openapi: 3.2.0 info: description: Welcome to Cloudflare's API documentation site. license: name: BSD-3-Clause url: https://opensource.org/licenses/BSD-3-Clause title: Cloudflare Resources API version: 4.0.0 servers: - description: Client API url: https://api.cloudflare.com/client/v4 security: - api_email: [] api_key: [] - api_token: [] - user_service_key: [] tags: - name: Resources paths: /accounts/{account_id}/magic/cloud/resources: get: operationId: resources-catalog-list summary: List Resources description: List resources in the Resource Catalog (Closed Beta). parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/mcn_account_id' - name: provider_id in: query schema: type: string - name: resource_type in: query schema: type: array items: $ref: '#/components/schemas/mcn_resource_type' - name: resource_id in: query schema: type: array items: $ref: '#/components/schemas/mcn_resource_id' - name: region in: query schema: type: string - name: resource_group in: query schema: type: string - name: managed in: query schema: type: boolean - name: search in: query schema: type: array items: type: string - name: order_by in: query description: One of ["id", "resource_type", "region"]. schema: type: string - name: desc in: query schema: type: boolean - name: per_page in: query schema: type: integer minimum: 1 - name: page in: query schema: type: integer minimum: 1 - name: cloudflare in: query schema: type: boolean - name: v2 in: query schema: type: boolean responses: '200': description: OK. content: application/json: schema: $ref: '#/components/schemas/mcn_read_account_resources_response' '400': description: Bad Request. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '401': description: Invalid Credentials. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '403': description: Forbidden. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '404': description: Not Found. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '500': description: Internal Server Error. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' security: - api_email: [] api_key: [] api_token: [] tags: - Resources x-api-token-group: - Magic WAN Write - Magic WAN Read x-fern-availability: beta x-fern-sdk-group-name: magic-cloud-networking.resources x-fern-sdk-method-name: list x-forge-hidden: true /accounts/{account_id}/magic/cloud/resources/export: get: operationId: resources-catalog-export summary: Export Resources description: Export resources in the Resource Catalog as a JSON file (Closed Beta). parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/mcn_account_id' - name: provider_id in: query schema: type: string - name: resource_type in: query schema: type: array items: $ref: '#/components/schemas/mcn_resource_type' - name: resource_id in: query schema: type: array items: $ref: '#/components/schemas/mcn_resource_id' - name: region in: query schema: type: string - name: resource_group in: query schema: type: string - name: search in: query schema: type: array items: type: string - name: order_by in: query description: One of ["id", "resource_type", "region"]. schema: type: string - name: desc in: query schema: type: boolean - name: v2 in: query schema: type: boolean responses: '200': description: Exported file. headers: Content-Disposition: schema: type: string example: attachment; filename="exported_resources.zip" content: application/octet-stream: schema: type: string format: binary '400': description: Bad Request. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '401': description: Invalid Credentials. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '403': description: Forbidden. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '404': description: Not Found. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '500': description: Internal Server Error. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' security: - api_email: [] api_key: [] api_token: [] tags: - Resources x-api-token-group: - Magic WAN Write - Magic WAN Read x-fern-availability: beta x-fern-sdk-group-name: magic-cloud-networking.resources x-fern-sdk-method-name: export x-forge-hidden: true /accounts/{account_id}/magic/cloud/resources/policy-preview: post: operationId: resources-catalog-policy-preview summary: Preview Rego Query description: Preview Rego query result against the latest resource catalog (Closed Beta). parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/mcn_account_id' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/mcn_resources_catalog_policy_preview_request' responses: '200': description: OK. content: application/json: schema: $ref: '#/components/schemas/mcn_resources_catalog_policy_preview_response' '400': description: Bad Request. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '401': description: Invalid Credentials. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '403': description: Forbidden. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '422': description: Unprocessable Entity. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '500': description: Internal Server Error. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' security: - api_email: [] api_key: [] api_token: [] tags: - Resources x-fern-availability: beta x-fern-sdk-group-name: magic-cloud-networking.resources x-fern-sdk-method-name: policy-preview x-forge-hidden: true /accounts/{account_id}/magic/cloud/resources/{resource_id}: get: operationId: resources-catalog-read summary: Read Resource description: Read an resource from the Resource Catalog (Closed Beta). parameters: - name: account_id in: path required: true schema: $ref: '#/components/schemas/mcn_account_id' - name: resource_id in: path required: true schema: $ref: '#/components/schemas/mcn_resource_id' - name: v2 in: query schema: type: boolean responses: '200': description: OK. content: application/json: schema: $ref: '#/components/schemas/mcn_read_account_resource_response' '400': description: Bad Request. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '401': description: Invalid Credentials. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '403': description: Forbidden. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '404': description: Not Found. