Pimp My IDE / garage dispatch
Back to garage
September 28, 2026 | agent CLIs / cloud APIs / authority

Search is not permission.

Cloudflare's new cf CLI can help an agent find one operation among thousands. That is a useful compression trick. It also shortens the road between a loose request and a live infrastructure change.

Keep five facts separate: the requested outcome, the discovered operation, the credential scope, the approved mutation, and the returned receipt.

The command catalog just got much wider.

Cloudflare introduced an open beta of cf, a new command line tool generated from the company's API schemas. The launch post says Wrangler covers about 280 command paths while cf covers more than 3,000 API operations. It uses JSON by default and includes cf cli search so an agent can find commands by describing a task.[1]

The public package is real. The npm registry reported version 1.0.0-beta.5 during this review. A temporary install completed, and cf --help listed command groups for accounts, cache, DNS, email routing, load balancers, Workers, and other products. No account login or live API call was attempted.[2]

Cheap discovery makes the next control more important, not less.

Discovery and execution are different jobs.

Cloudflare explored the same split in its earlier Code Mode work. That MCP design exposes one tool to search a typed API description and another to execute requests. Cloudflare says the search step narrows a large API without loading every endpoint into model context.[3]

That separation is useful even if you never use MCP. Search should identify an operation and its inputs. A later gate should decide whether the caller may run it. One good result from search must not become a blanket grant to mutate an account.

JSON is a good receipt format, not a safety policy.

Machine-readable output is easier to filter, compare, and save than terminal decoration. It also makes chained work easier. An agent can take an identifier from one response and feed it into the next request.

The same property raises the cost of a vague task. "Fix my DNS" can become a long sequence before a person sees a table. Give the run a named account or zone, a list of allowed methods, an operation budget, and a stop condition. Save the exact request and response fields needed for review.

Typed configuration helps review the proposal.

The launch post presents cloudflare.config.ts as a typed configuration format that language servers can inspect. That can move errors closer to the edit and give an agent better local feedback.[1]

Type checking answers whether the configuration fits its declared shape. It does not answer whether the account, route, hostname, or policy is the one the operator intended. Keep semantic approval outside the type checker.

Put a customs booth before apply.

  1. Write the requested outcome in plain language. Name the account, zone, or resource.
  2. Run discovery without mutation. Record the exact operation and method it found.
  3. Use credentials limited to the named resource and required methods.
  4. Preview the request, current state, expected change, and rollback command.
  5. Require approval for mutation. Then save the request ID, changed resource, response, and follow-up check.

The new tool can make a large API easier to drive. The operator still has to decide where the road ends.

Interactive makeover / API customs gantry

Put authority on rails

Traditional purpose replaced: hand an agent a broad token and approve one vague prompt. Better version: name the task, choose one authority mode, close four review clamps, and copy a bounded run card.

Route the request

The task and authority mode drive the handoff. The four native checkboxes mark which review sections the operator has selected.

Authority mode
Review clamps
Copyable authority card

Draft the run boundary

Replace every bracketed field. Selecting all clamps prepares the template. It does not approve a request or prove that a command ran.

What this component proves. It produces one run-card structure from the task, authority mode, and selected review sections. It does not discover a command, inspect credentials, call an API, approve a mutation, or attach execution evidence.

Sources and limits

Open the source log
  1. Cloudflare, "Introducing cf: the agentic CLI for the entire Cloudflare API", September 28, 2026. Read September 28. This first-party launch post describes the open beta, generated command catalog, JSON default, command search, typed configuration, and claimed operation counts.
  2. cloudflare/cf on GitHub and the cf npm package, read September 28, 2026. The repository identifies the public implementation. The registry returned version 1.0.0-beta.5. A temporary install and local cf --help run succeeded during this review.
  3. Cloudflare, "Code Mode: give agents an entire API in 1,000 tokens", February 20, 2026. Read September 28. This first-party engineering post separates API search from execution and describes typed discovery over a large OpenAPI description.
  4. Cloudflare API reference, read September 28, 2026. The reference shows the breadth of account, DNS, security, storage, Workers, and other operation families behind the CLI.
  5. Hacker News discussion, September 28, 2026. Used for discovery and public reaction only. Comments do not verify product behavior.

Evidence boundary. Operation counts, usage shares, and design benefits come from Cloudflare. The artifact check proves that one registry package installed and printed help in this environment. It does not prove authentication, account compatibility, mutation safety, or production readiness. The gantry is a review template, not a live Cloudflare control.