Skip to content
← Public packages

@kody/cloudflare

Call Cloudflare zones, Workers, analytics, WAF, and Log Explorer with a saved API token.

README.md

72 lines · 3.1 KB · Markdown

@kody/cloudflare

Intent

Reusable Cloudflare helpers so Kody agents can call the caller's API v4 endpoints, GraphQL analytics, Log Explorer, WAF rulesets, and allowlisted developer docs — not a shared platform account. Auth is a saved API token, not OAuth. Analytics, logs, and docs stay read-only. Rulesets default to dry-run and only apply after apply: true.

This listing is meant to be forked. After you fork, save your own cloudflareApiToken and call the helpers in your account. No account ids or zone names are baked into the package.

Share this package as https://kody.codes/@kody/cloudflare

What it does

  • Call Cloudflare API v4 for zones, Workers, D1, R2, KV, or related resources
  • Summarize zone HTTP traffic by status, path, or user agent during outage forensics
  • Search Workers traces, HTTP requests, or Access events via Log Explorer SQL
  • Preview or apply WAF custom rules that block bogus crawler routes before origin
  • Fetch allowlisted Cloudflare developer documentation while building integrations

Prerequisites / setup

API token (secret-backed). There is no Cloudflare OAuth integration. Do not open /connect/oauth for Cloudflare. Never paste the token into chat. Agents: see AGENTS.md for import paths, smoke, and mutation guards.

SecretPurpose
cloudflareApiTokenAPI token for API v4, GraphQL analytics, Log Explorer, and rulesets
  1. Create a token at dash.cloudflare.com/profile/api-tokens. A read token is enough for verify, analytics, and Log Explorer. Grant firewall / ruleset edit only if you will call ./rulesets with apply: true.
  2. Save it in Kody:

https://kody.codes/account/secrets/new?name=cloudflareApiToken&description=Cloudflare%20API%20token%20for%20API%20v4%2C%20analytics%2C%20Log%20Explorer%2C%20and%20rulesets&allowedHosts=api.cloudflare.com&scope=user

  1. Approve host api.cloudflare.com.
  2. Smoke-test with ./api-v4 against /client/v4/user/tokens/verify.

./docs fetches allowlisted pages from developers.cloudflare.com and does not use the token.

Hosts
  • api.cloudflare.com — API v4, GraphQL analytics, Log Explorer, rulesets
  • developers.cloudflare.com — allowlisted developer docs (./docs only)

Done when

  • cloudflareApiToken is saved and host api.cloudflare.com is approved
  • Token verify via ./api-v4 succeeds
  • ./rulesets stays dry-run unless apply: true; analytics/logs/docs stay read-only

Branding

community-icon.svg is Cloudflare's official cloud mark (Simple Icons, CC0) on Cloudflare orange #F38020. Cloudflare® is a trademark of Cloudflare, Inc. This package is not affiliated with or endorsed by Cloudflare.

Keep LICENSE (MIT), ## Intent, and community-icon.svg intact for community listing.

Docs