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' '500': description: Internal Server Error. content: application/json: schema: $ref: '#/components/schemas/mcn_bad_response' security: - api_email: [] api_key: [] api_token: [] tags: - Resources x-api-token-group: - Magic WAN Write - Magic WAN Read x-fern-availability: beta x-fern-sdk-group-name: magic-cloud-networking.resources x-fern-sdk-method-name: get x-forge-hidden: true components: schemas: mcn_resources_catalog_policy_preview: type: string mcn_resource_preview_item: type: object properties: item_type: type: string x-auditable: true resource_preview: $ref: '#/components/schemas/mcn_resource_preview' required: - item_type - resource_preview mcn_yaml_diff_item: type: object properties: item_type: type: string yaml_diff: $ref: '#/components/schemas/mcn_yaml_diff' required: - item_type - yaml_diff mcn_read_account_resource_response: type: object allOf: - $ref: '#/components/schemas/mcn_good_response' - properties: result: $ref: '#/components/schemas/mcn_resource_details' type: object mcn_read_account_resources_response: type: object allOf: - $ref: '#/components/schemas/mcn_good_response_collection' - properties: result: type: array items: $ref: '#/components/schemas/mcn_resource_details' result_info: $ref: '#/components/schemas/mcn_result_info' type: object mcn_response_collection: type: object properties: messages: type: array items: $ref: '#/components/schemas/mcn_error' result_info: $ref: '#/components/schemas/mcn_result_info' success: type: boolean required: - result - success - errors - messages mcn_observation: type: object properties: first_observed_at: type: string x-auditable: true last_observed_at: type: string x-auditable: true provider_id: $ref: '#/components/schemas/mcn_provider_id' resource_id: $ref: '#/components/schemas/mcn_resource_id' required: - provider_id - resource_id - first_observed_at - last_observed_at mcn_platform_client_id: type: string format: uuid x-auditable: true mcn_good_response: type: object allOf: - $ref: '#/components/schemas/mcn_response' - properties: errors: type: array items: $ref: '#/components/schemas/mcn_error' maxLength: 0 type: object mcn_result_info: type: object properties: count: description: The number of items in the current result set. type: integer example: 1 page: description: The current page (starts from zero). type: integer example: 1 per_page: description: The maximum number of items per page. type: integer example: 20 total_count: description: The total number of items in the entire result set. type: integer example: 2000 total_pages: description: The number of total pages in the entire result set. type: integer example: 200 required: - page - per_page - count - total_count mcn_bad_response: type: object allOf: - $ref: '#/components/schemas/mcn_response' - properties: errors: type: array items: $ref: '#/components/schemas/mcn_error' minLength: 1 result: type: - object - 'null' enum: - null type: object mcn_error: type: object properties: code: type: integer enum: - 1001 - 1002 - 1003 - 1004 - 1005 - 1006 - 1007 - 1008 - 1009 - 1010 - 1011 - 1012 - 1013 - 1014 - 1015 - 1016 - 1017 - 1018 - 2001 - 2002 - 2003 - 2004 - 2005 - 2006 - 2007 - 2008 - 2009 - 2010 - 2011 - 2012 - 2013 - 2014 - 2015 - 2016 - 2017 - 2018 - 2019 - 2020 - 2021 - 2022 - 3001 - 3002 - 3003 - 3004 - 3005 - 3006 - 3007 - 4001 - 4002 - 4003 - 4004 - 4005 - 4006 - 4007 - 4008 - 4009 - 4010 - 4011 - 4012 - 4013 - 4014 - 4015 - 4016 - 4017 - 4018 - 4019 - 4020 - 4021 - 4022 - 4023 - 5001 - 5002 - 5003 - 5004 - 102000 - 102001 - 102002 - 102003 - 102004 - 102005 - 102006 - 102007 - 102008 - 102009 - 102010 - 102011 - 102012 - 102013 - 102014 - 102015 - 102016 - 102017 - 102018 - 102019 - 102020 - 102021 - 102022 - 102023 - 102024 - 102025 - 102026 - 102027 - 102028 - 102029 - 102030 - 102031 - 102032 - 102033 - 102034 - 102035 - 102036 - 102037 - 102038 - 102039 - 102040 - 102041 - 102042 - 102043 - 102044 - 102045 - 102046 - 102047 - 102048 - 102049 - 102050 - 102051 - 102052 - 102053 - 102054 - 102055 - 102056 - 102057 - 102058 - 102059 - 102060 - 102061 - 102062 - 102063 - 102064 - 102065 - 102066 - 102067 - 102068 - 102069 - 102070 - 102071 - 102072 - 103001 - 103002 - 103003 - 103004 - 103005 - 103006 - 103007 - 103008 x-auditable: true documentation_url: type: string message: type: string meta: $ref: '#/components/schemas/mcn_error_meta' source: $ref: '#/components/schemas/mcn_error_source' required: - code - message mcn_error_source: type: object properties: parameter: type: string x-auditable: true parameter_value_index: type: integer x-auditable: true pointer: type: string x-auditable: true mcn_cloud_platform_client: type: object properties: client_type: type: string enum: - MAGIC_WAN_CLOUD_ONRAMP x-auditable: true id: $ref: '#/components/schemas/mcn_platform_client_id' name: type: string x-auditable: true required: - client_type - name - id mcn_resource_details_section: type: object properties: help_text: type: string hidden_items: type: array items: $ref: '#/components/schemas/mcn_resource_details_section_item' name: type: string visible_items: type: array items: $ref: '#/components/schemas/mcn_resource_details_section_item' required: - name - visible_items - hidden_items mcn_resource_preview: type: object properties: cloud_type: $ref: '#/components/schemas/mcn_cloud_type' detail: type: string id: $ref: '#/components/schemas/mcn_resource_id' name: type: string resource_type: $ref: '#/components/schemas/mcn_resource_type' title: type: string required: - id - cloud_type - resource_type - name - title - detail mcn_good_response_collection: type: object allOf: - $ref: '#/components/schemas/mcn_response_collection' - properties: errors: type: array items: $ref: '#/components/schemas/mcn_error' maxLength: 0 type: object mcn_error_meta: type: object properties: l10n_key: type: string x-auditable: true loggable_error: type: string template_data: type: object trace_id: type: string x-auditable: true mcn_yaml_item: type: object properties: item_type: type: string yaml: type: string required: - item_type - yaml mcn_string_item: type: object properties: item_type: type: string string: type: string required: - item_type - string mcn_resources_catalog_policy_preview_request: type: object properties: policy: type: string required: - policy mcn_yaml_diff: type: object properties: diff: type: string left_description: type: string left_yaml: type: string right_description: type: string right_yaml: type: string required: - left_yaml - left_description - right_yaml - right_description - diff mcn_list_item: type: object properties: item_type: type: string list: type: array items: discriminator: propertyName: item_type oneOf: - $ref: '#/components/schemas/mcn_string_item' - $ref: '#/components/schemas/mcn_resource_preview_item' type: object required: - item_type - list mcn_account_id: type: string x-auditable: true mcn_resource_id: type: string format: uuid x-auditable: true mcn_resource_type: type: string enum: - aws_customer_gateway - aws_egress_only_internet_gateway - aws_internet_gateway - aws_instance - aws_network_interface - aws_route - aws_route_table - aws_route_table_association - aws_subnet - aws_vpc - aws_vpc_ipv4_cidr_block_association - aws_vpn_connection - aws_vpn_connection_route - aws_vpn_gateway - aws_security_group - aws_vpc_security_group_ingress_rule - aws_vpc_security_group_egress_rule - aws_ec2_managed_prefix_list - aws_ec2_transit_gateway - aws_ec2_transit_gateway_prefix_list_reference - aws_ec2_transit_gateway_vpc_attachment - azurerm_application_security_group - azurerm_lb - azurerm_lb_backend_address_pool - azurerm_lb_nat_pool - azurerm_lb_nat_rule - azurerm_lb_rule - azurerm_local_network_gateway - azurerm_network_interface - azurerm_network_interface_application_security_group_association - azurerm_network_interface_backend_address_pool_association - azurerm_network_interface_security_group_association - azurerm_network_security_group - azurerm_public_ip - azurerm_route - azurerm_route_table - azurerm_subnet - azurerm_subnet_route_table_association - azurerm_virtual_machine - azurerm_virtual_network_gateway_connection - azurerm_virtual_network - azurerm_virtual_network_gateway - google_compute_network - google_compute_subnetwork - google_compute_vpn_gateway - google_compute_vpn_tunnel - google_compute_route - google_compute_address - google_compute_global_address - google_compute_router - google_compute_interconnect_attachment - google_compute_ha_vpn_gateway - google_compute_forwarding_rule - google_compute_network_firewall_policy - google_compute_network_firewall_policy_rule - cloudflare_static_route - cloudflare_ipsec_tunnel x-auditable: true mcn_response: type: object properties: messages: type: array items: $ref: '#/components/schemas/mcn_error' success: type: boolean x-auditable: true required: - result - success - errors - messages mcn_provider_id: type: string format: uuid x-auditable: true mcn_resource_details: type: object properties: account_id: $ref: '#/components/schemas/mcn_account_id' cloud_type: $ref: '#/components/schemas/mcn_cloud_type' config: type: object additionalProperties: true deployment_provider: $ref: '#/components/schemas/mcn_provider_id' id: $ref: '#/components/schemas/mcn_resource_id' managed: type: boolean x-auditable: true managed_by: type: array items: $ref: '#/components/schemas/mcn_cloud_platform_client' monthly_cost_estimate: $ref: '#/components/schemas/mcn_cost' name: type: string native_id: type: string observations: type: object additionalProperties: $ref: '#/components/schemas/mcn_observation' provider_ids: type: array items: $ref: '#/components/schemas/mcn_provider_id' provider_names_by_id: type: object additionalProperties: type: string region: type: string x-auditable: true resource_group: type: string x-auditable: true resource_type: $ref: '#/components/schemas/mcn_resource_type' sections: type: array items: $ref: '#/components/schemas/mcn_resource_details_section' state: type: object additionalProperties: true tags: type: object additionalProperties: type: string updated_at: type: string url: type: string required: - id - native_id - name - account_id - cloud_type - resource_type - managed - provider_ids - provider_names_by_id - region - resource_group - tags - updated_at - url - config - state - observations - deployment_provider - sections - monthly_cost_estimate mcn_resource_details_section_item: type: object properties: helpText: type: string name: type: string value: type: object discriminator: propertyName: item_type oneOf: - $ref: '#/components/schemas/mcn_string_item' - $ref: '#/components/schemas/mcn_yaml_item' - $ref: '#/components/schemas/mcn_yaml_diff_item' - $ref: '#/components/schemas/mcn_resource_preview_item' - $ref: '#/components/schemas/mcn_list_item' mcn_cloud_type: type: string enum: - AWS - AZURE - GOOGLE - CLOUDFLARE x-auditable: true mcn_resources_catalog_policy_preview_response: type: object allOf: - $ref: '#/components/schemas/mcn_good_response' - properties: result: $ref: '#/components/schemas/mcn_resources_catalog_policy_preview' type: object mcn_cost: type: object properties: currency: type: string x-auditable: true monthly_cost: type: number format: double required: - monthly_cost - currency securitySchemes: api_email: in: header name: X-Auth-Email type: apiKey api_key: in: header name: X-Auth-Key type: apiKey api_token: scheme: bearer type: http user_service_key: in: header name: X-Auth-User-Service-Key type: apiKey externalDocs: description: Cloudflare Radar Documentation url: https://developers.cloudflare.com/radar/ x-forge-commands: abuse-reports: description: Submit and track abuse reports for phishing, malware, and other policy violations on Cloudflare-proxied sites groups: appeals: description: Appeal eligibility for abuse reports emails: description: Emails sent for abuse reports mitigations: description: Mitigation actions taken in response to abuse reports accounts: description: Account settings, members, roles, subscriptions, and API tokens for your Cloudflare account groups: applications: description: Applications operations categories: description: Categories operations organizations: description: Move accounts between organizations profile: description: View and manage the profile for a Cloudflare account roles: description: View the roles available for assigning to account members, each defining a set of permissions subscriptions: description: View and manage plan subscriptions attached to this account tokens: description: Create and manage scoped API tokens for programmatic access to the Cloudflare API ai-gateway: description: Proxy, cache, rate-limit, and observe requests to AI providers — OpenAI, Anthropic, Workers AI, and more groups: custom-domains: description: Manage custom hostnames that route requests through an AI Gateway custom-providers: description: Manage account-level custom AI providers and their endpoint settings datasets: description: 'Deprecated: manage filtered collections of gateway logs used by evaluations' dynamic-routing: description: Route requests across multiple AI providers with fallback, load-balancing, and versioned deployments dynamic-routing.deployments: description: Deploy dynamic route versions and view deployment history dynamic-routing.versions: description: Create and inspect saved versions of a dynamic route evaluation-types: description: 'Deprecated: list the evaluator types that evaluations can use' evaluations: description: 'Deprecated: score the logs in a dataset with selected evaluator types' gateways: description: Create and configure AI Gateways for an account gateways.providers: description: Store and rotate upstream AI provider keys for a gateway logs: description: Inspect, annotate, and delete gateway request logs stored by Legacy Logs ai-search: description: 'Managed search-as-a-service: crawl, index, and query content with AI-powered relevance and chat completions' groups: items: description: Content indexed by AI Search instances jobs: description: Indexing job lifecycle for AI Search instances namespace: description: Logical groupings for organizing AI Search instances tokens: description: Credentials used by AI Search instances ai-security: description: Detect prompt injection, PII, and unsafe topics in traffic to your AI applications groups: custom-topics: description: Organization-specific topic categories used by AI Security for Apps content detection analytics: description: Zone-level traffic analytics — dashboard summaries, per-colo breakdowns, and Argo latency metrics groups: colo: description: Per-data-center (colo) traffic analytics breakdown for the zone dashboard: description: Aggregated zone dashboard analytics — requests, bandwidth, threats, and page views latency: description: Argo Smart Routing latency analytics showing time-to-first-byte improvements argo: description: Network optimization features that speed up and improve reliability of traffic to your origins groups: smart-routing: description: Route traffic through the fastest network paths to your origin using real-time latency data tiered-caching: description: Reduce origin load by having upper-tier data centers serve cache misses before reaching your origin basin-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables billing: description: Account billing profiles and usage data for Cloudflare subscriptions and add-on services groups: profiles: description: Billing profile with payment method, address, and invoice preferences usage: description: Metered usage data for billed services — requests, bandwidth, and feature consumption