openapi: 3.2.0 info: description: Welcome to Cloudflare's API documentation site. license: name: BSD-3-Clause url: https://opensource.org/licenses/BSD-3-Clause title: Cloudflare Zone API version: 4.0.0 servers: - description: Client API url: https://api.cloudflare.com/client/v4 security: - api_email: [] api_key: [] - api_token: [] - user_service_key: [] tags: - name: Zone paths: /zones: get: operationId: zones-get summary: List Zones description: 'Lists, searches, sorts, and filters your zones. Listing zones across more than 500 accounts is currently not allowed.' parameters: - name: name in: query schema: description: "A domain name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`\n" type: string maxLength: 253 examples: Basic Query: summary: Simple Query value: example.com Contains Query: summary: Contains Query value: contains:.org Ends With Query: summary: Ends With Query value: ends_with:arpa Starts With Query: summary: Starts With Query value: starts_with:dev - name: status in: query schema: description: Specify a zone status to filter by. type: string enum: - initializing - pending - active - moved - name: type in: query schema: description: Zone types to filter by. Multiple types can be specified as a comma-separated list (e.g., ?type=full,partial,secondary). When this parameter is not provided, zones with type "internal" are excluded from the results. type: array items: enum: - full - partial - secondary - internal type: string explode: false style: form - name: account.id in: query schema: description: Filter by an account ID. type: string - name: account.name in: query schema: description: "An account Name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`\n" type: string maxLength: 253 examples: Basic Query: summary: Simple Query value: Dev Account Contains Query: summary: Contains Query value: contains:Test - name: page in: query schema: description: Page number of paginated results. type: number default: 1 minimum: 1 - name: per_page in: query schema: description: Number of zones per page. type: number default: 20 maximum: 50 minimum: 5 - name: order in: query schema: description: Field to order zones by. type: string example: status enum: - name - status - account.id - account.name - plan.id - name: direction in: query schema: description: Direction to order zones. type: string example: desc enum: - asc - desc - name: match in: query schema: description: Whether to match all search requirements or at least one (any). type: string default: all enum: - any - all responses: '200': description: List Zones response. content: application/json: schema: allOf: - $ref: '#/components/schemas/zones_api-response-common' - properties: result_info: $ref: '#/components/schemas/zones_result_info' - properties: result: type: array items: $ref: '#/components/schemas/zones_zone' 4XX: description: List Zones response failure. content: application/json: schema: $ref: '#/components/schemas/zones_api-response-common-failure' security: - api_token: [] - api_email: [] api_key: [] tags: - Zone x-api-token-group: - Zone Zone Read x-fern-availability: generally-available x-fern-sdk-group-name: zones x-fern-sdk-method-name: list post: operationId: zones-post summary: Create Zone description: 'Creates a new zone (domain) in your Cloudflare account. The zone is created in a pending state and must be activated by updating your domain''s nameservers to point to Cloudflare, or by completing the verification process for partial (CNAME) setups.' requestBody: required: true content: application/json: schema: type: object properties: account: type: object properties: id: $ref: '#/components/schemas/zones_identifier' name: $ref: '#/components/schemas/zones_name' type: $ref: '#/components/schemas/zones_type' required: - name - account responses: '200': description: Create Zone response. content: application/json: schema: allOf: - $ref: '#/components/schemas/zones_api-response-common' - properties: result: $ref: '#/components/schemas/zones_zone' type: object 4XX: description: Create Zone response failure. content: application/json: schema: $ref: '#/components/schemas/zones_api-response-common-failure' security: - api_token: [] - api_email: [] api_key: [] tags: - Zone x-api-token-group: - Zone Zone Edit - Zone DNS Edit x-fern-availability: generally-available x-fern-sdk-group-name: zones x-fern-sdk-method-name: create /zones/{zone_id}: delete: operationId: zones-0-delete summary: Delete Zone description: Deletes an existing zone. parameters: - name: zone_id in: path required: true schema: $ref: '#/components/schemas/zones_identifier' responses: '200': description: Delete Zone response. content: application/json: schema: $ref: '#/components/schemas/zones_api-response-single-id' 4XX: description: Delete Zone response failure. content: application/json: schema: $ref: '#/components/schemas/zones_api-response-common-failure' security: - api_token: [] - api_email: [] api_key: [] tags: - Zone x-api-token-group: - Zone Write x-cfPermissionsRequired: enum: - '#zone:edit' x-cfPlanAvailability: business: true enterprise: true free: true pro: true x-fern-availability: generally-available x-fern-sdk-group-name: zones x-fern-sdk-method-name: delete get: operationId: zones-0-get summary: Zone Details description: 'Retrieves detailed information about a specific zone identified by its zone ID. Returns zone configuration, status, nameservers, and associated metadata.' parameters: - name: zone_id in: path required: true schema: $ref: '#/components/schemas/zones_identifier' responses: '200': description: Zone Details response. content: application/json: schema: allOf: - $ref: '#/components/schemas/zones_api-response-common' - properties: result: $ref: '#/components/schemas/zones_zone' type: object 4XX: description: Zone Details response failure. content: application/json: schema: $ref: '#/components/schemas/zones_api-response-common-failure' security: - api_token: [] - api_email: [] api_key: [] tags: - Zone x-api-token-group: - Trust and Safety Write - Trust and Safety Read - 'Zero Trust: PII Read' - Zaraz Edit - Zaraz Read - Zaraz Admin - 'Access: Apps and Policies Revoke' - 'Access: Apps and Policies Write' - 'Access: Apps and Policies Read' - 'Access: Apps and Policies Revoke' - 'Access: Mutual TLS Certificates Write' - 'Access: Organizations, Identity Providers, and Groups Write' - Zone Settings Write - Zone Settings Read - Zone Read - DNS Read - Workers Scripts Write - Workers Scripts Read - Zone Write - Workers Routes Write - Workers Routes Read - Stream Write - Stream Read - SSL and Certificates Write - SSL and Certificates Read - Logs Write - Logs Read - Cache Purge - Page Rules Write - Page Rules Read - Load Balancers Write - Load Balancers Read - Firewall Services Write - Firewall Services Read - DNS Write - Apps Write - Analytics Read - 'Access: Apps and Policies Write' - 'Access: Apps and Policies Read' x-cfPermissionsRequired: enum: - '#zone:read' x-cfPlanAvailability: business: true enterprise: true free: true pro: true x-fern-availability: generally-available x-fern-sdk-group-name: zones x-fern-sdk-method-name: get patch: operationId: zones-0-patch summary: Edit Zone description: Edits a zone. Only one zone property can be changed at a time. parameters: - name: zone_id in: path required: true schema: $ref: '#/components/schemas/zones_identifier' requestBody: required: true content: application/json: schema: type: object properties: paused: $ref: '#/components/schemas/zones_paused' plan: description: '(Deprecated) Please use the `/zones/{zone_id}/subscription` API to update a zone''s plan. Changing this value will create/cancel associated subscriptions. To view available plans for this zone, see Zone Plans. ' type: object properties: id: $ref: '#/components/schemas/zones_identifier' type: description: 'A full zone implies that DNS is hosted with Cloudflare. A partial zone is typically a partner-hosted zone or a CNAME setup. This parameter is only available to Enterprise customers or if it has been explicitly enabled on a zone. ' type: string example: full enum: - full - partial - secondary - internal vanity_name_servers: $ref: '#/components/schemas/zones_vanity_name_servers' example: paused: true responses: '200': description: Edit Zone response. content: application/json: schema: allOf: - $ref: '#/components/schemas/zones_api-response-common' - properties: result: $ref: '#/components/schemas/zones_zone' type: object 4XX: description: Edit Zone response failure. content: application/json: schema: $ref: '#/components/schemas/zones_api-response-common-failure' security: - api_token: [] - api_email: [] api_key: [] tags: - Zone x-api-token-group: - Zone Write x-cfPlanAvailability: business: true enterprise: true free: true pro: true x-fern-availability: generally-available x-fern-sdk-group-name: zones x-fern-sdk-method-name: edit /zones/{zone_id}/activation_check: put: operationId: put-zones-zone_id-activation_check summary: Rerun the Activation Check description: 'Triggeres a new activation check for a PENDING Zone. This can be triggered every 5 min for paygo/ent customers, every hour for FREE Zones.' parameters: - name: zone_id in: path description: Zone ID required: true schema: $ref: '#/components/schemas/zone-activation_identifier' responses: '200': description: Successful Response content: application/json: schema: allOf: - $ref: '#/components/schemas/zone-activation_api-response-single' - properties: result: type: object properties: id: $ref: '#/components/schemas/zone-activation_identifier' type: object 4XX: description: Client Error content: application/json: schema: allOf: - $ref: '#/components/schemas/zone-activation_api-response-common-failure' security: - api_token: [] - api_email: [] api_key: [] tags: - Zone x-api-token-group: - Zone Write x-fern-availability: generally-available x-fern-sdk-group-name: zone x-fern-sdk-method-name: activate /zones/{zone_id}/environments/{environment_id}/invalidate_cache: post: operationId: zone-environment-invalidate summary: Invalidate Cached Content by Environment description: 'Marks cached content as stale for one environment of the zone. Content cached for the zone''s other environments, including production, is not affected. Otherwise this works like `POST /zones/{zone_id}/invalidate_cache`: the next request for invalidated content makes Cloudflare revalidate it with your origin, and the request body takes the same fields. Environments are part