Cloudflare Cf
Drive Cloudflare's agent-first cf CLI from swamp — intent search, per-command API schemas, credential checks, and any of its 3,000+ API operations with writes dry-run by default, plus a cf activity report
Global Arguments
| Argument | Type | Description |
|---|---|---|
| apiToken? | string | Cloudflare API token, passed to cf as CLOUDFLARE_API_TOKEN. Store in a vault. When omitted, cf falls back to its OAuth profile (`cf auth login`). |
| accountId? | string | Default account ID, passed as CLOUDFLARE_ACCOUNT_ID for account-scoped operations. |
| zone? | string | Default zone (ID or domain name), passed as --zone. A per-call `zone` overrides it. |
| profile? | string | Named cf OAuth profile (--profile). Ignored by cf when apiToken is set. |
| cfCommand | array | Command that launches cf, e.g. ["cf"] or ["npx", "-y", "cf@1.0.0-beta.5"] to pin a version without a global install. |
| allowWrites | boolean | Permit `run` to execute non-GET operations when the call also passes apply=true. Off by default: writes are dry-run only. |
| telemetry | boolean | Allow cf's anonymous usage telemetry (CF_SEND_TELEMETRY). Off by default. |
| timeoutMs | number | Kill a cf invocation that runs longer than this. |
| maxOutputBytes | number | Largest cf stdout persisted per run; larger results are stored truncated as text. |
| workDir? | string | Directory cf runs in. cf writes an account cache (.cloudflare/cache/cloudflare-account.json: account ID and name) into its working directory, so it must not be your swamp repo. Default: $XDG_CACHE_HOME/swamp-cloudflare-cf, else ~/.cache/swamp-cloudflare-cf. |
| Argument | Type | Description |
|---|---|---|
| query | string | Describe the task by action and resource type only — cf asks that queries never include names, domains, IDs or tokens. |
| requestId | string | Data name for the stored search record. Defaults to the spec name so methods never share one. Avoid the reserved name 'latest'. |
| Argument | Type | Description |
|---|---|---|
| command | string | Command path without the leading "cf", e.g. "dns records list". |
| requestId | string | Data name for the stored operation record. Defaults to the spec name so methods never share one. Avoid the reserved name 'latest'. |
| Argument | Type | Description |
|---|---|---|
| requestId | string | Data name for the stored identity record. Defaults to the spec name so methods never share one. Avoid the reserved name 'latest'. |
| Argument | Type | Description |
|---|---|---|
| command | string | Command path without the leading "cf", e.g. "dns records list". Find it with the search method. |
| args | array | Positional arguments, e.g. ["<dns-record-id>"] for "dns records get". |
| flags | record | Command options without dashes, e.g. {"type": "A", "per-page": 100}. true emits a bare flag, false is omitted, arrays repeat the flag. |
| body? | unknown | Request body, sent as --body. An object or array is JSON-encoded; a string is passed through raw — use a string for octet-stream uploads (KV values, R2 objects), or a pre-serialized JSON document. |
| zone? | string | Zone ID or domain for this call; overrides the model's zone. |
| apply | boolean | Execute a non-GET operation for real. Also requires the model's allowWrites; otherwise the write is a dry-run. |
| requestId | string | Data name for the stored result record. Defaults to the spec name so methods never share one. Avoid the reserved name 'latest'. |
Resources
Summarize cf CLI activity for a model — reads, dry-runs and applied writes, per-command counts, and a log of every applied write
cf runs in a private workDir (default ~/.cache/swamp-cloudflare-cf) so its account cache never lands in a repo; string bodies are sent raw for octet-stream uploads; error summaries keep cf's error box. Adds a live e2e suite in the repo.
run fails when cf aborts an unconfirmed destructive action (exit 0, 'Aborted.') instead of recording it as applied; pass flags.force to confirm. Docs: zone names need accountId with scoped tokens.
whoami verifies API tokens with Cloudflare's token-verify endpoints (user, then account when accountId is set); scoped tokens no longer fail. identity gains tokenKind, tokenStatus, expiresOn.
Initial release: search, schema, whoami and run over Cloudflare's cf CLI (writes dry-run unless allowWrites + apply), plus the @sntxrr/cf-activity report.
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned