Client Catalog
Each of the eleven clients covers one purpose in Cloudflare's REST API, with a method for every operation in it. The program that uploads a Worker can also configure the domain it serves, from DNS records to a Turnstile widget on a signup form.
- Clients 11
- Operations 3,437
- Service families 163
- Schema
cloudflare/api-schemasatf2df0ca
Signup Widget
AccountsTurnstileWidgetCreate creates a Turnstile widget for the listed domains and their subdomains. The result has the site key, which your site uses to show the widget, and the secret key for server-side token validation.
open FSharp.CloudEdge.Core.Api.Types
open FSharp.CloudEdge.Management.Security
let createWidget (security: SecurityClient) accountId =
task {
let widget =
AccountsTurnstileWidgetCreatePayload.Create([ "example.com" ], turnstile_widget_mode.Managed, "signup-form")
match! security.AccountsTurnstileWidgetCreate(accountId, widget) with
| AccountsTurnstileWidgetCreate.OK payload ->
return payload.result |> Option.map (fun created -> created.sitekey, created.secret)
| AccountsTurnstileWidgetCreate.Status4XX(status, failure) ->
for error in failure.errors do
printfn "HTTP %d: %s" status error.message
return None
}
For the Worker that validates tokens, upload the secret key in a secret_text binding as on Worker Upload.
Chatbot Gateway
AigConfigCreateGateway creates an AI Gateway, here with a 300-second cache and a rate limit of 100 requests in each 60-second window. The operation declares two responses, OK and BadRequest, and the match covers both.
open FSharp.CloudEdge.Core.Api.Types
open FSharp.CloudEdge.Management.AI
let createGateway (ai: AIClient) accountId =
task {
let gateway =
{ AigConfigCreateGatewayPayload.Create(cache_invalidate_on_update = true, collect_logs = true, id = "chatbot") with
cache_ttl = Some 300
rate_limiting_limit = Some 100
rate_limiting_interval = Some 60
rate_limiting_technique = Some AigConfigCreateGatewayPayloadRate_limiting_technique.Fixed }
match! ai.AigConfigCreateGateway(accountId, body = gateway) with
| AigConfigCreateGateway.OK payload ->
printfn "Gateway %s created at %O" payload.result.id payload.result.created_at
| AigConfigCreateGateway.BadRequest failure ->
printfn "Gateway rejected: %A" failure.errors
}
Avatar Upload
CloudflareImagesCreateAuthenticatedDirectUploadUrlV2 returns a URL for one unauthenticated upload, a single multipart POST of the image. A browser can send a user's picture to that URL. The creator argument is the user's ID, which Cloudflare saves in the image's creator field. The expiry must be between 2 minutes and 6 hours after the call.
open System
open FSharp.CloudEdge.Core.Api.Types
open FSharp.CloudEdge.Management.Media
let uploadUrl (media: MediaClient) accountId (userId: string) =
task {
let expiry = DateTimeOffset.UtcNow.AddMinutes 30.
match! media.CloudflareImagesCreateAuthenticatedDirectUploadUrlV2(accountId, creator = userId, expiry = expiry) with
| CloudflareImagesCreateAuthenticatedDirectUploadUrlV2.OK payload ->
return Some(string payload.result["uploadURL"])
| CloudflareImagesCreateAuthenticatedDirectUploadUrlV2.Status4XX(status, failure) ->
for error in failure.errors do
printfn "HTTP %d: %s" status error.message
return None
}
Page View Report
AnalyticsEngineSqlQueryPost sends SQL to Workers Analytics Engine as a plain-text body. The query ends in FORMAT JSON, since the client decodes the OK response as one JSON object and the default output is newline-delimited JSON.
open FSharp.CloudEdge.Core.Api.Types
open FSharp.CloudEdge.Management.Observability
let topPages (observability: ObservabilityClient) accountId =
task {
let sql =
"SELECT blob1 AS path, SUM(_sample_interval) AS views FROM page_views "
+ "WHERE timestamp > NOW() - INTERVAL '7' DAY "
+ "GROUP BY path ORDER BY views DESC LIMIT 10 FORMAT JSON"
match! observability.AnalyticsEngineSqlQueryPost(accountId, sql) with
| AnalyticsEngineSqlQueryPost.OK report ->
for row in report.data do
printfn "%O %O" row["path"] row["views"]
| AnalyticsEngineSqlQueryPost.BadRequest message ->
printfn "Query rejected: %s" message
| other ->
printfn "%A" other
}
Needs a Worker that writes page paths to blob1 of a dataset named page_views, through an analytics_engine binding as listed on Worker Upload.
