Cloudflare/tunnel
Cloudflare Tunnel — tunnel management, configurations, connections
2026.09.18.1
Upgrade note: Normalized npm:zod dependency version to 4.6.5 across the
repo. No behavioral changes in this extension.
Global Arguments
| Argument | Type | Description |
|---|---|---|
| apiToken? | string | Cloudflare API token; overrides the CLOUDFLARE_API_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault. |
| accountId | string | Cloudflare account ID |
| Argument | Type | Description |
|---|---|---|
| name? | string | |
| is_deleted? | boolean | |
| existed_at? | string | |
| uuid? | string | |
| was_active_at? | string | |
| was_inactive_at? | string | |
| include_prefix? | string | |
| exclude_prefix? | string | |
| status? | string | |
| per_page? | string | |
| page? | string |
| Argument | Type | Description |
|---|---|---|
| config_src? | unknown | |
| name | unknown | |
| tunnel_secret? | unknown |
| Argument | Type | Description |
|---|---|---|
| tunnel_id | string |
| Argument | Type | Description |
|---|---|---|
| tunnel_id | string | |
| name? | unknown | |
| tunnel_secret? | unknown |
| Argument | Type | Description |
|---|---|---|
| tunnel_id | string |
| Argument | Type | Description |
|---|---|---|
| tunnel_id | string |
| Argument | Type | Description |
|---|---|---|
| tunnel_id | string | |
| config? | unknown |
| Argument | Type | Description |
|---|---|---|
| tunnel_id | string |
| Argument | Type | Description |
|---|---|---|
| tunnel_id | string | |
| client_id? | string |
| Argument | Type | Description |
|---|---|---|
| tunnel_id | string | |
| connector_id | string |
| Argument | Type | Description |
|---|---|---|
| tunnel_id | string | |
| resources | array |
| Argument | Type | Description |
|---|---|---|
| tunnel_id | string |
| Argument | Type | Description |
|---|---|---|
| name? | string | |
| is_deleted? | boolean | |
| existed_at? | string | |
| uuid? | string | |
| was_active_at? | string | |
| was_inactive_at? | string | |
| include_prefix? | string | |
| exclude_prefix? | string | |
| tun_types? | string | |
| status? | string | |
| per_page? | string | |
| page? | string |
Resources
2026.09.17.2
No changes to this extension's methods. Regenerated to refresh the shared _lib/api.ts helper library after PR #427 review fixes to cfApiPaginatedCursor (used by r2, kv, durable-objects, and workers-ai, but emitted into every extension's api.ts since it's part of the shared template).
2026.09.15.1
Changed: Bump zod 4.4.3 → 4.6.5
2026.08.28.2
Hardened codegen: instance names sanitized against path traversal; 429 rate-limit retry with Retry-After; string schema patterns emit regex validation; output schemas passthrough unknown fields; apiToken now optional and vault-wireable with CLOUDFLARE_API_TOKEN env fallback.
2026.08.28.2
Hardened codegen: instance names sanitized against path traversal; 429 rate-limit retry with Retry-After; string schema patterns emit regex validation; output schemas passthrough unknown fields; apiToken now optional and vault-wireable with CLOUDFLARE_API_TOKEN env fallback.
updated labels
2026.08.28.1
Changed: Normalized the extension license to Apache-2.0 and corrected the copyright holder to "Sean Escriva". Extensions that previously shipped an MIT LICENSE.md are now Apache-2.0, consistent with the repository root and every other extension. No code or behavioral changes.
Upgrade note: License text only. No API, schema, or runtime behavior changed.
2026.08.26.2
Fixed: Restored inline npm:zod@4.4.3 import specifiers so the registry
quality scorer can resolve dependencies and score the extension. An earlier
release used a bare "zod" import-map specifier, which published but scored as
unscored.
Changed: Retained explicit compilerOptions.strict in deno.json. No
behavioral or schema changes.
2026.08.26.2
Fixed: Restored inline npm:zod@4.4.3 import specifiers so the registry
quality scorer can resolve dependencies and score the extension. An earlier
release used a bare "zod" import-map specifier, which published but scored as
unscored.
Changed: Retained explicit compilerOptions.strict in deno.json. No
behavioral or schema changes.
2026.08.25.1
Changed: Updated labels for improved extension discoverability. Added cross-cutting category labels (security, observability, finops, infrastructure, networking, compliance, devops, ai, incident-response) where applicable.
updated labels
2026.08.24.1
Added: Output metadata attributes for observability.
durationMs: Method execution duration in milliseconds.collectedBy: Extension name that produced the data.fetchedAt: ISO 8601 timestamp when data was fetched (added to resources that previously lacked it).
2026.08.21.1
Changed: Errors and validation now say what went wrong and where.
- Cloudflare API failures (HTTP errors and
success: falseAPI responses) now name the HTTP method and path that was attempted, in addition to the original status/message. Previously the error read onlyCloudflare API error: <message>, with no indication of which endpoint the method call was hitting — now it readsCloudflare API request failed: GET /accounts/<account>/cfd_tunnel/<id>: <message>. This applies to every method on this model, since they all share the same request helper. tunnel_idandconnector_idare now validated as non-empty before any request is made. Passing an empty string previously sent a request to a malformed URL and produced a confusing 404 from Cloudflare; each now fails fast with a<field> must not be emptymessage.
Upgrade note: No method was added, removed, or renamed. Existing callers that always pass non-empty identifiers see no behavioral change beyond clearer error text.
2026.07.27.1
Fixed: Regenerated from scripts/cloudflare-codegen after two generator
bugs were repaired (webframp/swamp-extensions#284).
Methods referencing an undeclared path parameter did not compile. The generator derived a method's arguments schema and execute signature from the OpenAPI
parameterslist, but built the request URL from the path template. Where the Cloudflare spec omits a declaration for a{placeholder}— which it does in several places — the result was a method witharguments: z.object({})and an unused_argsparameter whose body still interpolatedargs.<name>. Those methods failed type checking and were uncallable even if they had compiled, because the argument was never declared. Path-template placeholders are now unioned into the declared parameters, so the schema, the signature, and the body agree.Generated tests could request a URL the mock server did not serve. Test arguments merged the request-body fixture over the path-parameter values, so a body property sharing a name with a path parameter (commonly
id) substituted its own example value into the URL. The request then missed the mock and failed withCloudflare API error: Not found. Path parameters now take precedence, matching what the generated model already does by excluding path-parameter names from the request body.
Upgrade note: No API surface change and no method was added or removed. If
this extension type-checked and tested cleanly before, its behavior is unchanged
and only the version moved. Extensions that previously failed deno check or
deno task test now pass.
2026.07.19.1
Added: Initial code-generated release of @webframp/cloudflare/tunnel with 13 methods covering the Cloudflare tunnel API surface.
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned