Every cf workflow starts the same way: install the CLI, sign in, and run a
command. The reference sections at the end of this page explain how cf
chooses credentials, accounts, and zones.
- A Cloudflare account. If you do not have one, sign up ↗︎.
- Node.js 22.18 or later. Bun is not supported. When
cfruns on Bun, commands that loadcloudflare.config.tsfail.
Install cf globally so the command is available in every directory:
npm install --global cfyarn global add cfpnpm add --global cfbun add --global cfThe package installs two commands that run the same CLI: cf and
cloudflare. Use cloudflare if another tool named cf is already on your
PATH.
Confirm the installation:
cf --versionTo update cf later, install the latest release:
npm install --global cf@latestyarn global add cf@latestpnpm add --global cf@latestbun add --global cf@latestA project can also add cf as a development dependency. Inside that project,
the global cf command runs the version installed in the project, so
collaborators, coding agents, and continuous integration (CI) use the same
release. Projects created with cf init already include it.
-
Start the sign-in flow:
cf auth logincfprints a link and a one-time code, and opens the link in your browser. Approve the request to givecfaccess to your Cloudflare account. -
Confirm that you are signed in:
cf auth whoami
On a remote machine, over SSH, or in a container, add --no-browser. cf
prints the link without opening it, and you can approve the request from a
browser on another device. To sign in again, add --force.
cf keeps its own credentials and does not reuse a Wrangler login. Sign in
once, even if you already use Wrangler.
List the zones you can access:
cf zones listResults are JSON on standard output. Progress and status messages go to standard error, so you can redirect or pipe results without extra flags:
cf zones list > zones.jsonTo find the command for a task, describe the task to cf cli search:
cf cli search "create a DNS record"cf cli search prints up to five matching commands as JSON. It runs locally
and does not need credentials. To browse instead, add --help to cf, to a
product such as cf dns, or to any command.
For a walkthrough that finds, creates, and deletes a resource, refer to Manage resources from the command line.
Add completion to your shell profile, then restart your shell:
cf complete zsh >> ~/.zshrccf complete also supports bash, fish, and powershell. Run
cf complete --help for the bash and fish equivalents.
cf uses the first credential it finds:
- The
CLOUDFLARE_API_TOKENenvironment variable, including a value loaded from a.envfile. - The profile selected with
--profile <NAME>. - The profile bound to the current directory, or to its nearest parent, with
cf auth activate. - The default profile, which
cf auth loginsigns in to.
cf does not support the Global API Key.
When a command needs an account, cf selects one in this order:
- The
CLOUDFLARE_ACCOUNT_IDenvironment variable. - The
accountIdfield in the default export ofcloudflare.config.ts. - The account
cfsaved for this project on an earlier command. - The only account your credentials can access. If there are several,
cfasks you to choose one.
When cf selects your only account, or you choose one, it saves that account
and uses it on later commands in the same project without asking. It stores
the account in cloudflare-account.json, or cloudflare-account-<PROFILE>.json
for a named profile, in .cache/cloudflare/ inside the nearest node_modules
directory. It uses .cloudflare/cache/ in the current directory instead when
there is no node_modules directory, or when .cloudflare/cache/ already
exists and the node_modules cache does not.
To choose again, delete that file. Running cf auth login --force or
cf auth logout from the project directory also clears it, but not while
CLOUDFLARE_API_TOKEN is set.
In a non-interactive session, such as a script or CI job, a command fails if your credentials can access more than one account and no account is set or saved.
To set a default account for a project, refer to Set account defaults.
Zone-scoped commands accept --zone or -z. The value can be a zone ID or a
domain name:
cf dns records list --zone example.comFor a domain name, cf looks up the matching zone in the
selected account. The --zone option takes priority over
the CLOUDFLARE_ZONE_ID environment variable.
Profiles keep separate credentials, for example for work and personal accounts. Create a profile:
cf auth create workcf auth create creates the profile and starts a sign-in for it. To use the
profile in a project, bind it to the project directory:
cf auth activate workcf auth activate binds the profile to the current directory and its
subdirectories. To bind a different directory, pass it after the profile name.
To remove the binding, run cf auth deactivate. To use a profile for a single
command, pass --profile <NAME>. To see your profiles, run cf auth list.
cf auth create, cf auth activate, cf auth deactivate, and
cf auth delete do not run while CLOUDFLARE_API_TOKEN is set, because the
token takes priority over every profile.
In CI and other non-interactive environments, set an API token instead of
running cf auth login:
export CLOUDFLARE_API_TOKEN=<API_TOKEN>
export CLOUDFLARE_ACCOUNT_ID=<ACCOUNT_ID>Give the token only the permissions the job needs. To create one, refer to
Create an API token. For a
complete pipeline setup, refer to Use cf in CI.
API commands read these variables from a .env file in the current directory:
CLOUDFLARE_API_TOKENCLOUDFLARE_ACCOUNT_IDCLOUDFLARE_ZONE_IDCLOUDFLARE_COMPLIANCE_REGIONCLOUDFLARE_ACCESS_CLIENT_IDCLOUDFLARE_ACCESS_CLIENT_SECRET
For example:
CLOUDFLARE_API_TOKEN=<API_TOKEN>
CLOUDFLARE_ACCOUNT_ID=<ACCOUNT_ID>cf reads only .env. It does not read .env.local or mode-specific files
such as .env.<MODE>. Variables already set in your environment override the
file.
Commands run with --local do not read the file. cf deploy,
cf previews deploy, cf workers versions create, and
cf workers triggers deploy read it only after the build finishes.
- To review CLI settings, see the environment variables.
- If you are new to Workers, deploy your first Worker.
- If you manage zones and DNS, manage resources from the command line.
- If you use Wrangler today, read
cffor Wrangler users. - If you work with a coding agent, set up
cffor agents. - If you deploy from a pipeline, use
cfin CI.