Cloudflare

Cloud API token

Manage zones, DNS, workers, R2 and the rest of the Cloudflare API from any Windmill script, flow or app.

Set up in 3 steps

1

Create an API token

In the Cloudflare dashboard, open My Profile then API Tokens. Create a token, granting only the permissions and zones your scripts need, and copy it.

2

Add the resource in Windmill

Open Resources, add a resource of type cloudflare, and paste the token. account_id is there for scripts that need it in a path; leave email and key empty.

3

Run your first script

Fork any script below and list your zones. There are over a thousand here, so search by the verb you need.

Scripts

Building blocks, if none of the projects above fit. Fork one, run it, or call it as a step inside your own flow.

Submit a script →

Get Attack Bitrate Summary

Script cloudflare Verified

Update Cron Triggers

Script cloudflare Verified

List virtual networks

Script cloudflare Verified

Update priority of a firewall rule

Script cloudflare Verified

Update Queue

Script cloudflare Verified

Delete Hostname Client Certificate

Script cloudflare Verified

Get IP address

Script cloudflare Verified

Get a firewall rule

Script cloudflare Verified

Get Always Use HTTPS setting

Script cloudflare Verified

Create a list

Script cloudflare Verified

Execute AI model

Script cloudflare Verified

Update Prefix Description

Script cloudflare Verified

Create a new output, connected to a live input

Script cloudflare Verified

Get Access authentication logs

Script cloudflare Verified

Get ASN Subnets

Script cloudflare Verified

Set Account Custom Nameserver Related Zone Metadata

Script cloudflare Verified

Create Custom Hostname

Script cloudflare Verified

Update multiple interconnects

Script cloudflare Verified

Retrieve information about all schemas on a zone

Script cloudflare Verified

List indicator feed permissions

Script cloudflare Verified

Get Layer 3 Attacks By Protocol Timeseries

Script cloudflare Verified

List service tokens

Script cloudflare Verified

List Cloudflare Tunnel connections

Script cloudflare Verified

Update rules

Script cloudflare Verified

Get Top Locations By Device Type

Script cloudflare Verified

Get the default device settings profile

Script cloudflare Verified

By Time

Script cloudflare Verified

Get Deployment Detail

Script cloudflare Verified

Update all list items

Script cloudflare Verified

Delete IPFS Universal Path Gateway Content List Entry

Script cloudflare Verified

Resource type

The shape of the credential every script on this page expects.

FieldTypeRequiredWhat it is
tokenstringYes
account_idstringNo
emailstringNodeprecated
keystringNodeprecated

Questions

What are the email and key fields?

The legacy Global API Key pair, kept for older scripts and marked deprecated. It authenticates as your whole account with no scoping — use an API token instead.

A call returns 403 on one zone but works on another

API tokens are scoped per zone and per permission. Edit the token in Cloudflare to include the zone, rather than widening it to everything.

Is my token stored on the hub?

Never. It lives only in your own Windmill workspace, encrypted at rest.