botnet-feed: description: Botnet threat intelligence feeds — IP and ASN-level data on known command-and-control infrastructure groups: asn: description: ASN-level botnet activity data showing networks with known C2 infrastructure configs: description: Botnet feed subscription configuration and notification preferences builds: description: Build and deploy Workers from connected repositories, then inspect build status and logs. groups: deploy-hooks: description: Manage branch-specific HTTP hooks that start builds. limits: description: View build-minute availability and refresh information. logs: description: Retrieve build logs. repos: description: Manage source repository connections for Workers Builds. tokens: description: Manage credentials used by Workers Builds to deploy Workers. triggers: description: Configure how repository changes build and deploy Workers. versions: description: Find builds associated with Worker versions. workers: description: Manage repository-backed build configuration for Workers. cache: description: Purge cached content and configure Cache Reserve, tiered caching, and variant serving groups: origin-cloud-regions: description: Manage Origin Cloud Regions routing and failover configurations settings: description: Configure Cache Reserve, tiered caching, and variant serving settings.regional-tiered-cache: description: Restrict tiered cache topology to data centers within a specific geographic region settings.reserve: description: Persistent storage tier that keeps cached assets even after eviction from edge caches settings.smart-tiered-cache: description: Automatically determine the best upper-tier data centers for tiered cache topology settings.variants: description: Serve different cached versions of an image based on the Accept header (WebP, AVIF, etc.) client-side-security: description: Client-Side Security — monitor JavaScript, connections, and cookies on your pages for supply-chain attacks groups: connections: description: Third-party connections made by scripts on your pages — track data exfiltration risks cookies: description: Cookies set by your pages with classification and same-site attribute tracking policies: description: Content Security Policies that control which scripts and connections are allowed on your pages scripts: description: JavaScript files detected on your pages with change tracking and malicious code detection settings: description: Fine tune Client-Side Security behaviors cloud-connector: description: Route traffic from Cloudflare directly to cloud provider services (AWS, Azure, GCP) without origin servers groups: rules: description: Routing rules that map request patterns to cloud provider endpoints cloudforce-one: description: Detection rule management APIs groups: binary-storage: description: Upload and retrieve malware samples and suspicious binaries for analysis requests: description: Additional request operations — priority listing and asset creation rules: description: Rule management operations groups: approvals: description: Approval workflow operations email: description: Email rule operations exemptions: description: Exemption rule operations managed: description: Managed rule operations stats: description: Rule statistics operations tree: description: Rule navigation tree operations scans: description: Scan URLs, IPs, and domains for threat intelligence indicators containers: description: Deploy and manage Containers applications on Cloudflare's global network groups: applications: description: Manage Containers applications applications.instances: description: Inspect Containers instances belonging to applications applications.rollouts: description: Manage rollouts for scheduler-backed applications applications.versions: description: Inspect versions of scheduler-backed applications registries: description: Manage Containers image registries registries.credentials: description: Generate image registry credentials content-scan: description: Malicious uploads detection, scan uploaded content in HTTP requests for malware and malicious payloads groups: expressions: description: Custom expressions that tell the scanner how to reach content objects it cannot parse on its own custom-pages: description: Manage custom error and challenge pages and their assets for accounts and zones groups: account-custom-pages: description: Manage account-level custom pages account-custom-pages.preview-tokens: description: Preview tokens for account-level custom pages assets: description: Manage account- and zone-level custom assets zone-custom-pages: description: Manage zone-level custom pages zone-custom-pages.preview-tokens: description: Preview tokens for zone-level custom pages d1: description: D1 is Cloudflare's managed, serverless database with SQLite's SQL semantics, built-in disaster recovery, and Worker and HTTP API access. groups: time-travel: description: use specific point-in-time backups of your D1 database x-forge-epilogue: For more information about Time Travel, see https://developers.cloudflare.com/d1/reference/time-travel diagnostics: description: Network diagnostic tools — traceroutes from Cloudflare's edge and endpoint health checks groups: endpoint-healthchecks: description: Monitor external endpoint availability with periodic HTTP/HTTPS health checks traceroutes: description: Run traceroutes from Cloudflare data centers to diagnose network path issues email-routing: description: Route incoming email to verified destination addresses or Workers with routing rules, catch-all behavior, and managed DNS records groups: addresses: description: Verified destination email addresses that can receive forwarded mail dns: description: Inspect or unlock the DNS records required by Email Routing rules: description: Match incoming email addresses and forward messages to destination mailboxes or Workers settings: description: Inspect and update Email Routing settings email-security: description: Cloud email security — investigate threats, manage allow/block policies, and detect phishing groups: analytics: description: Analytics and reporting — monthly report and per-day breakdowns of threat activity bulk-actions: description: Asynchronous jobs that move or release every message matching a search — create, monitor, and manage bulk jobs investigate: description: Search and investigate email messages — view detections, traces, raw content, and take remediation actions phishguard: description: PhishGuard user-reported phishing reports — view detected threats for a date range settings: description: Email security configuration — block senders, allow policies, content policies, domains, trusted domains, impersonation registry, and URL handling submissions: description: Reclassify submissions — track user and team reports of false positives and missed detections email-sending: description: Send transactional email and manage sending subdomains and their DNS configuration groups: limits: description: Inspect account-level sending quotas and current usage subdomains: description: Configure sending subdomains and keep their DNS records healthy suppressions: description: Prevent delivery to suppressed addresses and manage the account suppression list filters: description: Filter expressions used by