One parameter now moves the search engine.
Cloudflare released Web Search API in open beta on October 2. A request names Ceramic.ai, Exa, or Linkup. Cloudflare routes the query through AI Gateway and returns normalized items with URLs, titles, and descriptions.[1][2]
The clean interface is useful. It is not proof that the providers are interchangeable. The provider page lists different prices, retention support, search modes, and description behavior. Ceramic is the default. Exa uses its auto mode and returns highlights. Linkup uses its fast depth with raw search results.[3]
Shared JSON removes adapter work. It does not remove procurement work.
Zero retention and gateway logging are separate controls.
Cloudflare's provider table marks Ceramic and Linkup as supporting Zero Data Retention. It marks Exa as not supporting it. That statement concerns provider retention for requests made through this product. It does not mean the gateway keeps no record.
AI Gateway logging is enabled by default. Cloudflare says a log can include the prompt, response, provider, time, status, usage, cost, duration, and user agent. The gateway setting can disable collection, and a request can override that setting with a header.[4]
For search, the query may carry unreleased product names, incident details, customer identifiers, or a private error string. Decide whether the query belongs in a gateway log before the tool call leaves the agent.
A source link is an address, not a supported claim.
The API returns up to ten items. Each item can include a URL, title, and description. The response metadata can include the original query, a request ID, and latency. That is enough to discover pages. It is not enough to prove that a drafted sentence follows from the page.[2]
Fetch the selected page. Read the relevant passage. Save the exact URL beside the claim. If the page cannot be retrieved, mark the claim unsupported instead of treating a search description as evidence.
Crawler rules matter upstream.
Cloudflare requires the participating search providers to use crawlers that meet its verified-bot rules and to return a source link with each result. Its verified-bot policy requires deterministic identification, respect for robots.txt and crawl directives, reasonable request rates, and non-abusive behavior.[5]
That is a useful upstream commitment. It does not tell you whether a result is current, complete, independent, or suitable for the claim your agent wants to make. Provider conduct, result quality, and claim support need separate checks.