Cloudflare · all settings
/api/v1/domains/{id}/operationsOperates on your account only. Send your API key in the Authorization header. Responses use JSON.
Request
Set BASE_URL to this website’s HTTPS origin and API_KEY to your private key. Replace RESOURCE_ID with the ID returned by the API.
curl --request POST "${BASE_URL}/api/v1/domains/RESOURCE_ID/operations" \
--header "Authorization: Bearer $API_KEY" \
--header "Content-Type: application/json" \
--header "Idempotency-Key: YOUR_UNIQUE_ACTION_UUID" \
--data '{"kind": "cloudflare.setting", "payload": {"setting": "always_use_https", "value": "on"}}'Headers & parameters
AuthorizationrequiredBearer YOUR_API_KEY
idpath · stringrequiredNumeric domain ID; UUID for an order, operation or request.
Idempotency-Keyheader · stringrequiredUnique action identifier. Reuse the same value and JSON on retries.
JSON body
cloudflare.setting
kindstringrequiredAction type; choose the appropriate variant below.
const: "cloudflare.setting"
payloadobjectrequiredParameters for the selected action.
payload.settingstringrequiredSetting name from cloudflare.available_settings on the domain.
payload.valueobjectrequiredAllowed value for the selected setting from available_settings.
payload.countriesarrayGEO only: ISO 3166-1 alpha-2 country codes, e.g. ["US", "DE"]. Omit to reuse the domain’s saved list.
maxItems: 249
Cloudflare: setup and status
Connect requires Prime for a new connection. Existing connections remain editable after Prime expires. Connection creates the zone, sets up DNS and HTTPS, and changes nameservers. Use a public server IP you control; omit ip if you do not want an initial A record. Certificate issuance and delegation are asynchronous.
Poll GET /operations/{id} for completion. Read GET /domains/{id}: cloudflare.status is the zone state, ssl_status is the visitor certificate, origin_tls_status is origin HTTPS, and checked_at is the last verification. An accepted request is not proof that SSL is active.
Setting names and values
Send one setting/value pair per operation. First inspect cloudflare.available_settings on your domain: availability depends on delegation and service configuration. Use JSON booleans for protection switches, not strings. For GEO send setting=geo, value=true and countries=["US","DE"]. Each domain has its own country list. value=false disables blocking; countries=[] clears the selection. Omitting countries reuses the saved selection.
ssl["strict", "full", "flexible", "off"]
tls_1_3["on", "off"]
cache_level["basic", "simplified", "aggressive"]
browser_cache_ttl[0, 1800, 3600, 7200, 14400, 28800, 43200, 86400, 604800]
under_attack[false, true]
development_mode["off", "on"]
always_online["off", "on"]
fight_mode[false, true]
always_use_https["on", "off"]
geo[false, true]
ssl: SSL mode; tls_1_3: TLS 1.3; always_use_https: HTTPS redirects; under_attack: Under Attack; fight_mode: bot protection; geo: country blocking; cache_level and browser_cache_ttl: cache behavior; development_mode: development mode; always_online: Always Online.
Response
request_idstringrequiredIdentifier used to recover an outcome after a network failure.
idstringrequireddomain_idintegerkindstringAction type; choose the appropriate variant below.
statusstringrequiredCurrent state. An accepted job does not mean completion.
created_atstring | nullneeds_reviewbooleanrequiredAn uncertain outcome requires reconciliation, not a repeated operation.
messagestring | nullResponse structure example · illustrative values
{
"request_id": "00000000-0000-4000-8000-000000000001",
"id": "00000000-0000-4000-8000-000000000001",
"domain_id": 1,
"kind": "string",
"status": "string",
"created_at": "2026-10-02T12:00:00Z",
"needs_review": false,
"message": "string"
}Errors & statuses
error.code · error.message · request_id
401Invalid or revoked key.
404Resource not found in your account.
409Idempotency conflict or request in progress.
422Invalid parameters or business rule, including balance.
500Outcome may be uncertain. Poll the request.
503Temporarily unavailable. Respect Retry-After.