legacy firewall rules to match requests — prefer Rulesets for new configurations firewall: description: Legacy firewall rules, zone lockdowns, access rules, user-agent blocking, and WAF packages groups: access-rules: description: IP-based access rules that allow, block, challenge, or whitelist traffic globally or per-zone lockdowns: description: Zone lockdown rules that restrict access to URLs by IP address or range rules: description: Legacy firewall rules with filter expressions — prefer Rulesets for new configurations ua-rules: description: Block or challenge requests based on the User-Agent header string waf: description: Legacy WAF managed rule packages, rule groups, individual rules, and override configurations zone-access-rules: description: Zone-scoped IP access rules for blocking or allowing traffic google-tag-gateway: description: Google Tag Gateway operations groups: config: description: Google Tag Gateway config operations healthchecks: description: Standalone health checks that monitor origin server availability from Cloudflare's edge groups: previews: description: Test a health check configuration before deploying it to production hyperdrive: description: Accelerate access to existing databases by caching queries and pooling connections at the edge iam: description: Identity and access management — permission groups, resource groups, user groups, and SSO connectors groups: permission-groups: description: View the permission groups that can be assigned to API tokens and policies resource-groups: description: Define scopes that limit which account resources a policy or token can access sso: description: Configure single sign-on connectors to authenticate account members through an external identity provider user-groups: description: Organize account members into groups for easier permission assignment images: description: Store, resize, and deliver optimized images globally — variants, signing keys, and direct uploads groups: flows: description: Zone-level transformation flows that control how images are resized and optimized on delivery import: description: Import images from S3 keys: description: Manage signing keys for generating private image URLs variants: description: Manage named resize variants for transforming images on delivery intel: description: Threat intelligence lookups — IP reputation, domain info, ASN details, WHOIS, and indicator feeds groups: asn: description: ASN intelligence — ownership, geolocation, and subnet details for autonomous systems attack-surface-report: description: Attack surface intelligence — exposed assets, vulnerabilities, and infrastructure mapping dns: description: Passive DNS data showing historical DNS resolution records for domains domain-history: description: Historical domain registration and categorization changes over time domains: description: Domain intelligence — risk scores, categories, and associated infrastructure indicator-feeds: description: Threat indicator feeds — subscribe to and manage curated lists of malicious IPs, domains, and URLs ip-lists: description: Curated IP lists used for threat detection and policy enforcement ips: description: IP address intelligence — geolocation, risk assessment, and hosting provider details miscategorizations: description: Report and track domain miscategorization corrections whois: description: WHOIS registration data for domains including registrant, registrar, and nameservers k2: description: Durable, ordered event streams that you produce records to and consume from with subscriptions groups: streams: description: K2 streams, their retention, and the HTTP and Workers binding inputs used to produce records streams.subscriptions: description: Subscriptions that consume a K2 stream, with committed-position lag leaked-credential-checks: description: Detect compromised credentials in login requests by checking against known breach databases groups: detections: description: Custom detection locations that tell the WAF where to find usernames and passwords in requests load-balancers: description: Distribute traffic across origin pools with health monitoring, geo-steering, and failover groups: monitor-groups: description: Group monitors together for shared configuration and bulk management monitor-groups.references: description: List references to monitor groups used by load balancer pools monitors: description: Health check configurations that probe origin servers and determine pool availability monitors.previews: description: Health check configurations that probe origin servers and determine pool availability monitors.references: description: Health check configurations that probe origin servers and determine pool availability pools: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.health: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.references: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences previews: description: Preview the result of a health check monitor configuration before applying it regions: description: Geographic regions used for regional pool steering and traffic policies searches: description: Search across all load balancer resources (pools, monitors, load balancers) by name or reference logs: description: Log control, retention, and raw log access — CMB config, ray ID lookups, and received fields groups: control: description: Log control operations received: description: Received log operations magic-network-monitoring: description: Flow-based network traffic monitoring with configurable alerting rules and VPC flow ingestion groups: configs: description: Account-level monitoring configuration — sampling rates, thresholds, and notification settings rules: description: Monitoring rules that define traffic thresholds and trigger alerts or prefix advertisements vpc-flows: description: Ingest VPC flow logs from cloud providers for network visibility and anomaly detection magic-transit: description: DDoS-protected network transit — GRE/IPsec tunnels, static routes, Magic WAN sites, connectors, and packet captures groups: advanced-dns-protection: description: Advanced Dns Protection operations advanced-tcp-protection: description: Advanced Tcp Protection operations apps: description: Application-aware traffic policies for Magic WAN that steer traffic by app type bgp-filter-profiles: description: BGP filter profiles for controlling which routes are allowed or denied on Magic Transit tunnels bgp-settings: description: BGP settings for controlling default ASN and route redistribution on Magic Transit tunnels cf-interconnects: description: Cloudflare Network Interconnect (CNI) links for direct physical or virtual peering gre-tunnels: description: GRE tunnel endpoints that connect your network to Cloudflare for Magic Transit ipsec-tunnels: description: IPsec tunnel endpoints with pre-shared key management for encrypted transit pcaps: description: Packet capture requests for debugging traffic flowing through Magic Transit tunnels routes: description: Static routes that direct IP prefix traffic through specific GRE/IPsec tunnels sites: description: Magic WAN branch sites — base CRUD, LAN/WAN interface configuration, ACLs, connectors, app configuration, and NetFlow config mcp: description: Manage MCP portals and upstream