of Version Management. To delete the content instead, use `POST /zones/{zone_id}/environments/{environment_id}/purge_cache`. Invalidating by URL (`files`) does not work for environments that select requests by IP address, country, ASN, or threat score, and fails with error `1136`. Use `tags`, `hosts`, `prefixes`, or `purge_everything` for those environments. ### Availability and limits Rate limits and the number of items you can send in one request depend on your plan. See Purge cache: availability and limits.' parameters: - name: zone_id in: path description: The zone ID. required: true schema: $ref: '#/components/schemas/cache-purge_identifier' - name: environment_id in: path description: The environment ID, from Version Management. required: true schema: $ref: '#/components/schemas/cache-purge_identifier' requestBody: required: true content: application/json: examples: Cache tags: summary: Content with these Cache-Tag values value: tags: - product-1234 - homepage Everything: summary: All cached content value: purge_everything: true Hostnames: summary: Content cached for these hostnames value: hosts: - www.example.com - images.example.com Prefixes: summary: Content under these URL prefixes value: prefixes: - www.example.com/blog/ - images.example.com/avatars/ URLs: summary: Specific URLs value: files: - https://www.example.com/css/styles.css - https://www.example.com/js/index.js URLs with cache key headers: summary: URLs cached with request headers in the cache key value: files: - headers: Accept-Language: zh-CN CF-Device-Type: desktop CF-IPCountry: US url: https://www.example.com/cat_picture.jpg - headers: Accept-Language: en-US CF-Device-Type: mobile CF-IPCountry: DE url: https://www.example.com/dog_picture.jpg schema: anyOf: - $ref: '#/components/schemas/cache-purge_FlexPurgeByTags' - $ref: '#/components/schemas/cache-purge_FlexPurgeByHostnames' - $ref: '#/components/schemas/cache-purge_FlexPurgeByPrefixes' - $ref: '#/components/schemas/cache-purge_Everything' - $ref: '#/components/schemas/cache-purge_SingleFile' - $ref: '#/components/schemas/cache-purge_SingleFileWithUrlAndHeaders' responses: '200': description: 'Cloudflare accepted the request. If Cloudflare could not accept some of the items, `success` is `false` and `errors` lists them, followed by error `1016`. ' content: application/json: example: errors: [] messages: [] result: id: 023e105f4ecef8ad9ca31a8372d0c353 success: true schema: $ref: '#/components/schemas/cache-purge_api-response-single-id' 4XX: description: Cloudflare rejected the request. `errors` explains why. content: application/json: examples: Invalid request body: summary: purge_everything sent with other fields (HTTP 400) value: errors: - code: 1092 message: Request cannot contain "purge_everything" and any of "files", "tags", "hosts" or "prefixes" messages: [] result: null success: false Rate limited: summary: Rate limit reached (HTTP 429) value: errors: - code: 1134 message: Unable to purge, rate limit reached. Please wait and consider throttling your request speed messages: [] result: null success: false schema: allOf: - $ref: '#/components/schemas/cache-purge_api-response-single-id' - $ref: '#/components/schemas/cache-purge_api-response-common-failure' security: - api_token: [] - api_email: [] api_key: [] tags: - Zone x-api-token-group: - Zone Versioning Write x-fern-availability: generally-available x-fern-sdk-group-name: cache x-fern-sdk-method-name: invalidate-environment x-forge-require-confirmation: This operation marks the selected content in the environment's cache as stale. /zones/{zone_id}/environments/{environment_id}/purge_cache: post: operationId: zone-environment-purge summary: Purge Cached Content by Environment description: 'Deletes cached content for one environment of the zone. Content cached for the zone''s other environments, including production, is not affected. Otherwise this works like `POST /zones/{zone_id}/purge_cache`: the next request for purged content is a cache `MISS`, and the request body takes the same fields. Environments are part of Version Management. To keep content cached and have Cloudflare revalidate it instead, use `POST /zones/{zone_id}/environments/{environment_id}/invalidate_cache`. Purging by URL (`files`) does not work for environments that select requests by IP address, country, ASN, or threat score, and fails with error `1136`. Use `tags`, `hosts`, `prefixes`, or `purge_everything` for those environments. ### Availability and limits Rate limits and the number of items you can send in one request depend on your plan. See Purge cache: availability and limits.' parameters: - name: zone_id in: path description: The zone ID. required: true schema: $ref: '#/components/schemas/cache-purge_identifier' - name: environment_id in: path description: The environment ID, from Version Management. required: true schema: $ref: '#/components/schemas/cache-purge_identifier' requestBody: required: true content: application/json: examples: Cache tags: summary: Content with these Cache-Tag values value: tags: - product-1234 - homepage Everything: summary: All cached content value: purge_everything: true Hostnames: summary: Content cached for these hostnames value: hosts: - www.example.com - images.example.com Prefixes: summary: Content under these URL prefixes value: prefixes: - www.example.com/blog/ - images.example.com/avatars/ URLs: summary: Specific URLs value: files: - https://www.example.com/css/styles.css - https://www.example.com/js/index.js URLs with cache key headers: summary: URLs cached with request headers in the cache key value: files: - headers: Accept-Language: zh-CN CF-Device-Type: desktop CF-IPCountry: US url: https://www.example.com/cat_picture.jpg - headers: Accept-Language: en-US CF-Device-Type: mobile CF-IPCountry: DE url: https://www.example.com/dog_picture.jpg schema: anyOf: - $ref: '#/components/schemas/cache-purge_FlexPurgeByTags' - $ref: '#/components/schemas/cache-purge_FlexPurgeByHostnames' - $ref: '#/components/schemas/cache-purge_FlexPurgeByPrefixes' - $ref: '#/components/schemas/cache-purge_Everything' - $ref: '#/components/schemas/cache-purge_SingleFile' - $ref: '#/components/schemas/cache-purge_SingleFileWithUrlAndHeaders' responses: '200': description: 'Cloudflare accepted the request. If Cloudflare could not accept some of the items, `success` is `false` and `errors` lists them, followed by error `1016`. ' content: application/json: example: errors: [] messages: [] result: id: 023e105f4ecef8ad9ca31a8372d0c353 success: true schema: $ref: '#/components/schemas/cache-purge_api-response-single-id' 4XX: description: Cloudflare rejected the request. `errors` explains why. content: application/json: examples: Invalid request body: summary: purge_everything sent with other fields (HTTP 400) value: errors: - code: 1092 message: Request cannot contain "purge_everything" and any of "files", "tags", "hosts" or "prefixes" messages: [] result: null success: false Rate limited: summary: Rate limit reached (HTTP 429) value: errors: - code: 1134 message: Unable to purge, rate limit reached. Please wait and consider throttling your request speed messages: [] result: null success: false schema: allOf: - $ref: '#/components/schemas/cache-purge_api-response-single-id' - $ref: '#/components/schemas/cache-purge_api-response-common-failure' security: - api_token: [] - api_email: [] api_key: [] tags: - Zone x-api-token-group: - Cache Purge x-cfPermissionsRequired: enum: - '#cache_purge:edit' x-fern-availability: generally-available x-fern-sdk-group-name: cache x-fern-sdk-method-name: purge-environment x-forge-require-confirmation: This operation deletes the selected content from the environment's cache. /zones/{zone_id}/invalidate_cache: post: operationId: zone-invalidate summary: Invalidate Cached Content description: 'Marks cached content as stale in every Cloudflare data center and cache tier, including Cache Reserve. The content stays in cache. The next request for it makes Cloudflare revalidate it with your origin, using the `ETag` and `Last-Modified` values it was cached with: - If your origin answers `304 Not Modified`, Cloudflare serves the cached copy without downloading it again, and `CF-Cache-Status` is `REVALIDATED`. - If your origin sends a full response, Cloudflare serves and caches the new content, and `CF-Cache-Status` is `EXPIRED`. With Tiered Cache, each tier revalidates with the tier above it, so a visitor can see `EXPIRED` even when your origin answered `304`. Until content is revalidated, your `stale-while-revalidate` and `stale-if-error` directives still apply, counted from the time you invalidated it. For example, if your origin fails during revalidation, Cloudflare can keep serving the stale copy for the `stale-if-error` window. ### Invalidate or purge? - **Invalidate** when content may not have changed, for example after a deploy. Unchanged content costs your origin a `304` instead of a full response. That saving needs an origin that sends `ETag` or `Last-Modified` and answers conditional requests. Otherwise, every revalidation downloads the full response. - **Purge**, with `POST /zones/{zone_id}/purge_cache`, when content must not be served again, for example content you removed for legal or security reasons. Invalidating takes the same request bodies as purging, needs the same permission, and counts against the same rate limits. After a broad invalidation, such as `purge_everything`, expect more conditional requests to your origin while visitors request the invalidated content again. ### Choose what to invalidate Send one of these fields in the request body: - `files`: specific URLs. If your cache key includes request headers, send each URL with the header values it was cached with. - `tags`: all content whose `Cache-Tag` response header contains one of the tags. - `hosts`: all content cached for the hostnames. - `prefixes`: all content whose URL starts with one of the prefixes. - `purge_everything`: all cached content in the zone. ### Check the result A `200` response with `success: true` means Cloudflare accepted the request. To check, request an invalidated URL and confirm that the `CF-Cache-Status` response header is `REVALIDATED` or `EXPIRED`. ### Availability and limits Rate limits and the number of items you can send in one request depend on your plan. See Purge cache: availability and limits.' parameters: - name: zone_id in: path description: The zone ID. required: true