation. GET /accounts//ai-gateway/gateways//evaluations/. Path parameters: account_id, gateway_id, id. Returns the raw Cloudflare response envelope {success, errors, messages, result, result_info} exactly as the vendor sent it - the payload is under result and any paging metadata under result_info.
cf_get_ai_gateway_gateways_log details
cf_get_ai_gateway_gateways_log details
[Cloudflare] Get Gateway Log Detail. One log
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team