Repository navigation
Cloudflare CLI
cf is Cloudflare's successor to Wrangler. It covers the whole Cloudflare API (about 2,900 commands, compared with about 280 in Wrangler) and replaces wrangler.jsonc with a typed cloudflare.config.ts. This page covers what applies across images: which ones can run it, when a project should switch, and how credentials work in a container. Setup inside claude-code is in its README.
cf needs Node.js 22.18 or later, and it doesn't support Bun: when cf runs on Bun, every command that loads cloudflare.config.ts fails.
| Image | cf |
|---|---|
claude-code, claude-code-sandbox
|
Preinstalled, pinned and bumped by Renovate, telemetry off, zsh completion set up |
hugo-bun-node |
Not preinstalled. Node 24 is there, so npm install -g cf works. See the README
|
ralphex-fe |
Not preinstalled. Node 24 is there |
bun, hugo-bun, claude-bun
|
Can't run it: no Node |
| The project has | Use |
|---|---|
cloudflare.config.ts |
cf |
wrangler.jsonc, wrangler.json or wrangler.toml, and no cloudflare.config.ts
|
Wrangler, until the project is migrated |
| Neither (account work: DNS, zones, D1, R2…) | cf |
Don't run
cf dev,cf buildorcf deployin a project that is still on Wrangler. They generate a new configuration that ignoreswrangler.jsonc. Without a terminal, which is how agents and CI run, they rewritepackage.json, the lockfile,.gitignoreandvite.config.tswithout asking. Migrate first.
The two tools share nothing:
| Wrangler | cf |
|
|---|---|---|
| Project config |
wrangler.jsonc / .toml
|
cloudflare.config.ts |
| Environments |
env blocks, --env
|
modes, --mode
|
| Login | wrangler login |
cf auth login, which doesn't reuse a Wrangler login |
| Resources | Accepts names | Expects IDs, e.g. cf d1 query <DATABASE_ID>
|
| Output | Tables | JSON on stdout, messages on stderr |
Neither tool reads the other's config. A migrated project that still needs a Wrangler-only command keeps both files.
-
Wrangler isn't deprecated yet. When the
cfbeta ends, Cloudflare will ship a final Wrangler major that points tocf, then maintain Wrangler for 18 more months. No end date for the beta had been announced as of the date below. -
Some tasks still need Wrangler: live logs (
wrangler tail) and setting a single secret. -
cf migrateleaves manual work: Durable Object migrations, Workflows, Containers and package scripts, each marked with aTODO(@cloudflare)comment. The build fails until they're resolved. -
Some Workers still build with Wrangler under the hood: JavaScript Workers built with esbuild, plus Rust and Python Workers.
cfhands their dev and deploy to Wrangler.
The steps are in the claude-code README: Recommended: migrate Workers projects to cloudflare.config.ts. In short: cf migrate --dry-run, then cf migrate, then resolve the TODOs. Migration also adds cf as a dev dependency, and from then on the global cf runs the project's copy.
cf uses the first credential it finds:
-
CLOUDFLARE_API_TOKENin the environment, or in a.envfile in the current directory - a profile chosen with
--profile - a profile bound to the directory with
cf auth activate - the default profile from
cf auth login
Things that catch people out:
-
A project
.envbeats your login. If the project's.envsetsCLOUDFLARE_API_TOKEN,cfuses that token instead of your login, without saying so. It reads only.env, not.env.localor.env.<mode>. -
Sign-in inside a container needs
--no-browser.cf auth login --no-browserprints a link and a code to approve in your host browser. -
The login lives in
~/.config/cloudflare. Without a volume there, a rebuild signs you out. Theclaude-codetemplates mount one. -
Use a scoped token for agents and CI. Create an API token limited to what the job needs, and set it with
CLOUDFLARE_ACCOUNT_ID. This matters most inclaude-code-sandbox, which shares the default variant's login and where Claude Code may run with permission prompts skipped. -
Firewalled containers need two domains:
dash.cloudflare.comfor sign-in (OAuth device flow) andapi.cloudflare.comfor everything else. Nothing else is required while telemetry is off.
In claude-code, managed settings give every Claude Code session the per-project rule above. They also make it ask before any cf command with --force or -f. Without a terminal, cf aborts deletes unless they carry that flag, so this is the one prompt that guards destructive Cloudflare calls. Details are in the README.
Cloudflare's cloudflare plugin stays alongside cf. Its wrangler skill applies the same rule when it loads, and its MCP server searches current Cloudflare docs, which cf doesn't do.
To find a command, run cf cli search "<task>". It runs locally and needs no credentials. Add --dry-run to see a request without sending it.
-
#204:
cfinclaude-code, the managedclaudeMdrule andaskrule, the~/.config/cloudflarevolume, firewall domains, zsh completion. The sign-in hosts and firewall behavior were tested in that PR. - Introducing cf: open beta from 2026-09-28, and Wrangler's 18 months of maintenance after the beta
- Cloudflare docs: Get started (requirements, credential order,
.env), cf for Wrangler users, Use cf with coding agents, Use cf in CI
Last verified: 2026-10-08, against cf 1.0.0-beta.13