schema: $ref: '#/components/schemas/cache-purge_identifier' requestBody: required: true content: application/json: examples: Cache tags: summary: Content with these Cache-Tag values value: tags: - product-1234 - homepage Everything: summary: All cached content value: purge_everything: true Hostnames: summary: Content cached for these hostnames value: hosts: - www.example.com - images.example.com Prefixes: summary: Content under these URL prefixes value: prefixes: - www.example.com/blog/ - images.example.com/avatars/ URLs: summary: Specific URLs value: files: - https://www.example.com/css/styles.css - https://www.example.com/js/index.js URLs with cache key headers: summary: URLs cached with request headers in the cache key value: files: - headers: Accept-Language: zh-CN CF-Device-Type: desktop CF-IPCountry: US url: https://www.example.com/cat_picture.jpg - headers: Accept-Language: en-US CF-Device-Type: mobile CF-IPCountry: DE url: https://www.example.com/dog_picture.jpg schema: anyOf: - $ref: '#/components/schemas/cache-purge_FlexPurgeByTags' - $ref: '#/components/schemas/cache-purge_FlexPurgeByHostnames' - $ref: '#/components/schemas/cache-purge_FlexPurgeByPrefixes' - $ref: '#/components/schemas/cache-purge_Everything' - $ref: '#/components/schemas/cache-purge_SingleFile' - $ref: '#/components/schemas/cache-purge_SingleFileWithUrlAndHeaders' responses: '200': description: 'Cloudflare accepted the request. If Cloudflare could not accept some of the items, `success` is `false` and `errors` lists them, followed by error `1016`. ' content: application/json: example: errors: [] messages: [] result: id: 023e105f4ecef8ad9ca31a8372d0c353 success: true schema: $ref: '#/components/schemas/cache-purge_api-response-single-id' 4XX: description: Cloudflare rejected the request. `errors` explains why. content: application/json: examples: Invalid request body: summary: purge_everything sent with other fields (HTTP 400) value: errors: - code: 1092 message: Request cannot contain "purge_everything" and any of "files", "tags", "hosts" or "prefixes" messages: [] result: null success: false Rate limited: summary: Rate limit reached (HTTP 429) value: errors: - code: 1134 message: Unable to purge, rate limit reached. Please wait and consider throttling your request speed messages: [] result: null success: false schema: allOf: - $ref: '#/components/schemas/cache-purge_api-response-single-id' - $ref: '#/components/schemas/cache-purge_api-response-common-failure' security: - api_token: [] - api_email: [] api_key: [] tags: - Zone x-fern-availability: generally-available x-fern-sdk-group-name: cache x-fern-sdk-method-name: invalidate x-forge-require-confirmation: This operation marks the selected content in the zone's cache as stale. /zones/{zone_id}/purge_cache: post: operationId: zone-purge summary: Purge Cached Content description: 'Deletes cached content in every Cloudflare data center and cache tier, including Cache Reserve. The next request for purged content is a cache `MISS`: Cloudflare fetches the full response from your origin and caches it again. Cloudflare does not serve purged content from cache again, even if your origin is unavailable. To keep content cached and have Cloudflare revalidate it with your origin instead, use `POST /zones/{zone_id}/invalidate_cache`. ### Choose what to purge Send one of these fields in the request body: - `files`: specific URLs. If your cache key includes request headers, send each URL with the header values it was cached with. - `tags`: all content whose `Cache-Tag` response header contains one of the tags. - `hosts`: all content cached for the hostnames. - `prefixes`: all content whose URL starts with one of the prefixes. - `purge_everything`: all cached content in the zone. ### Check the result A `200` response with `success: true` means Cloudflare accepted the request. It does not confirm that any content was cached or removed. To check, request a purged URL and confirm that the `CF-Cache-Status` response header is `MISS`. ### Availability and limits Rate limits and the number of items you can send in one request depend on your plan. See Purge cache: availability and limits.' parameters: - name: zone_id in: path description: The zone ID. required: true schema: $ref: '#/components/schemas/cache-purge_identifier' requestBody: required: true content: application/json: examples: Cache tags: summary: Content with these Cache-Tag values value: tags: - product-1234 - homepage Everything: summary: All cached content value: purge_everything: true Hostnames: summary: Content cached for these hostnames value: hosts: - www.example.com - images.example.com Prefixes: summary: Content under these URL prefixes value: prefixes: - www.example.com/blog/ - images.example.com/avatars/ URLs: summary: Specific URLs value: files: - https://www.example.com/css/styles.css - https://www.example.com/js/index.js URLs with cache key headers: summary: URLs cached with request headers in the cache key value: files: - headers: Accept-Language: zh-CN CF-Device-Type: desktop CF-IPCountry: US url: https://www.example.com/cat_picture.jpg - headers: Accept-Language: en-US CF-Device-Type: mobile CF-IPCountry: DE url: https://www.example.com/dog_picture.jpg schema: anyOf: - $ref: '#/components/schemas/cache-purge_FlexPurgeByTags' - $ref: '#/components/schemas/cache-purge_FlexPurgeByHostnames' - $ref: '#/components/schemas/cache-purge_FlexPurgeByPrefixes' - $ref: '#/components/schemas/cache-purge_Everything' - $ref: '#/components/schemas/cache-purge_SingleFile' - $ref: '#/components/schemas/cache-purge_SingleFileWithUrlAndHeaders' responses: '200': description: 'Cloudflare accepted the request. If Cloudflare could not accept some of the items, `success` is `false` and `errors` lists them, followed by error `1016`. ' content: application/json: example: errors: [] messages: [] result: id: 023e105f4ecef8ad9ca31a8372d0c353 success: true schema: $ref: '#/components/schemas/cache-purge_api-response-single-id' 4XX: description: Cloudflare rejected the request. `errors` explains why. content: application/json: examples: Invalid request body: summary: purge_everything sent with other fields (HTTP 400) value: errors: - code: 1092 message: Request cannot contain "purge_everything" and any of "files", "tags", "hosts" or "prefixes" messages: [] result: null success: false Rate limited: summary: Rate limit reached (HTTP 429) value: errors: - code: 1134 message: Unable to purge, rate limit reached. Please wait and consider throttling your request speed messages: [] result: null success: false schema: allOf: - $ref: '#/components/schemas/cache-purge_api-response-single-id' - $ref: '#/components/schemas/cache-purge_api-response-common-failure' security: - api_token: [] - api_email: [] api_key: [] tags: - Zone x-api-token-group: - Cache Purge x-cfPermissionsRequired: enum: - '#cache_purge:edit' x-fern-availability: generally-available x-fern-sdk-group-name: cache x-fern-sdk-method-name: purge x-forge-require-confirmation: This operation deletes the selected content from the zone's cache. components: schemas: cache-purge_api-response-single-id: type: object properties: errors: $ref: '#/components/schemas/cache-purge_messages' messages: $ref: '#/components/schemas/cache-purge_messages' result: type: - object - 'null' properties: id: $ref: '#/components/schemas/cache-purge_identifier' required: - id success: description: Indicates the API call's success or failure. type: boolean example: true required: - success - errors - messages cache-purge_identifier: type: string example: 023e105f4ecef8ad9ca31a8372d0c353 maxLength: 32 cache-purge_api-response-common-failure: type: object properties: errors: example: - code: 7003 message: No route for the URI allOf: - $ref: '#/components/schemas/cache-purge_messages' minLength: 1 messages: example: [] allOf: - $ref: '#/components/schemas/cache-purge_messages' result: type: - object - 'null' success: description: Indicates the API call's success or failure. type: boolean example: false required: - success - errors - messages - result zone-activation_api-response-common-failure: type: object properties: errors: example: - code: 7003 message: No route for the URI allOf: - $ref: '#/components/schemas/zone-activation_messages' minLength: 1 messages: example: [] allOf: - $ref: '#/components/schemas/zone-activation_messages' result: type: - object - 'null' enum: - null success: description: Whether the API call was successful. type: boolean example: false enum: - false required: - success - errors - messages - result cache-purge_FlexPurgeByPrefixes: type: object properties: prefixes: description: URL prefixes, each a hostname followed by a path, such as `www.example.com/blog/`. Targets all content whose URL starts with one of these prefixes. Do not include a scheme, query string, or fragment. See [Purge cache by prefix](https://developers.cloudflare.com/cache/how-to/purge-cache/purge_by_prefix/). type: array items: type: string x-auditable: true example: - www.example.com/blog/ - images.example.com/avatars/ title: Purge by prefixes zone-activation_identifier: description: Identifier. type: string example: 023e105f4ecef8ad9ca31a8372d0c353 maxLength: 32 x-auditable: true zone-activation_api-response-single: type: object allOf: - $ref: '#/components/schemas/zone-activation_api-response-common' zones_paused: description: 'Indicates whether the zone is only using Cloudflare DNS services. A true value means the zone will not receive security or performance benefits. ' type: boolean default: false cache-purge_SingleFileWithUrlAndHeaders: type: object properties: files: description: 'URLs with the request headers your cache key uses. Use this form when your cache key includes request headers, or the visitor''s device type, country, or language: send the header values each URL was cached with, such as `CF-Device-Type`, `CF-IPCountry`, or `Accept-Language`. When you send the `Origin` header, include the scheme and hostname. Include the port unless it is the default for the scheme: 80 for `http`, 443 for `https`. See [Purge by single-file](https://developers.cloudflare.com/cache/how-to/purge-cache/purge-by-single-file/). ' type: array items: properties: headers: description: Request headers and the values the content was cached with. type: object example: CF-Device-Type: desktop CF-IPCountry: US additionalProperties: type: string x-auditable: true url: description: Full URL of the content. type: string example: https://www.example.com/cat_picture.jpg x-auditable: true type: object example: - headers: Accept-Language: zh-CN CF-Device-Type: desktop CF-IPCountry: US url: https://www.example.com/cat_picture.jpg - headers: Accept-Language: en-US CF-Device-Type: mobile CF-IPCountry: DE url: https://www.example.com/dog_picture.jpg title: Purge files with URL and headers cache-purge_Everything: type: object properties: purge_everything: description: Set to `true` to target all cached content in the zone, or in the environment for the environment endpoints. Must be the only field in the request. See [Purge everything](https://developers.cloudflare.com/cache/how-to/purge-cache/purge-everything/). type: boolean example: true x-auditable: true title: Purge everything zones_name: description: The domain name. Per [RFC 1035](https://datatracker.ietf.org/doc/html/rfc1035#section-2.3.4) the overall zone name can be up to 253 characters, with each segment ("label") not exceeding 63 characters. type: string example: example.com maxLength: 253 pattern: ^([a-zA-Z0-9][\-a-zA-Z0-9]*\.)