Contact Address
An Email Routing rule forwards mail for one address on your domain to another inbox. Forward actions require a verified destination address. The operation's two error responses are union cases without a payload: BadRequest for an unverified destination and UnprocessableEntity for invalid input.
open FSharp.CloudEdge.Core.Api.Types
open FSharp.CloudEdge.Management.Messaging
let forwardContact (messaging: MessagingClient) zoneId =
task {
let toContact =
{ email_rule_matcher.Create email_rule_matcherType.Literal with
field = Some Field.To
value = Some "hello@example.com" }
let forward = { email_rule_action.Create email_rule_actionType.Forward with value = Some [ "owner@example.net" ] }
let rule = { email_create_rule_properties.Create([ forward ], [ toContact ]) with name = Some "Contact address" }
match! messaging.EmailRoutingRoutingRulesCreateRoutingRule(zoneId, rule) with
| EmailRoutingRoutingRulesCreateRoutingRule.OK _ ->
printfn "hello@example.com forwards to owner@example.net"
| EmailRoutingRoutingRulesCreateRoutingRule.BadRequest ->
printfn "Rule rejected with HTTP 400"
| EmailRoutingRoutingRulesCreateRoutingRule.UnprocessableEntity ->
printfn "Rule rejected with HTTP 422"
}
Needs a verified destination address and the zone ID from the domain's Overview page. EmailRoutingSettingsEnableEmailRouting turns on Email Routing for the zone and adds its MX and SPF records.
Tiered Cache
With Smart Tiered Cache, Cloudflare picks the upper-tier data center for each of a site's origins from its latency data. This call turns it on for one zone.
open FSharp.CloudEdge.Core.Api.Types
open FSharp.CloudEdge.Management.ContentDelivery
let enable (delivery: ContentDeliveryClient) zoneId =
task {
let turnOn = cache_u002D_rules_smart_tiered_cache_patch.Create cache_u002D_rules_smart_tiered_cache_patchValue.On
match! delivery.SmartTieredCachePatchSmartTieredCacheSetting(zoneId, turnOn) with
| SmartTieredCachePatchSmartTieredCacheSetting.OK _ ->
printfn "Smart Tiered Cache is on"
| SmartTieredCachePatchSmartTieredCacheSetting.Status4XX(status, failure) ->
printfn "HTTP %d: %O" status failure.errors
}
Shop Record
The request type for a DNS record is a JSON wrapper, one of 217 such types in Core.Api. Its FromJson method takes a JsonElement, which JsonSerializer.SerializeToElement produces from an anonymous record. This CNAME points shop.example.com at another host through Cloudflare's proxy. The name is the full name including the zone, and a ttl of 1 means automatic.
open System.Text.Json
open FSharp.CloudEdge.Core.Api.Types
open FSharp.CloudEdge.Management.Networking
let addRecord (networking: NetworkingClient) zoneId =
task {
let record =
JsonSerializer.SerializeToElement
{| ``type`` = "CNAME"; name = "shop.example.com"; content = "shop.example.net"; proxied = true; ttl = 1 |}
|> dns_u002D_records_dns_u002D_record_u002D_post.FromJson
match! networking.DnsRecordsForAZoneCreateDnsRecord(zoneId, record) with
| DnsRecordsForAZoneCreateDnsRecord.OK payload ->
printfn "DNS record created: %b" payload.success
| DnsRecordsForAZoneCreateDnsRecord.Status4XX(status, failure) ->
for error in failure.errors do
printfn "HTTP %d: %s" status error.message
}
Library Table
| Library | Operations | What it covers |
|---|---|---|
| Application Platform | ||
Management.Compute |
304 | Workers, Pages, Queues, Workflows, Containers |
Management.Storage |
153 | R2, D1, Workers KV, Vectorize, Hyperdrive |
Management.AI |
152 | AI Gateway, AI Search, Workers AI |
Management.Media |
175 | Stream, Images, Realtime, Calls |
| Network and Security | ||
Management.Networking |
505 | DNS, load balancing, Tunnel, Spectrum |
Management.ContentDelivery |
65 | Cache settings, Pay per crawl, Smart Shield |
Management.Security |
1,295 | Zero Trust, rulesets, API Shield, Turnstile |
| Insight and Messaging | ||
Management.Observability |
386 | Logs, Logpush, analytics, Radar |
Management.Messaging |
98 | Email Routing, email sending, notifications |
| Account Administration | ||
Tenancy |
300 | Accounts, members, API tokens, zones |
Management.Browser |
4 | Browser extension settings |
Core.Api contains every payload type and response union. The clients also share its HTTP transport. Cloudflare's OpenAPI document has 3,448 operations. The difference is eight retired operations and three internal routes.