MCP servers for Cloudflare Access AI controls groups: portals: description: Manage MCP portals, attached servers, and Code Mode settings servers: description: Manage upstream MCP servers, credentials, capabilities, and sync state network-interconnects: description: Physical and virtual private interconnects between your infrastructure and Cloudflare's network groups: cnis: description: Cloud Network Interconnect (CNI) connections — private links from cloud providers to Cloudflare interconnects: description: Physical cross-connect and partner interconnect sessions with LOA and status tracking settings: description: Account-level interconnect settings and default configurations slots: description: Available interconnect facility slots showing port capacity at Cloudflare data centers organizations: description: Multi-user organizations that group accounts, members, and shared settings under a single entity groups: account-organizations: description: List organizations associated with a specific account accounts: description: Accounts operations members: description: Members operations members-batch-create: description: Members Batch Create operations organization-profile: description: View and update the public profile information for an organization shares: description: Shares operations origin-post-quantum-encryption: description: Enable post-quantum key exchange for connections between Cloudflare and your origin server pages: description: Full-stack application hosting with Git-integrated builds, preview deployments, and custom domains groups: projects: description: Pages projects, deployments, build logs, and custom domain bindings pipelines: description: Ingest, transform, and route event streams into R2, analytics, or other destinations in real time groups: sinks: description: Destinations where pipeline data is written — R2 buckets, HTTP endpoints, or other storage streams: description: Inbound data streams that feed events into a pipeline for processing precursor: description: Precursor settings for a zone queues: description: Reliable message queuing between Workers — produce, consume, and batch-process messages at scale groups: consumers: description: Workers that automatically receive and process messages from a queue messages: description: Push messages to a queue and pull or acknowledge them from consumers purge: description: Remove all pending messages from a queue subscriptions: description: Manage queue subscriptions for event-driven message routing r2: description: S3-compatible object storage with zero egress fees — buckets, lifecycle rules, event notifications, and data migration groups: buckets: description: Create and configure R2 buckets including CORS, lifecycle, custom domains, event notifications, and object locks buckets.jobs: description: Create and inspect background jobs for an R2 bucket buckets.local-uploads: description: R2 bucket local upload configuration super-slurper: description: Migrate data from external S3-compatible storage into R2 buckets with resumable transfer jobs temporary-credentials: description: Generate short-lived S3-compatible credentials scoped to specific buckets and operations r2-data-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables radar: description: Internet-wide traffic intelligence — BGP, DNS, HTTP trends, attack data, and network quality insights groups: agent-readiness: description: Agent readiness summary statistics across the Cloudflare network ai: description: AI inference trends and model usage statistics across the Cloudflare network annotations: description: Radar annotations marking significant Internet events (outages, cable cuts, etc.) as112: description: AS112 DNS sinkhole statistics — reverse DNS query volumes for private address space attacks: description: DDoS and application-layer attack trends, vectors, and target analysis bgp: description: BGP routing data — prefix announcements, AS-level stats, route leaks, and hijack events bots: description: Internet-wide bot traffic trends, categories, and distribution statistics ct: description: Certificate Transparency log monitoring and newly-issued certificate discovery datasets: description: Downloadable Radar datasets for offline analysis and research dns: description: Global DNS query trends — top domains, resolver stats, and DNSSEC adoption email: description: Email security trends — DMARC/SPF/DKIM adoption, spam, and phishing statistics entities: description: Look up ASNs, IPs, domains, and locations with metadata and traffic summaries geolocations: description: Geographic location metadata used for regional traffic analysis http: description: HTTP protocol trends — TLS versions, HTTP versions, browser share, and OS distribution leaked-credentials: description: Leaked credential detection trends and exposure statistics netflows: description: Network-layer traffic flow data and volumetric trend analysis origins: description: Cloud and hosting origin providers (e.g. Amazon, by region) and their traffic metrics post-quantum: description: Post-quantum encryption adoption and deployment trends across the Internet quality: description: Internet connection quality metrics — speed, latency, and jitter by geography and ASN ranking: description: Top domain rankings based on DNS query popularity across the Cloudflare network robots-txt: description: Robots.txt adoption and crawler directive trends across the web search: description: Search Radar data across IPs, ASNs, domains, and locations tcp-resets-timeouts: description: TCP connection reset and timeout statistics indicating network health issues tlds: description: Top-level domain (TLD) metadata and performance trends traffic-anomalies: description: Detected traffic anomalies and unusual patterns in Internet traffic flows verified-bots: description: Catalog of known good bots (Googlebot, Bingbot, etc.) and their traffic patterns rate-limits: description: Legacy per-zone rate limiting rules — prefer Advanced Rate Limiting in Rulesets for new configurations realtime: description: Real-time audio, video, and data services on Cloudflare's global network groups: kit: description: SDK-backed meetings, participants, recordings, livestreams, and webhooks kit.analytics: description: Usage and livestream analytics for RealtimeKit applications kit.analytics.livestreams: description: Livestream analytics for RealtimeKit applications kit.analytics.livestreams.daily: description: Daily livestream analytics for RealtimeKit applications kit.analytics.usage: description: Usage analytics for RealtimeKit applications kit.apps: description: RealtimeKit applications that group meetings, sessions, and configuration kit.livestreams: description: Independent and meeting-based livestreams and their sessions kit.livestreams.sessions: description: Sessions for RealtimeKit livestreams kit.meetings: description: Meetings, participants, access tokens, and meeting livestreams kit.meetings.active: description: Live meeting state and participant controls kit.meetings.active.polls: description: Polls for active meeting sessions kit.meetings.livestream: description: Livestream operations associated with RealtimeKit meetings kit.meetings.participants: description: Participants in RealtimeKit meetings kit.meetings.participants.tokens: description: Access tokens for RealtimeKit meeting participants kit.presets: description: Reusable meeting configuration for media, permissions, and interface behavior kit.recordings: description: Meeting and participant-track recordings and recording controls kit.recordings.active: description: Active recordings for RealtimeKit meetings kit.recordings.tracks: description: Participant-track recordings for RealtimeKit meetings kit.sessions: description: Historical session data, participants, chat, transcripts, and summaries kit.sessions.chat: description: Chat messages from historical RealtimeKit sessions kit.sessions.livestreams: description: Livestreams associated with historical RealtimeKit sessions kit.sessions.participants: description: Participants in historical RealtimeKit sessions kit.sessions.peers: description: Peer details from historical RealtimeKit sessions kit.sessions.summaries: description: Summaries of historical RealtimeKit sessions kit.sessions.transcripts: description: Transcripts from historical RealtimeKit sessions kit.webhooks: description: Webhook endpoints and supported events for RealtimeKit notifications kit.webhooks.events: description: Supported events for RealtimeKit webhooks moq: description: MoQ relays for publishing and subscribing to media streams moq.relays: description: Relays are isolated MoQ scopes that carry media between publishers and subscribers moq.relays.tokens: description: Tokens that authorize publishers and subscribers to connect to a relay sfu: description: SFU apps that route WebRTC media and data between participants sfu.apps: description: SFU application namespaces for sessions and tracks turn: description: TURN keys that help clients traverse NATs and firewalls turn.keys: description: Keys used to generate short-lived TURN credentials request-tracers: description: Trace how a request would be processed through Cloudflare's rules and configuration pipeline groups: traces: description: Simulate request processing to debug rule matches, transforms, and routing decisions resource-sharing: description: Share Cloudflare resources (zones, accounts) across organizations with granular access controls groups: recipients: description: Update share recipients resources: description: Individual resources (zones, configs) that have been shared with recipients rules: description: Resources used by Cloudflare rules and rulesets groups: lists: description: Custom account-level lists of IPs, hostnames, ASNs, or redirects used in rule expressions rum: description: Real User Measurement (Web Analytics) — track page loads, Core Web Vitals, and visitor metrics groups: rules: description: Rules that control which pages and paths are tracked by Web Analytics site-info: description: Web Analytics sites — register domains and get the JavaScript beacon snippet scim: description: SCIM 2.0 provisioning — manage users, groups, and identity provider sync for your account groups: groups: description: Groups operations resource-types: description: Resource Types operations schemas: description: Schemas operations service-provider-config: description: Service Provider Config operations users: description: Users operations secrets-store: description: Centralized secret management — store API keys, tokens, and credentials for use across Workers and other products groups: quota: description: Account quota limits for secrets stores, secrets count, and storage capacity secrets: description: Encrypted key-value secrets within a store. Pass --store-id to scope. stores: description: Secret stores that hold encrypted key-value secrets accessible by Workers and services security-center: description: Security posture dashboard — view and manage security insights, misconfigurations, and vulnerabilities groups: insights: description: Security findings and recommendations across your account — DNS, SSL, WAF misconfigurations, etc. zone-insights: description: Zone-scoped security insights — counts by class, severity, type, and dismissal security-txt: description: Manage the /.well-known/security.txt file that tells security researchers how to report vulnerabilities smart-shield: description: Smart Shield settings, health checks, and cache reserve management groups: cache-reserve-clear: description: Cache Reserve Clear operations health-checks: description: Health checks operations spectrum: description: Proxy and protect arbitrary TCP/UDP applications through Cloudflare's network with DDoS mitigation groups: analytics: description: Real-time and historical connection analytics for Spectrum applications apps: description: Spectrum application configurations that map protocols and ports to origin servers speed: description: Observatory speed tests — run Lighthouse audits, track performance trends, and schedule recurring tests groups: availabilities: description: Check which speed test regions and configurations are available for your zone pages: description: Tested pages with their performance history, trends, and individual test results schedule: description: Scheduled recurring speed tests that automatically run at regular intervals ssl: description: SSL/TLS certificate management — certificate packs, Universal SSL, verification, and TLS mode recommendations groups: automatic-upgrader: description: SSL automatic mode enrollment — get or update automatic SSL/TLS upgrader settings recommendations: description: Get the recommended SSL/TLS encryption mode based on your origin server's certificate configuration stream: description: Video encoding, storage, and delivery — upload, live-stream, clip, caption, and embed video at scale groups: audio-tracks: description: Add, edit, or remove additional audio tracks on a video captions: description: Upload, generate, or retrieve captions and subtitles for videos in multiple languages clip: description: Create a new video clip from an existing video by specifying start and end times copy: description: Import a video from a URL into Stream for processing and delivery direct-upload: description: Generate a tokenized URL that lets end-users upload video directly to Stream downloads: description: Create downloadable MP4 renditions of a video for offline viewing embed: description: Retrieve the HTML embed code snippet for a video keys: description: Signing keys used to generate short-lived signed URLs for private video playback live-inputs: description: Enable and disable live input streams token: description: Generate short-lived signed URL tokens for secure private video playback typed-downloads: description: Type-specific stream download creation and deletion videos: description: Aggregate video storage usage statistics for the account watermarks: description: Watermark profiles that overlay an image on every video in the account webhooks: description: Webhook notifications for video lifecycle events (ready, error, etc.) tenants: description: Multi-tenant account management — manage tenant accounts, entitlements, and memberships groups: account-types: description: Account Types operations accounts: description: Accounts operations entitlements: description: Entitlements operations memberships: description: Memberships operations turnstile: description: CAPTCHA-free bot