+[\-a-zA-Z0-9]{2,20}$ x-auditable: true zones_api-response-single-id: type: object allOf: - $ref: '#/components/schemas/zones_api-response-common' - properties: result: type: - object - 'null' properties: id: $ref: '#/components/schemas/zones_identifier' required: - id cache-purge_messages: type: array items: properties: code: type: integer minimum: 1000 message: type: string required: - code - message type: object uniqueItems: true example: [] zone-activation_api-response-common: type: object properties: errors: $ref: '#/components/schemas/zone-activation_messages' messages: $ref: '#/components/schemas/zone-activation_messages' success: description: Whether the API call was successful. type: boolean example: true enum: - true required: - success - errors - messages zones_api-response-common-failure: type: object properties: errors: example: - code: 7003 message: No route for the URI allOf: - $ref: '#/components/schemas/zones_messages' minLength: 1 messages: example: [] allOf: - $ref: '#/components/schemas/zones_messages' result: type: - object - 'null' success: description: Whether the API call was successful. type: boolean example: false required: - success - errors - messages - result zones_messages: type: array items: properties: code: type: integer minimum: 1000 message: type: string required: - code - message type: object uniqueItems: true example: [] zones_type: description: 'A full zone implies that DNS is hosted with Cloudflare. A partial zone is typically a partner-hosted zone or a CNAME setup. ' type: string example: full default: full enum: - full - partial - secondary - internal cache-purge_FlexPurgeByHostnames: type: object properties: hosts: description: Hostnames, such as `www.example.com`. Targets all content cached for these hostnames. See [Purge cache by hostname](https://developers.cloudflare.com/cache/how-to/purge-cache/purge-by-hostname/). type: array items: type: string x-auditable: true example: - www.example.com - images.example.com title: Purge by hostnames cache-purge_SingleFile: type: object properties: files: description: Full URLs, such as `https://www.example.com/css/styles.css`. Targets the content cached for each URL. If your cache key includes request headers, send objects with `url` and `headers` instead. See [Purge by single-file](https://developers.cloudflare.com/cache/how-to/purge-cache/purge-by-single-file/). type: array items: type: string x-auditable: true example: - https://www.example.com/css/styles.css - https://www.example.com/js/index.js title: Purge files zones_vanity_name_servers: description: 'An array of domains used for custom name servers. This is only available for Business and Enterprise plans.' type: array items: format: hostname maxLength: 253 type: string example: - ns1.example.com - ns2.example.com default: [] zones_api-response-common: type: object properties: errors: $ref: '#/components/schemas/zones_messages' messages: $ref: '#/components/schemas/zones_messages' success: description: Whether the API call was successful. type: boolean example: true required: - success - errors - messages zones_zone: type: object properties: account: description: The account the zone belongs to. type: object properties: id: description: Identifier type: string example: 023e105f4ecef8ad9ca31a8372d0c353 maxLength: 32 x-auditable: true name: description: The name of the account. type: string example: Example Account Name activated_on: description: 'The last time proof of ownership was detected and the zone was made active.' type: - string - 'null' format: date-time example: '2014-01-02T00:01:00.12345Z' readOnly: true cname_suffix: description: 'Allows the customer to use a custom apex. *Tenants Only Configuration*.' type: string example: cdn.cloudflare.com created_on: description: When the zone was created. type: string format: date-time example: '2014-01-01T05:20:00.12345Z' readOnly: true development_mode: description: 'The interval (in seconds) from when development mode expires (positive integer) or last expired (negative integer) for the domain. If development mode has never been enabled, this value is 0.' type: number example: 7200 readOnly: true id: description: Identifier type: string example: 023e105f4ecef8ad9ca31a8372d0c353 maxLength: 32 x-auditable: true meta: description: Metadata about the zone. type: object properties: cdn_only: description: The zone is only configured for CDN. type: boolean example: true custom_certificate_quota: description: Number of Custom Certificates the zone can have. type: integer example: 1 dns_only: description: The zone is only configured for DNS. type: boolean example: true foundation_dns: description: The zone is setup with Foundation DNS. type: boolean example: true page_rule_quota: description: Number of Page Rules a zone can have. type: integer example: 100 phishing_detected: description: The zone has been flagged for phishing. type: boolean example: false step: type: integer example: 2 modified_on: description: When the zone was last modified. type: string format: date-time example: '2014-01-01T05:20:00.12345Z' readOnly: true name: description: The domain name. Per [RFC 1035](https://datatracker.ietf.org/doc/html/rfc1035#section-2.3.4) the overall zone name can be up to 253 characters, with each segment ("label") not exceeding 63 characters. type: string example: example.com maxLength: 253 pattern: ^([a-zA-Z0-9][\-a-zA-Z0-9]*\.)+[\-a-zA-Z0-9]{2,20}$ x-auditable: true name_servers: description: The name servers Cloudflare assigns to a zone. type: array items: format: hostname type: string example: - bob.ns.cloudflare.com - lola.ns.cloudflare.com readOnly: true original_dnshost: description: DNS host at the time of switching to Cloudflare. type: - string - 'null' example: NameCheap maxLength: 50 readOnly: true original_name_servers: description: Original name servers before moving to Cloudflare. type: - array - 'null' items: format: hostname type: string example: - ns1.originaldnshost.com - ns2.originaldnshost.com readOnly: true original_registrar: description: Registrar for the domain at the time of switching to Cloudflare. type: - string - 'null' example: GoDaddy readOnly: true owner: description: The owner of the zone. type: object properties: id: $ref: '#/components/schemas/zones_identifier' name: description: Name of the owner. type: string example: Example Org type: description: The type of owner. type: string example: organization paused: $ref: '#/components/schemas/zones_paused' permissions: description: Legacy permissions based on legacy user membership information. type: array items: example: '#worker:read' type: string deprecated: true x-stainless-deprecation-message: This has been replaced by Account memberships. plan: description: A Zones subscription information. deprecated: true properties: can_subscribe: description: States if the subscription can be activated. type: boolean example: false currency: description: The denomination of the customer. type: string example: USD externally_managed: description: If this Zone is managed by another company. type: boolean example: false frequency: description: How often the customer is billed. type: string example: monthly id: $ref: '#/components/schemas/zones_identifier' is_subscribed: description: States if the subscription active. type: boolean example: false legacy_discount: description: If the legacy discount applies to this Zone. type: boolean example: false legacy_id: description: The legacy name of the plan. type: string example: free name: description: Name of the owner. type: string example: Example Org price: description: How much the customer is paying. type: number example: 10.99 x-stainless-deprecation-message: 'Please use the `/zones/{zone_id}/subscription` API to update a zone''s plan. Changing this value will create/cancel associated subscriptions. To view available plans for this zone, see [Zone Plans](https://developers.cloudflare.com/api/resources/zones/subresources/plans/).' status: description: The zone status on Cloudflare. type: string example: active enum: - initializing - pending - active - moved readOnly: true tenant: description: The root organizational unit that this zone belongs to (such as a tenant or organization). properties: id: $ref: '#/components/schemas/zones_identifier' name: description: The name of the Tenant account. type: string example: Example Account Name tenant_unit: description: The immediate parent organizational unit that this zone belongs to (such as under a tenant or sub-organization). properties: id: $ref: '#/components/schemas/zones_identifier' type: $ref: '#/components/schemas/zones_type' vanity_name_servers: description: An array of domains used for custom name servers. This is only available for Business and Enterprise plans. type: array items: format: hostname maxLength: 253 type: string example: - ns1.example.com - ns2.example.com default: [] verification_key: description: Verification key for partial zone setup. type: string example: 284344499-1084221259 readOnly: true required: - id - name - development_mode - owner - account - meta - name_servers - original_name_servers - original_registrar - original_dnshost - created_on - modified_on - activated_on - plan zones_result_info: type: object properties: count: description: Total number of results for the requested service. type: number example: 1 page: