K2 streams can be created, updated, and deleted with the REST API.
To create, update, or delete streams, your API token needs the K2 Config Write permission. To get or list streams, it needs the K2 Config Read permission.
| Setting | Type | Required | Default | Description |
|---|---|---|---|---|
name |
string | Yes | None | 1 to 128 letters, numbers, or underscores. Must be unique in your account. Not case-sensitive. |
retention_seconds |
integer | No | 604800 |
How long K2 retains records, from 3600 (one hour) to 2592000 (30 days). |
http |
object | Yes | None | Configures the HTTP input. Refer to HTTP input. |
worker_binding |
object | No | { enabled: true } |
Configures the Workers binding input. Refer to Workers binding input. |
At least one of http or worker_binding must be enabled.
You cannot rename a stream after you create it.
An input is a way for producers to write records to a stream. K2 supports two inputs:
- HTTP: Producers send records to the stream's
/produceendpoint. - Workers binding: A Worker sends records through a binding.
| Field | Type | Required | Description |
|---|---|---|---|
enabled |
boolean | Yes | Enables the /produce endpoint. |
authentication |
boolean | No | Requires an API token with the K2 Produce permission to produce. If omitted or false, anyone with the stream endpoint can produce. |
cors.origins |
array of strings | No | Origins allowed to produce from a browser. Refer to CORS. |
When authentication is true, producers using the HTTP API must send an API token in the
Authorization: Bearer <TOKEN> header. The token must have permission to
produce to K2 streams (K2 Produce) in the account that owns the stream.
Configure cors.origins to allow browsers to produce records from a web page. Each entry must be one of the following:
- An
http://orhttps://origin, such ashttps://example.com. Origins cannot include a path, query string, fragment, or credentials. *, to allow any origin. If you use*, it must be the only entry.
You can configure up to five origins. Each origin must be unique.
| Field | Type | Required | Description |
|---|---|---|---|
enabled |
boolean | Yes | Allows Workers to produce to the stream with a binding. |
If you omit worker_binding when you create a stream, the Workers binding input is enabled.
retention_seconds sets how long K2 retains records after it receives them.
The value must be between 3600 (one hour) and 2592000 (30 days). The
default is 604800 (seven days).
K2 deletes expired records in the background. Records can remain readable for some time after their retention period ends, so do not rely on retention to remove data at an exact time.
To change a stream's settings, send a PATCH request with the settings to change. You can update retention_seconds, http, and worker_binding. Include at least one of these fields.
curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/k2/streams/$STREAM_ID" \
--request PATCH \
--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
--header "Content-Type: application/json" \
--data '{
"retention_seconds": 86400,
"worker_binding": { "enabled": false }
}'The response contains the updated stream:
{
"success": true,
"errors": [],
"messages": [],
"result": {
"id": "241fa65b438a4d539a19371f58bfdae0",
"name": "orders",
"retention_seconds": 86400,
"endpoint": "https://241fa65b438a4d539a19371f58bfdae0.k2.cloudflarestorage.com",
"http": {
"enabled": true,
"authentication": true
},
"worker_binding": {
"enabled": false
},
"created_at": "2026-09-24T21:19:19.246Z",
"modified_at": "2026-09-29T14:25:54.712Z"
}
}When you update an input, the new object replaces the existing one. For
example, to add a CORS origin to the HTTP input, send the complete http
object, including enabled and authentication. To disable an input, set it
to { "enabled": false }. You cannot disable both inputs.