verification widgets that protect forms and APIs without degrading user experience groups: widgets: description: Turnstile widget configurations — site keys, secret rotation, and challenge mode settings url-scanner: description: Scan URLs for phishing, malware, and other threats — submit scans and retrieve detailed results groups: response: description: Response operations responses: description: Raw HTTP response data captured during URL scans scan: description: Scan operations scans: description: URL scan requests and results — submit URLs for analysis and retrieve threat verdicts user: description: Your Cloudflare user profile, invitations, organizations, billing, and personal API tokens groups: billing: description: View billing history and payment profile for your user (deprecated — prefer account-level billing) firewall: description: Firewall operations load-balancers.monitors: description: Load Balancers operations load-balancers.monitors.preview: description: Load Balancers operations load-balancers.monitors.references: description: Load Balancers operations load-balancers.pools: description: Load Balancers operations load-balancers.pools.edit.pools: description: Load Balancers operations load-balancers.pools.health: description: Load Balancers operations load-balancers.pools.preview: description: Load Balancers operations load-balancers.pools.references: description: Load Balancers operations load-balancers.preview: description: Load Balancers operations load-balancing-analytics.events: description: Load Balancing Analytics operations subscriptions: description: View and manage zone-level plan subscriptions owned by your user tenants: description: Tenants operations tokens: description: Create and manage personal API tokens scoped to your user for programmatic API access user.analytics: description: User-level traffic analytics — aggregated totals and timeseries across all zones vectorize: description: Globally distributed vector database for building semantic search, recommendations, and RAG applications on Workers groups: deprecated-indexes: description: Deprecated v1 Vectorize index operations metadata-index: description: Metadata indexes for filtered vector search waiting-rooms: description: Virtual queues that throttle traffic to your site during peak demand with customizable waiting pages groups: account-waiting-rooms: description: Account-scoped waiting room listing events: description: Scheduled events that temporarily override waiting room settings for sales, launches, etc. page: description: Custom HTML waiting page templates and preview rendering rules: description: Rules that bypass or modify waiting room behavior for specific request patterns settings: description: Zone-level waiting room defaults and cookie configuration statuses: description: Real-time queue status showing active users, queued users, and estimated wait times workflows: description: Durable, multi-step workflows that run on Workers with automatic retries and state persistence groups: instances: description: Workflow instance operations versions: description: Workflow version operations zaraz: description: Server-side tag manager — load third-party tools (analytics, pixels, etc.) from Cloudflare's edge without client-side JS groups: config: description: Full Zaraz configuration including tools, triggers, and variables for the zone default: description: Default Zaraz configuration template used as a starting point for new zones export: description: Export the current Zaraz configuration as a portable JSON document history: description: Configuration version history — browse and restore previous Zaraz configurations publish: description: Publish pending Zaraz configuration changes to make them live on the zone workflow: description: Workflow state for Zaraz configuration changes (draft vs. published) zero-trust: description: Cloudflare's SASE platform — secure access, device posture, DLP, tunnels, gateway policies, and network segmentation groups: dex: description: Digital Experience Monitoring — synthetic tests, fleet-wide device metrics, and network path diagnostics dlp.custom-prompt-topics: description: Data Loss Prevention - manage custom prompt topics for AI-based content detection dlp.data-classes: description: Data Loss Prevention - manage data classes used to classify sensitive information dlp.data-tag-categories: description: Data Loss Prevention - manage categories that organize data tags dlp.data-tag-category-templates: description: Data Loss Prevention - browse templates for creating data tag categories dlp.data-tags: description: Data Loss Prevention - manage tags used to classify and organize sensitive data dlp.datasets: description: Data Loss Prevention - manage datasets, versions, and uploads dlp.document-fingerprints: description: Data Loss Prevention - manage document fingerprints for detecting matching documents dlp.email.account-mapping: description: Data Loss Prevention - configure account mappings for outbound email scanning dlp.email.rules: description: Data Loss Prevention - manage outbound email scanning rules and their priorities dlp.entries: description: Data Loss Prevention - list and manage detection entries dlp.limits: description: Data Loss Prevention - view account limits and resource quotas dlp.patterns: description: Data Loss Prevention - validate regular expressions used for content detection dlp.profiles: description: Data Loss Prevention - list and retrieve profiles dlp.profiles.custom: description: Data Loss Prevention - manage custom profiles dlp.profiles.predefined: description: Data Loss Prevention - manage predefined profiles dlp.sensitivity-group-templates: description: Data Loss Prevention - browse templates for creating sensitivity groups dlp.sensitivity-groups: description: Data Loss Prevention - manage sensitivity groups and their level ordering dlp.sensitivity-levels: description: Data Loss Prevention - manage sensitivity levels within sensitivity groups dlp.settings: description: Data Loss Prevention - manage account-level settings dlp.validators: description: Data Loss Prevention - list and retrieve content validators dlp.validators.proximity-words: description: Data Loss Prevention - manage proximity-word validators risk-scoring: description: User Risk Scoring - retrieve and reset user risk scores risk-scoring.behaviours: description: User Risk Scoring - manage behaviors used to calculate user risk scores risk-scoring.integrations: description: User Risk Scoring - manage integrations that provide risk score signals risk-scoring.integrations.references: description: User Risk Scoring - retrieve integrations by external reference risk-scoring.summary: description: User Risk Scoring - retrieve account risk score summaries zones: description: Zones are domains on Cloudflare — list, create, and configure domain settings groups: aegis: description: Aegis operations fonts: description: Fonts operations origin-h2-max-streams: description: Origin H2 Max Streams operations origin-max-http-version: description: Origin Max Http Version operations origin-tls-compliance-modes: description: Manage zone Origin TLS Compliance Modes setting rum: description: Rum operations speed-brain: description: Speed Brain operations