description: Current page within paginated list of results. type: number example: 1 per_page: description: Number of results per page of results. type: number example: 20 total_count: description: Total results available without any search parameters. type: number example: 2000 total_pages: description: Total number of pages type: number example: 100 cache-purge_FlexPurgeByTags: type: object properties: tags: description: Cache tags. Targets all content whose `Cache-Tag` response header contains at least one of these tags. See [Purge cache by cache-tags](https://developers.cloudflare.com/cache/how-to/purge-cache/purge-by-tags/). type: array items: type: string x-auditable: true example: - product-1234 - homepage title: Purge by tags zones_identifier: description: Identifier type: string example: 023e105f4ecef8ad9ca31a8372d0c353 maxLength: 32 zone-activation_messages: type: array items: properties: code: type: integer minimum: 1000 documentation_url: type: string message: type: string source: type: object properties: pointer: type: string required: - code - message type: object uniqueItems: true example: [] securitySchemes: api_email: in: header name: X-Auth-Email type: apiKey api_key: in: header name: X-Auth-Key type: apiKey api_token: scheme: bearer type: http user_service_key: in: header name: X-Auth-User-Service-Key type: apiKey externalDocs: description: Cloudflare Radar Documentation url: https://developers.cloudflare.com/radar/ x-forge-commands: abuse-reports: description: Submit and track abuse reports for phishing, malware, and other policy violations on Cloudflare-proxied sites groups: appeals: description: Appeal eligibility for abuse reports emails: description: Emails sent for abuse reports mitigations: description: Mitigation actions taken in response to abuse reports accounts: description: Account settings, members, roles, subscriptions, and API tokens for your Cloudflare account groups: applications: description: Applications operations categories: description: Categories operations organizations: description: Move accounts between organizations profile: description: View and manage the profile for a Cloudflare account roles: description: View the roles available for assigning to account members, each defining a set of permissions subscriptions: description: View and manage plan subscriptions attached to this account tokens: description: Create and manage scoped API tokens for programmatic access to the Cloudflare API ai-gateway: description: Proxy, cache, rate-limit, and observe requests to AI providers — OpenAI, Anthropic, Workers AI, and more groups: custom-domains: description: Manage custom hostnames that route requests through an AI Gateway custom-providers: description: Manage account-level custom AI providers and their endpoint settings datasets: description: 'Deprecated: manage filtered collections of gateway logs used by evaluations' dynamic-routing: description: Route requests across multiple AI providers with fallback, load-balancing, and versioned deployments dynamic-routing.deployments: description: Deploy dynamic route versions and view deployment history dynamic-routing.versions: description: Create and inspect saved versions of a dynamic route evaluation-types: description: 'Deprecated: list the evaluator types that evaluations can use' evaluations: description: 'Deprecated: score the logs in a dataset with selected evaluator types' gateways: description: Create and configure AI Gateways for an account gateways.providers: description: Store and rotate upstream AI provider keys for a gateway logs: description: Inspect, annotate, and delete gateway request logs stored by Legacy Logs ai-search: description: 'Managed search-as-a-service: crawl, index, and query content with AI-powered relevance and chat completions' groups: items: description: Content indexed by AI Search instances jobs: description: Indexing job lifecycle for AI Search instances namespace: description: Logical groupings for organizing AI Search instances tokens: description: Credentials used by AI Search instances ai-security: description: Detect prompt injection, PII, and unsafe topics in traffic to your AI applications groups: custom-topics: description: Organization-specific topic categories used by AI Security for Apps content detection analytics: description: Zone-level traffic analytics — dashboard summaries, per-colo breakdowns, and Argo latency metrics groups: colo: description: Per-data-center (colo) traffic analytics breakdown for the zone dashboard: description: Aggregated zone dashboard analytics — requests, bandwidth, threats, and page views latency: description: Argo Smart Routing latency analytics showing time-to-first-byte improvements argo: description: Network optimization features that speed up and improve reliability of traffic to your origins groups: smart-routing: description: Route traffic through the fastest network paths to your origin using real-time latency data tiered-caching: description: Reduce origin load by having upper-tier data centers serve cache misses before reaching your origin basin-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables billing: description: Account billing profiles and usage data for Cloudflare subscriptions and add-on services groups: profiles: description: Billing profile with payment method, address, and invoice preferences usage: description: Metered usage data for billed services — requests, bandwidth, and feature consumption botnet-feed: description: Botnet threat intelligence feeds — IP and ASN-level data on known command-and-control infrastructure groups: asn: description: ASN-level botnet activity data showing networks with known C2 infrastructure configs: description: Botnet feed subscription configuration and notification preferences builds: description: Build and deploy Workers from connected repositories, then inspect build status and logs. groups: deploy-hooks: description: Manage branch-specific HTTP hooks that start builds. limits: description: View build-minute availability and refresh information. logs: description: Retrieve build logs. repos: description: Manage source repository connections for Workers Builds. tokens: description: Manage credentials used by Workers Builds to deploy Workers. triggers: description: Configure how repository changes build and deploy Workers. versions: description: Find builds associated with Worker versions. workers: description: Manage repository-backed build configuration for Workers. cache: description: Purge cached content and configure Cache Reserve, tiered caching, and variant serving groups: origin-cloud-regions: description: Manage Origin Cloud Regions routing and failover configurations settings: description: Configure Cache Reserve, tiered caching, and variant serving settings.regional-tiered-cache: description: Restrict tiered cache topology to data centers within a specific geographic region settings.reserve: description: Persistent storage tier that keeps cached assets even after eviction from edge caches settings.smart-tiered-cache: description: Automatically determine the best upper-tier data centers for tiered cache topology settings.variants: description: Serve different cached versions of an image based on the Accept header (WebP, AVIF, etc.) client-side-security: description: Client-Side Security — monitor JavaScript, connections, and cookies on your pages for supply-chain attacks groups: connections: description: Third-party connections made by scripts on your pages — track data exfiltration risks cookies: description: Cookies set by your pages with classification and same-site attribute tracking policies: description: Content Security Policies that control which scripts and connections are allowed on your pages scripts: description: JavaScript files detected on your pages with change tracking and malicious code detection settings: description: Fine tune Client-Side Security behaviors cloud-connector: description: Route traffic from Cloudflare directly to cloud provider services (AWS, Azure, GCP) without origin servers groups: rules: description: Routing rules that map request patterns to cloud provider endpoints cloudforce-one: description: Detection rule management APIs groups: binary-storage: description: Upload and retrieve malware samples and suspicious binaries for analysis requests: description: Additional request operations — priority listing and asset creation rules: description: Rule management operations groups: approvals: description: Approval workflow operations email: description: Email rule operations exemptions: description: Exemption rule operations managed: description: Managed rule operations stats: description: Rule statistics operations tree: description: Rule navigation tree operations scans: description: Scan URLs, IPs, and domains for threat intelligence indicators containers: description: Deploy and manage Containers applications on Cloudflare's global network groups: applications: description: Manage Containers applications applications.instances: description: Inspect Containers instances belonging to applications applications.rollouts: description: Manage rollouts for scheduler-backed applications applications.versions: description: Inspect versions of scheduler-backed applications registries: description: Manage Containers image registries registries.credentials: description: Generate image registry credentials content-scan: description: Malicious uploads detection, scan uploaded content in HTTP requests for malware and malicious payloads groups: expressions: description: Custom expressions that tell the scanner how to reach content objects it cannot parse on its own custom-pages: description: Manage custom error and challenge pages and their assets for accounts and zones groups: account-custom-pages: description: Manage account-level custom pages account-custom-pages.preview-tokens: description: Preview tokens for account-level custom pages assets: description: Manage account- and zone-level custom assets zone-custom-pages: description: Manage zone-level custom pages zone-custom-pages.preview-tokens: description: Preview tokens for zone-level custom pages d1: description: D1 is Cloudflare's managed, serverless database with SQLite's SQL semantics, built-in disaster recovery, and Worker and HTTP API access. groups: time-travel: description: use specific point-in-time backups of your D1 database x-forge-epilogue: For