Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Cloudflare’s beta cf CLI is built for working with both the public Cloudflare API and Workers projects. With a coding agent, the safest documented workflow is to search for the task, inspect the matching command, preview changes with --dry-run, and execute only after checking the target and scope. The CLI returns command results as JSON, but a zero exit code does not always mean a destructive action happened.

What the cf CLI does—and what “agentic” means here

Cloudflare describes cf as one command-line interface for the public Cloudflare API and Workers projects. It is a beta product, so commands and configuration can change. Cloudflare says it includes more than 2,900 commands, most generated from public API schemas; that is Cloudflare’s documented count, not an independent audit or a measure of agent performance. Cloudflare CLI overview

The agent-oriented design is a sequence of discover, inspect, preview, and act. Instead of asking an agent to load a huge command tree at once, the CLI can find likely operations from a task description, expose their arguments and API shape, and show a proposed request before sending it. These are documented capabilities, not evidence of measured improvements in accuracy, speed, or safety.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Find a command by describing the task

Use cf cli search with a short description of the operation, for example cf cli search "create D1 database" or cf cli search "create a DNS record". Search runs locally, does not require credentials, and returns up to five matching commands as JSON, with the best match first. This narrows the options without requiring the agent to inspect every command’s help.

cf cli search "create D1 database"

Treat the results as candidates rather than permission to act. Check that the command matches the intended resource, account, and operation before continuing. Cloudflare’s guide to using cf with coding agents

Inspect the command before calling it

After choosing a candidate, inspect its API operation and command-specific help. The schema describes the operation ID, HTTP method, path, parameters, whether there is a request body, and the body fields when they are available.

Check the API schema

cf schema <command>

Some request-body schemas have incomplete or empty field listings. Do not infer that an operation needs no body from an empty listing; consult the relevant API reference and, where appropriate, pass the complete body with --body.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check arguments and options

cf <command> --help

Use help alongside the schema: the schema explains the underlying API operation, while command help shows the CLI’s accepted arguments and options. Together they let an agent verify what it will send rather than relying only on a search result.

Preview writes and handle destructive operations cautiously

Add --dry-run to print the request as JSON without sending it. A dry run does not require credentials. Review the preview for the intended resource and scope before allowing a write.

cf <command> --dry-run

For destructive commands, inspect the result as well as the exit status. Cloudflare warns that a destructive command run without --force in a non-interactive session may print Aborted. and still exit with status 0. Therefore, a successful process status alone does not prove that a deletion occurred.

Do not add --force merely to make automation continue. In some commands, force is also an API parameter and can broaden the impact—for example, deleting a Worker that other Workers reference. Verify exactly what is being removed and which dependent resources may be affected.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use JSON output without assuming every response is a populated object

Command results go to standard output as JSON; messages and errors go to standard error. When stdout is not a terminal, it contains only the result, which makes it suitable for parsing or piping to tools such as jq.

cf <command> | jq

Build automation around the command’s documented response shape, not a universal assumption that every invocation emits one populated JSON object. List commands return one page at a time, and paging options vary by command. Some commands that return no data produce no stdout. Account for pagination and empty output in scripts, and use stderr and the exit status as separate signals rather than treating either as a complete description of what happened.

Set up authentication for people and automation

Cloudflare’s getting-started guide lists global installation through npm, Yarn, pnpm, or Bun. Node.js 22.18 or later is required for loading cloudflare.config.ts; Bun is not supported for loading that file. The package provides both cf and cloudflare command names, so use cloudflare if another program already occupies cf on your PATH. Cloudflare CLI getting started

Interactive login

  1. Run cf auth login and complete Cloudflare’s OAuth flow.

    Free tools Windows power users keep installed

    One-click scans. No signup required.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Confirm the logged-in identity with cf auth whoami.

The CLI manages its own credentials and does not reuse a Wrangler login.

Unattended agents and CI

For automation, set CLOUDFLARE_API_TOKEN and limit the token to the permissions the job requires. The Global API Key is not supported. Credential precedence starts with the environment token, followed by a selected profile, a directory-bound profile, and then the default login. In a non-interactive session where more than one account is accessible, resolve account selection explicitly or save the intended selection before running commands. Cloudflare’s guide to using cf with coding agents

Choose the right boundary between cf and Wrangler

Cloudflare says resource commands can run alongside an existing Wrangler project. That does not mean every project command can safely use the project’s existing Wrangler configuration: the tools have different documented scopes and configuration expectations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Consideration cf Wrangler
Scope Public Cloudflare API and Workers projects, according to Cloudflare’s CLI overview. Workers project workflows, according to Cloudflare’s CLI overview.
Configuration cloudflare.config.ts for Workers project configuration; the format is open beta. Existing projects may use wrangler.jsonc or wrangler.toml.
Agent discovery Natural-language command search, schema inspection, command help, and JSON output are documented. The sources do not establish an equivalent agent-oriented discovery flow.
Migration risk Project commands need the supported configuration or a migration; beta behavior can change. Existing Wrangler projects can continue to use their current configuration for Wrangler workflows.
Authentication Uses its own credentials; an environment API token takes precedence, and non-interactive account selection may need to be explicit. The sources do not establish a like-for-like authentication comparison.

The comparison is not a claim that one tool is universally better. The right choice depends on whether the task is a public API resource operation or a Workers project operation, and on the project’s current configuration. Cloudflare’s guide to using cf with coding agents

Do not run project commands against an unmigrated Wrangler configuration

Cloudflare warns against running cf dev, cf build, or cf deploy in a project that has a Wrangler configuration but no cloudflare.config.ts. Those commands may generate a configuration that ignores wrangler.jsonc, or they may fail.

The documented migration path begins with a preview:

  1. Run cf migrate --dry-run to preview the migration.

  2. Proceed with the migration only after reviewing the proposed changes.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  3. Resolve the generated TODO(@cloudflare) comments in the resulting configuration.

The typed configuration format is open beta. It can define Worker, Container, and account settings; loading it requires Node.js 22.18 or later, and Bun is not supported for loading it. Project commands can evaluate the configuration and build the application, so configuration errors can affect execution. Cloudflare typed configuration documentation

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A practical agent workflow

  1. Confirm the project context: identify whether the task concerns a public API resource or a Workers project, and check the project’s configuration before using project commands.

  2. Search with a task phrase using cf cli search.

  3. Inspect the selected operation with cf schema <command> and cf <command> --help. Check request-body details in the API reference if the schema listing is incomplete.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  4. Check authentication and account selection, especially in unattended runs.

  5. Preview a write with --dry-run; verify the target, parameters, body, and scope.

  6. Execute only after the preview is acceptable. For destructive operations, treat --force as high-impact and inspect the resulting output rather than relying on a zero exit status.

  7. Parse stdout as JSON, handle stderr separately, and account for pagination or no-output responses where relevant.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare’s documentation describes these behaviors as features of the beta CLI; it does not provide published benchmarks for agent accuracy, token savings, task completion time, or safety outcomes. Cloudflare’s cf CLI launch article

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.