The command catalog just got much wider.
Cloudflare introduced an open beta of cf, a new command line tool generated from the company's API schemas. The launch post says Wrangler covers about 280 command paths while cf covers more than 3,000 API operations. It uses JSON by default and includes cf cli search so an agent can find commands by describing a task.[1]
The public package is real. The npm registry reported version 1.0.0-beta.5 during this review. A temporary install completed, and cf --help listed command groups for accounts, cache, DNS, email routing, load balancers, Workers, and other products. No account login or live API call was attempted.[2]
Cheap discovery makes the next control more important, not less.
Discovery and execution are different jobs.
Cloudflare explored the same split in its earlier Code Mode work. That MCP design exposes one tool to search a typed API description and another to execute requests. Cloudflare says the search step narrows a large API without loading every endpoint into model context.[3]
That separation is useful even if you never use MCP. Search should identify an operation and its inputs. A later gate should decide whether the caller may run it. One good result from search must not become a blanket grant to mutate an account.
JSON is a good receipt format, not a safety policy.
Machine-readable output is easier to filter, compare, and save than terminal decoration. It also makes chained work easier. An agent can take an identifier from one response and feed it into the next request.
The same property raises the cost of a vague task. "Fix my DNS" can become a long sequence before a person sees a table. Give the run a named account or zone, a list of allowed methods, an operation budget, and a stop condition. Save the exact request and response fields needed for review.
Typed configuration helps review the proposal.
The launch post presents cloudflare.config.ts as a typed configuration format that language servers can inspect. That can move errors closer to the edit and give an agent better local feedback.[1]
Type checking answers whether the configuration fits its declared shape. It does not answer whether the account, route, hostname, or policy is the one the operator intended. Keep semantic approval outside the type checker.
Put a customs booth before apply.
- Write the requested outcome in plain language. Name the account, zone, or resource.
- Run discovery without mutation. Record the exact operation and method it found.
- Use credentials limited to the named resource and required methods.
- Preview the request, current state, expected change, and rollback command.
- Require approval for mutation. Then save the request ID, changed resource, response, and follow-up check.
The new tool can make a large API easier to drive. The operator still has to decide where the road ends.