more information about Time Travel, see https://developers.cloudflare.com/d1/reference/time-travel diagnostics: description: Network diagnostic tools — traceroutes from Cloudflare's edge and endpoint health checks groups: endpoint-healthchecks: description: Monitor external endpoint availability with periodic HTTP/HTTPS health checks traceroutes: description: Run traceroutes from Cloudflare data centers to diagnose network path issues email-routing: description: Route incoming email to verified destination addresses or Workers with routing rules, catch-all behavior, and managed DNS records groups: addresses: description: Verified destination email addresses that can receive forwarded mail dns: description: Inspect or unlock the DNS records required by Email Routing rules: description: Match incoming email addresses and forward messages to destination mailboxes or Workers settings: description: Inspect and update Email Routing settings email-security: description: Cloud email security — investigate threats, manage allow/block policies, and detect phishing groups: analytics: description: Analytics and reporting — monthly report and per-day breakdowns of threat activity bulk-actions: description: Asynchronous jobs that move or release every message matching a search — create, monitor, and manage bulk jobs investigate: description: Search and investigate email messages — view detections, traces, raw content, and take remediation actions phishguard: description: PhishGuard user-reported phishing reports — view detected threats for a date range settings: description: Email security configuration — block senders, allow policies, content policies, domains, trusted domains, impersonation registry, and URL handling submissions: description: Reclassify submissions — track user and team reports of false positives and missed detections email-sending: description: Send transactional email and manage sending subdomains and their DNS configuration groups: limits: description: Inspect account-level sending quotas and current usage subdomains: description: Configure sending subdomains and keep their DNS records healthy suppressions: description: Prevent delivery to suppressed addresses and manage the account suppression list filters: description: Filter expressions used by legacy firewall rules to match requests — prefer Rulesets for new configurations firewall: description: Legacy firewall rules, zone lockdowns, access rules, user-agent blocking, and WAF packages groups: access-rules: description: IP-based access rules that allow, block, challenge, or whitelist traffic globally or per-zone lockdowns: description: Zone lockdown rules that restrict access to URLs by IP address or range rules: description: Legacy firewall rules with filter expressions — prefer Rulesets for new configurations ua-rules: description: Block or challenge requests based on the User-Agent header string waf: description: Legacy WAF managed rule packages, rule groups, individual rules, and override configurations zone-access-rules: description: Zone-scoped IP access rules for blocking or allowing traffic google-tag-gateway: description: Google Tag Gateway operations groups: config: description: Google Tag Gateway config operations healthchecks: description: Standalone health checks that monitor origin server availability from Cloudflare's edge groups: previews: description: Test a health check configuration before deploying it to production hyperdrive: description: Accelerate access to existing databases by caching queries and pooling connections at the edge iam: description: Identity and access management — permission groups, resource groups, user groups, and SSO connectors groups: permission-groups: description: View the permission groups that can be assigned to API tokens and policies resource-groups: description: Define scopes that limit which account resources a policy or token can access sso: description: Configure single sign-on connectors to authenticate account members through an external identity provider user-groups: description: Organize account members into groups for easier permission assignment images: description: Store, resize, and deliver optimized images globally — variants, signing keys, and direct uploads groups: flows: description: Zone-level transformation flows that control how images are resized and optimized on delivery import: description: Import images from S3 keys: description: Manage signing keys for generating private image URLs variants: description: Manage named resize variants for transforming images on delivery intel: description: Threat intelligence lookups — IP reputation, domain info, ASN details, WHOIS, and indicator feeds groups: asn: description: ASN intelligence — ownership, geolocation, and subnet details for autonomous systems attack-surface-report: description: Attack surface intelligence — exposed assets, vulnerabilities, and infrastructure mapping dns: description: Passive DNS data showing historical DNS resolution records for domains domain-history: description: Historical domain registration and categorization changes over time domains: description: Domain intelligence — risk scores, categories, and associated infrastructure indicator-feeds: description: Threat indicator feeds — subscribe to and manage curated lists of malicious IPs, domains, and URLs ip-lists: description: Curated IP lists used for threat detection and policy enforcement ips: description: IP address intelligence — geolocation, risk assessment, and hosting provider details miscategorizations: description: Report and track domain miscategorization corrections whois: description: WHOIS registration data for domains including registrant, registrar, and nameservers k2: description: Durable, ordered event streams that you produce records to and consume from with subscriptions groups: streams: description: K2 streams, their retention, and the HTTP and Workers binding inputs used to produce records streams.subscriptions: description: Subscriptions that consume a K2 stream, with committed-position lag leaked-credential-checks: description: Detect compromised credentials in login requests by checking against known breach databases groups: detections: description: Custom detection locations that tell the WAF where to find usernames and passwords in requests load-balancers: description: Distribute traffic across origin pools with health monitoring, geo-steering, and failover groups: monitor-groups: description: Group monitors together for shared configuration and bulk management monitor-groups.references: description: List references to monitor groups used by load balancer pools monitors: description: Health check configurations that probe origin servers and determine pool availability monitors.previews: description: Health check configurations that probe origin servers and determine pool availability monitors.references: description: Health check configurations that probe origin servers and determine pool availability pools: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.health: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.references: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences previews: description: Preview the result of a health check monitor configuration before applying it regions: description: Geographic regions used for regional pool steering and traffic policies searches: description: Search across all load balancer resources (pools, monitors, load balancers) by name or reference logs: description: Log control, retention, and raw log access — CMB config, ray ID lookups, and received fields groups: control: description: Log control operations received: description: Received log operations magic-network-monitoring: description: Flow-based network traffic monitoring with configurable alerting rules and VPC flow ingestion groups: configs: description: Account-level monitoring configuration — sampling rates, thresholds, and notification settings rules: description: Monitoring rules that define traffic thresholds and trigger alerts or prefix advertisements vpc-flows: description: Ingest VPC flow logs from cloud providers for network visibility and anomaly detection magic-transit: description: DDoS-protected network transit — GRE/IPsec tunnels, static routes, Magic WAN sites, connectors, and packet captures groups: advanced-dns-protection: description: Advanced Dns Protection operations advanced-tcp-protection: description: Advanced Tcp Protection operations apps: description: Application-aware traffic policies for Magic WAN that steer traffic by app type bgp-filter-profiles: description: BGP filter profiles for controlling which routes are allowed or denied on Magic Transit tunnels bgp-settings: description: BGP settings for controlling default ASN and route redistribution on Magic Transit tunnels cf-interconnects: description: Cloudflare Network Interconnect (CNI) links for direct physical or virtual peering gre-tunnels: description: GRE tunnel endpoints that connect your network to Cloudflare for Magic Transit ipsec-tunnels: description: IPsec tunnel endpoints with pre-shared key management for encrypted transit pcaps: description: Packet capture requests for debugging traffic flowing through Magic Transit tunnels routes: description: Static routes that direct IP prefix traffic through specific GRE/IPsec tunnels sites: description: Magic WAN branch sites — base CRUD, LAN/WAN interface configuration, ACLs, connectors, app configuration, and NetFlow config mcp: description: Manage MCP portals and upstream MCP servers for Cloudflare Access AI controls groups: portals: description: Manage MCP portals, attached servers, and Code Mode settings servers: description: Manage upstream MCP servers, credentials, capabilities, and sync state network-interconnects: description: Physical and virtual private interconnects between your infrastructure and Cloudflare's network groups: cnis: description: Cloud Network Interconnect (CNI) connections — private links from cloud providers to Cloudflare interconnects: description: Physical cross-connect and partner interconnect sessions with LOA and status tracking settings: description: Account-level interconnect settings and default configurations slots: description: Available interconnect facility slots showing port capacity at Cloudflare data centers organizations: description: Multi-user organizations that group accounts, members, and shared settings