Service families in each client
Management.Compute, 11 families:workers114,builds31,browser-rendering28,pages26,queues23,workflows23,pipelines19,containers14,flagship14,snippets8,triggers4Management.Storage, 9 families:r246,vectorize24,artifacts17,storage14,r2-catalog13,d112,secrets-store12,hyperdrive8,resource-library7Management.AI, 6 families:ai-gateway66,ai-search49,agent-memory14,ai14,autorag7,ai-audit2Management.Media, 6 families:realtime61,stream50,images44,calls10,moq8,media2Management.Networking, 29 families:magic177,load-balancers42,addressing41,secondary-dns28,waiting-rooms24,custom-pages18,cni16,mnm16,dns-records15,teamnet14,cfd-tunnel12,web312,warp-connector11,dns-firewall9,dns-settings9,healthchecks9,spectrum9,data-localization7,origin7,connectivity5,custom-ns5,argo4,dnssec4,hostnames4,cloud-connector2,dns-analytics2,cache1,ips1,tunnels1Management.ContentDelivery, 6 families:cache21,pay-per-crawl17,smart-shield10,environments7,pagerules7,url-normalization3Management.Security, 53 families:cloudforce-one231,access165,dlp93,email-security73,devices70,gateway57,api-gateway44,firewall42,brand-protection41,intel39,data-security36,rulesets32,dex31,security-center26,vuln-scanner22,scim16,schema-validation15,token-validation15,zerotrust15,urlscanner14,origin-tls-client-auth13,page-shield13,ssl12,custom-hostnames11,one11,rules11,zt-risk-scoring11,abuse-reports10,pcaps9,content-upload-scan8,custom-csrs8,infrastructure8,filters7,leaked-credential-checks7,oauth-clients7,advanced-certificates6,challenges6,custom-certificates6,sso-connectors6,client-certificates5,keyless-certificates5,mtls-certificates5,rate-limits5,ai-security4,bot-management4,botnet-feed4,certificates4,managed-headers3,certificate-authorities2,ct2,fraud-detection2,precursor2,dcv-delegation1Management.Observability, 12 families:radar273,logpush34,logs29,rum13,analytics10,speed-api10,diagnostics6,reporting6,analytics-engine2,audit-logs1,rate-limit-analytics1,request-tracer1Management.Messaging, 4 families:email64,alerting25,event-subscriptions5,event-notifications4Tenancy, 26 families:settings57,user55,shares20,billing18,organizations18,iam17,zones16,registrar13,subscriptions13,registrar-sandbox10,tags10,tenants8,tokens8,accounts7,payment-methods6,members5,memberships4,subscription4,entitlements2,profile2,roles2,invoices1,oauth1,pay-bad-debt1,pay-invoice1,receipts1Management.Browser, 1 family:browser-extension4
Related Pages
NuGet packages
Core.Api 0.1.0, Management.AI 0.1.0, Management.Browser 0.1.0, Management.Compute 0.1.0, Management.ContentDelivery 0.1.0, Management.Media 0.1.0, Management.Messaging 0.1.0, Management.Networking 0.1.0, Management.Observability 0.1.0, Management.Security 0.1.0, Management.Storage 0.1.0, Tenancy 0.1.0.