Skip to main content

Cloudflare Cf

@sntxrr/cloudflare-cfv2026.09.29.2· 7d agoMODELSREPORTS
01README

Drive Cloudflare's agent-first cf CLI from swamp — intent search, per-command API schemas, credential checks, and any of its 3,000+ API operations with writes dry-run by default, plus a cf activity report

02Models1
@sntxrr/cloudflare-cfv2026.09.29.2cloudflare_cf.ts

Global Arguments

ArgumentTypeDescription
apiToken?stringCloudflare API token, passed to cf as CLOUDFLARE_API_TOKEN. Store in a vault. When omitted, cf falls back to its OAuth profile (`cf auth login`).
accountId?stringDefault account ID, passed as CLOUDFLARE_ACCOUNT_ID for account-scoped operations.
zone?stringDefault zone (ID or domain name), passed as --zone. A per-call `zone` overrides it.
profile?stringNamed cf OAuth profile (--profile). Ignored by cf when apiToken is set.
cfCommandarrayCommand that launches cf, e.g. ["cf"] or ["npx", "-y", "cf@1.0.0-beta.5"] to pin a version without a global install.
allowWritesbooleanPermit `run` to execute non-GET operations when the call also passes apply=true. Off by default: writes are dry-run only.
telemetrybooleanAllow cf's anonymous usage telemetry (CF_SEND_TELEMETRY). Off by default.
timeoutMsnumberKill a cf invocation that runs longer than this.
maxOutputBytesnumberLargest cf stdout persisted per run; larger results are stored truncated as text.
workDir?stringDirectory cf runs in. cf writes an account cache (.cloudflare/cache/cloudflare-account.json: account ID and name) into its working directory, so it must not be your swamp repo. Default: $XDG_CACHE_HOME/swamp-cloudflare-cf, else ~/.cache/swamp-cloudflare-cf.
fn search(query: string, requestId: string)
Find the cf command for a task by describing it (cf cli search)
ArgumentTypeDescription
querystringDescribe the task by action and resource type only — cf asks that queries never include names, domains, IDs or tokens.
requestIdstringData name for the stored search record. Defaults to the spec name so methods never share one. Avoid the reserved name 'latest'.
fn schema(command: string, requestId: string)
Record a cf command's API operation: HTTP method, path and parameters
ArgumentTypeDescription
commandstringCommand path without the leading "cf", e.g. "dns records list".
requestIdstringData name for the stored operation record. Defaults to the spec name so methods never share one. Avoid the reserved name 'latest'.
fn whoami(requestId: string)
Verify the configured credential: API tokens against Cloudflare's token-verify endpoints, OAuth via cf auth whoami; fails when it is not usable
ArgumentTypeDescription
requestIdstringData name for the stored identity record. Defaults to the spec name so methods never share one. Avoid the reserved name 'latest'.
fn run(command: string, args: array, flags: record, body?: unknown, zone?: string, apply: boolean, requestId: string)
Run a cf API operation and store its JSON result; non-GET operations are dry-run unless allowWrites and apply are both set
ArgumentTypeDescription
commandstringCommand path without the leading "cf", e.g. "dns records list". Find it with the search method.
argsarrayPositional arguments, e.g. ["<dns-record-id>"] for "dns records get".
flagsrecordCommand options without dashes, e.g. {"type": "A", "per-page": 100}. true emits a bare flag, false is omitted, arrays repeat the flag.
body?unknownRequest body, sent as --body. An object or array is JSON-encoded; a string is passed through raw — use a string for octet-stream uploads (KV values, R2 objects), or a pre-serialized JSON document.
zone?stringZone ID or domain for this call; overrides the model's zone.
applybooleanExecute a non-GET operation for real. Also requires the model's allowWrites; otherwise the write is a dry-run.
requestIdstringData name for the stored result record. Defaults to the spec name so methods never share one. Avoid the reserved name 'latest'.

Resources

search(infinite)— Commands matching a `cf cli search` intent query
operation(infinite)— API schema of one cf command: HTTP method, path and parameters
identity(infinite)— Authentication status reported by `cf auth whoami`
result(infinite)— Outcome of a `run`: the argv, read/dry-run/apply mode, and parsed JSON output
03Reports1
@sntxrr/cf-activitymodel
cf_activity.ts

Summarize cf CLI activity for a model — reads, dry-runs and applied writes, per-command counts, and a log of every applied write

cloudflareauditcf
04Previous Versions4
2026.09.29.1

cf runs in a private workDir (default ~/.cache/swamp-cloudflare-cf) so its account cache never lands in a repo; string bodies are sent raw for octet-stream uploads; error summaries keep cf's error box. Adds a live e2e suite in the repo.

2026.09.28.3

run fails when cf aborts an unconfirmed destructive action (exit 0, 'Aborted.') instead of recording it as applied; pass flags.force to confirm. Docs: zone names need accountId with scoped tokens.

2026.09.28.2

whoami verifies API tokens with Cloudflare's token-verify endpoints (user, then account when accountId is set); scoped tokens no longer fail. identity gains tokenKind, tokenStatus, expiresOn.

2026.09.28.1

Initial release: search, schema, whoami and run over Cloudflare's cf CLI (writes dry-run unless allowWrites + apply), plus the @sntxrr/cf-activity report.

05Stats
A
100 / 100
Downloads
14
Archive size
21.5 KB
  • Has README or module doc2/2earned
  • README has a code example1/1earned
  • README is substantive1/1earned
  • Most symbols documented1/1earned
  • No slow types (deprecated)1/1earned
  • Dependencies pass trust audit2/2earned
  • Has description1/1earned
  • Platform support declared (or universal)2/2earned
  • License declared1/1earned
  • Verified public repository2/2earned
06Platforms
07Labels