under a single entity groups: account-organizations: description: List organizations associated with a specific account accounts: description: Accounts operations members: description: Members operations members-batch-create: description: Members Batch Create operations organization-profile: description: View and update the public profile information for an organization shares: description: Shares operations origin-post-quantum-encryption: description: Enable post-quantum key exchange for connections between Cloudflare and your origin server pages: description: Full-stack application hosting with Git-integrated builds, preview deployments, and custom domains groups: projects: description: Pages projects, deployments, build logs, and custom domain bindings pipelines: description: Ingest, transform, and route event streams into R2, analytics, or other destinations in real time groups: sinks: description: Destinations where pipeline data is written — R2 buckets, HTTP endpoints, or other storage streams: description: Inbound data streams that feed events into a pipeline for processing precursor: description: Precursor settings for a zone queues: description: Reliable message queuing between Workers — produce, consume, and batch-process messages at scale groups: consumers: description: Workers that automatically receive and process messages from a queue messages: description: Push messages to a queue and pull or acknowledge them from consumers purge: description: Remove all pending messages from a queue subscriptions: description: Manage queue subscriptions for event-driven message routing r2: description: S3-compatible object storage with zero egress fees — buckets, lifecycle rules, event notifications, and data migration groups: buckets: description: Create and configure R2 buckets including CORS, lifecycle, custom domains, event notifications, and object locks buckets.jobs: description: Create and inspect background jobs for an R2 bucket buckets.local-uploads: description: R2 bucket local upload configuration super-slurper: description: Migrate data from external S3-compatible storage into R2 buckets with resumable transfer jobs temporary-credentials: description: Generate short-lived S3-compatible credentials scoped to specific buckets and operations r2-data-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables radar: description: Internet-wide traffic intelligence — BGP, DNS, HTTP trends, attack data, and network quality insights groups: agent-readiness: description: Agent readiness summary statistics across the Cloudflare network ai: description: AI inference trends and model usage statistics across the Cloudflare network annotations: description: Radar annotations marking significant Internet events (outages, cable cuts, etc.) as112: description: AS112 DNS sinkhole statistics — reverse DNS query volumes for private address space attacks: description: DDoS and application-layer attack trends, vectors, and target analysis bgp: description: BGP routing data — prefix announcements, AS-level stats, route leaks, and hijack events bots: description: Internet-wide bot traffic trends, categories, and distribution statistics ct: description: Certificate Transparency log monitoring and newly-issued certificate discovery datasets: description: Downloadable Radar datasets for offline analysis and research dns: description: Global DNS query trends — top domains, resolver stats, and DNSSEC adoption email: description: Email security trends — DMARC/SPF/DKIM adoption, spam, and phishing statistics entities: description: Look up ASNs, IPs, domains, and locations with metadata and traffic summaries geolocations: description: Geographic location metadata used for regional traffic analysis http: description: HTTP protocol trends — TLS versions, HTTP versions, browser share, and OS distribution leaked-credentials: description: Leaked credential detection trends and exposure statistics netflows: description: Network-layer traffic flow data and volumetric trend analysis origins: description: Cloud and hosting origin providers (e.g. Amazon, by region) and their traffic metrics post-quantum: description: Post-quantum encryption adoption and deployment trends across the Internet quality: description: Internet connection quality metrics — speed, latency, and jitter by geography and ASN ranking: description: Top domain rankings based on DNS query popularity across the Cloudflare network robots-txt: description: Robots.txt adoption and crawler directive trends across the web search: description: Search Radar data across IPs, ASNs, domains, and locations tcp-resets-timeouts: description: TCP connection reset and timeout statistics indicating network health issues tlds: description: Top-level domain (TLD) metadata and performance trends traffic-anomalies: description: Detected traffic anomalies and unusual patterns in Internet traffic flows verified-bots: description: Catalog of known good bots (Googlebot, Bingbot, etc.) and their traffic patterns rate-limits: description: Legacy per-zone rate limiting rules — prefer Advanced Rate Limiting in Rulesets for new configurations realtime: description: Real-time audio, video, and data services on Cloudflare's global network groups: kit: description: SDK-backed meetings, participants, recordings, livestreams, and webhooks kit.analytics: description: Usage and livestream analytics for RealtimeKit applications kit.analytics.livestreams: description: Livestream analytics for RealtimeKit applications kit.analytics.livestreams.daily: description: Daily livestream analytics for RealtimeKit applications kit.analytics.usage: description: Usage analytics for RealtimeKit applications kit.apps: description: RealtimeKit applications that group meetings, sessions, and configuration kit.livestreams: description: Independent and meeting-based livestreams and their sessions kit.livestreams.sessions: description: Sessions for RealtimeKit livestreams kit.meetings: description: Meetings, participants, access tokens, and meeting livestreams kit.meetings.active: description: Live meeting state and participant controls kit.meetings.active.polls: description: Polls for active meeting sessions kit.meetings.livestream: description: Livestream operations associated with RealtimeKit meetings kit.meetings.participants: description: Participants in RealtimeKit meetings kit.meetings.participants.tokens: description: Access tokens for RealtimeKit meeting participants kit.presets: description: Reusable meeting configuration for media, permissions, and interface behavior kit.recordings: description: Meeting and participant-track recordings and recording controls kit.recordings.active: description: Active recordings for RealtimeKit meetings kit.recordings.tracks: description: Participant-track recordings for RealtimeKit meetings kit.sessions: description: Historical session data, participants, chat, transcripts, and summaries kit.sessions.chat: description: Chat messages from historical RealtimeKit sessions kit.sessions.livestreams: description: Livestreams associated with historical RealtimeKit sessions kit.sessions.participants: description: Participants in historical RealtimeKit sessions kit.sessions.peers: description: Peer details from historical RealtimeKit sessions kit.sessions.summaries: description: Summaries of historical RealtimeKit sessions kit.sessions.transcripts: description: Transcripts from historical RealtimeKit sessions kit.webhooks: description: Webhook endpoints and supported events for RealtimeKit notifications kit.webhooks.events: description: Supported events for RealtimeKit webhooks moq: description: MoQ relays for publishing and subscribing to media streams moq.relays: description: Relays are isolated MoQ scopes that carry media between publishers and subscribers moq.relays.tokens: description: Tokens that authorize publishers and subscribers to connect to a relay sfu: description: SFU apps that route WebRTC media and data between participants sfu.apps: description: SFU application namespaces for sessions and tracks turn: description: TURN keys that help clients traverse NATs and firewalls turn.keys: description: Keys used to generate short-lived TURN credentials request-tracers: description: Trace how a request would be processed through Cloudflare's rules and configuration pipeline groups: traces: description: Simulate request processing to debug rule matches, transforms, and routing decisions resource-sharing: description: Share Cloudflare resources (zones, accounts) across organizations with granular access controls groups: recipients: description: Update share recipients resources: description: Individual resources (zones, configs) that have been shared with recipients rules: description: Resources used by Cloudflare rules and rulesets groups: lists: description: Custom account-level lists of IPs, hostnames, ASNs, or redirects used in rule expressions rum: description: Real User Measurement (Web Analytics) — track page loads, Core Web Vitals, and visitor metrics groups: rules: description: Rules that control which pages and paths are tracked by Web Analytics site-info: description: Web Analytics sites — register domains and get the JavaScript beacon snippet scim: description: SCIM 2.0 provisioning — manage users, groups, and identity provider sync for your account groups: groups: description: Groups operations resource-types: description: Resource Types operations schemas: description: Schemas operations service-provider-config: description: Service Provider Config operations users: description: Users operations secrets-store: description: Centralized secret management — store API keys, tokens, and credentials for use across Workers and other products groups: quota: description: Account quota limits for secrets stores, secrets count, and storage capacity secrets: description: Encrypted key-value secrets within a store. Pass --store-id to scope. stores: description: Secret stores that hold encrypted key-value secrets accessible by Workers and services security-center: description: Security posture dashboard — view and manage security insights, misconfigurations, and vulnerabilities groups: insights: description: Security findings and recommendations across your account — DNS, SSL, WAF misconfigurations, etc. zone-insights: description: Zone-scoped security insights — counts by class, severity, type, and dismissal security-txt: description: Manage the /.well-known/security.txt file that tells security researchers how to report vulnerabilities smart-shield: description: Smart Shield settings, health checks, and cache reserve management groups: cache-reserve-clear: description: Cache Reserve Clear operations health-checks: description: Health checks operations spectrum: description: Proxy and protect arbitrary TCP/UDP applications through Cloudflare's network with DDoS mitigation groups: analytics: description: Real-time and historical connection analytics for Spectrum applications apps: description: Spectrum application configurations that map protocols and ports to origin servers speed: description: Observatory speed tests — run Lighthouse audits, track performance trends, and schedule recurring tests groups: availabilities: description: Check which speed test regions and configurations are available for your zone pages: description: Tested pages with their performance history, trends, and individual test results schedule: description: Scheduled recurring speed tests that automatically run at regular intervals ssl: description: SSL/TLS certificate management — certificate packs, Universal SSL, verification, and TLS mode recommendations groups: automatic-upgrader: description: SSL automatic mode enrollment — get or update automatic SSL/TLS upgrader settings recommendations: description: Get the recommended SSL/TLS encryption mode based on your origin server's certificate configuration stream: description: Video encoding, storage, and delivery — upload, live-stream, clip, caption, and embed video at scale groups: audio-tracks: description: Add, edit, or remove additional audio tracks on a video captions: description: Upload, generate, or retrieve captions and subtitles for videos in multiple languages clip: description: Create a new video clip from an existing video by specifying start and end times copy: description: Import a video from a URL into Stream for processing and delivery direct-upload: description: Generate a tokenized URL that lets end-users upload video directly to Stream downloads: description: Create downloadable MP4 renditions of a video for offline viewing embed: description: Retrieve the HTML embed code snippet for a video keys: description: Signing keys used to generate short-lived signed URLs for private video playback live-inputs: description: Enable and disable live input streams token: description: Generate short-lived signed URL tokens for secure private video playback typed-downloads: description: Type-specific stream download creation and deletion videos: description: Aggregate video storage usage statistics for the account watermarks: description: Watermark profiles that overlay an image on every video in the account webhooks: description: Webhook notifications for video lifecycle events (ready, error, etc.) tenants: description: Multi-tenant account management — manage tenant accounts, entitlements, and memberships groups: account-types: description: Account Types operations accounts: description: Accounts operations entitlements: description: Entitlements operations memberships: description: Memberships operations turnstile: description: CAPTCHA-free bot verification widgets that protect forms and APIs without degrading user experience groups: widgets: description: Turnstile widget configurations — site keys, secret rotation, and challenge mode settings url-scanner: description: Scan URLs for phishing, malware, and other threats — submit scans and retrieve detailed results groups: response: description: Response operations responses: description: Raw HTTP response data captured during URL scans scan: description: Scan operations scans: description: URL scan requests and results — submit URLs for analysis and retrieve threat verdicts user: description: Your Cloudflare user profile, invitations, organizations, billing, and personal API tokens groups: billing: description: View billing history and payment profile for your user (deprecated — prefer account-level billing) firewall: description: Firewall operations load-balancers.monitors: description: Load Balancers operations load-balancers.monitors.preview: description: Load Balancers operations load-balancers.monitors.references: description: Load Balancers operations load-balancers.pools: description: Load Balancers operations load-balancers.pools.edit.pools: description: Load Balancers operations load-balancers.pools.health: description: Load Balancers operations load-balancers.pools.preview: description: Load Balancers operations load-balancers.pools.references: description: Load Balancers operations load-balancers.preview: description: Load Balancers operations load-balancing-analytics.events: description: Load Balancing Analytics operations subscriptions: description: View and manage zone-level plan subscriptions owned by your user tenants: description: Tenants operations tokens: description: Create and manage personal API tokens scoped to your user for programmatic API access user.analytics: description: User-level traffic analytics — aggregated totals and timeseries across all zones vectorize: description: Globally distributed vector database for building semantic search, recommendations, and RAG applications on Workers groups: deprecated-indexes: description: Deprecated v1 Vectorize index operations metadata-index: description: Metadata indexes for filtered vector search waiting-rooms: description: Virtual queues that throttle traffic to your site during peak demand with customizable waiting pages groups: account-waiting-rooms: description: Account-scoped waiting room listing events: description: Scheduled events that temporarily override waiting room settings for sales, launches, etc. page: description: Custom HTML waiting page templates and preview rendering rules: description: Rules that bypass or modify waiting room behavior for specific request patterns settings: description: Zone-level waiting room defaults and cookie configuration statuses: description: Real-time queue status showing active users, queued users, and estimated wait times workflows: description: Durable, multi-step workflows that run on Workers with automatic retries and state persistence groups: instances: description: Workflow instance operations versions: description: Workflow version operations zaraz: description: Server-side tag manager — load third-party tools (analytics, pixels, etc.) from Cloudflare's edge without client-side JS groups: config: description: Full Zaraz configuration including tools, triggers, and variables for the zone default: description: Default Zaraz configuration template used as a starting point for new zones export: description: Export the current Zaraz configuration as a portable JSON document history: description: Configuration version history — browse and restore previous Zaraz configurations publish: description: Publish pending Zaraz configuration changes to make them live on the zone workflow: description: Workflow state for Zaraz configuration changes (draft vs. published) zero-trust: description: Cloudflare's SASE platform — secure access, device posture, DLP, tunnels, gateway policies, and network segmentation groups: dex: description: Digital Experience Monitoring — synthetic tests, fleet-wide device metrics, and network path diagnostics dlp.custom-prompt-topics: description: Data Loss Prevention - manage custom prompt topics for AI-based content detection dlp.data-classes: description: Data Loss Prevention - manage data classes used to classify sensitive information dlp.data-tag-categories: description: Data Loss Prevention - manage categories that organize data tags dlp.data-tag-category-templates: description: Data Loss Prevention - browse templates for creating data tag categories dlp.data-tags: description: Data Loss Prevention - manage tags used to classify and organize sensitive data dlp.datasets: description: Data Loss Prevention - manage datasets, versions, and uploads dlp.document-fingerprints: description: Data Loss Prevention - manage document fingerprints for detecting matching documents dlp.email.account-mapping: description: Data Loss Prevention - configure account mappings for outbound email scanning dlp.email.rules: description: Data Loss Prevention - manage outbound email scanning rules and their priorities dlp.entries: description: Data Loss Prevention - list and manage detection entries dlp.limits: description: Data Loss Prevention - view account limits and resource quotas dlp.patterns: description: Data Loss Prevention - validate regular expressions used for content detection dlp.profiles: description: Data Loss Prevention - list and retrieve profiles dlp.profiles.custom: description: Data Loss Prevention - manage custom profiles dlp.profiles.predefined: description: Data Loss Prevention - manage predefined profiles dlp.sensitivity-group-templates: description: Data Loss Prevention - browse templates for creating sensitivity groups dlp.sensitivity-groups: description: Data Loss Prevention - manage sensitivity groups and their level ordering dlp.sensitivity-levels: description: Data Loss Prevention - manage sensitivity levels within sensitivity groups dlp.settings: description: Data Loss Prevention - manage account-level settings dlp.validators: description: Data Loss Prevention - list and retrieve content validators dlp.validators.proximity-words: description: Data Loss Prevention - manage proximity-word validators risk-scoring: description: User Risk Scoring - retrieve and reset user risk scores risk-scoring.behaviours: description: User Risk Scoring - manage behaviors used to calculate user risk scores risk-scoring.integrations: description: User Risk Scoring - manage integrations that provide risk score signals risk-scoring.integrations.references: description: User Risk Scoring - retrieve integrations by external reference risk-scoring.summary: description: User Risk Scoring - retrieve account risk score summaries zones: description: Zones are domains on Cloudflare — list, create, and configure domain settings groups: aegis: description: Aegis operations fonts: description: Fonts operations origin-h2-max-streams: description: Origin H2 Max Streams operations origin-max-http-version: description: Origin Max Http Version operations origin-tls-compliance-modes: description: Manage zone Origin TLS Compliance Modes setting rum: description: Rum operations speed-brain: description: Speed Brain operations