--- title: "Cloudflare Built a CLI for Coding Agents. The Safety Feature Is Dry Run." description: "The new cf CLI gives agents more than 2,900 commands, machine-readable output, and request previews. Broad access still needs narrow credentials." date: "2026-10-01" tags: ["Cloudflare", "Developer Tools", "Coding Agents", "CLI", "DevOps"] canonical: "https://news.maestromojo.com/news/cloudflare-cf-cli-coding-agents-dry-run/" --- **Maestro’s take.** Cloudflare’s new `cf` CLI is a useful blueprint for tools built for coding agents. The clever part is not thousands of commands. It is letting an agent find, inspect, and preview many commands before it changes anything. [Cloudflare released `cf` in open beta on September 28](https://blog.cloudflare.com/cloudflare-cf-cli-launch/). It is a new command-line interface for Cloudflare’s API. Cloudflare says it exposes more than 2,900 commands, compared with roughly 280 operations in Wrangler. That sounds like a bigger toolbox. For an AI agent, the more important change is predictability. According to [Cloudflare’s agent documentation](https://developers.cloudflare.com/cf/agents/), `cf` returns JSON by default, separates machine output from human messages, lets the agent search commands locally, exposes schemas for generated API commands, and can preview many API requests with `--dry-run`. ## TL;DR - `cf` gives an agent broad access to Cloudflare’s API from one CLI. - It is easier for an agent to discover the right command and read the result without scraping human-formatted text. - Cloudflare says agents accounted for 48% of Wrangler usage in the week before launch. That is Cloudflare telemetry, not an independent market-share measure. - `--dry-run` can show many generated API requests before they are sent. It is not available for every command, and it does not make an overpowered API token safe. - `cf` is in open beta. Do not blindly replace Wrangler in an existing production project. - Cloudflare has not published an independent reliability or token-savings benchmark for this workflow. ## What changed Wrangler was designed around Cloudflare developer workflows: build a Worker, run it locally, deploy it, and manage common resources. `cf` is broader. It maps Cloudflare’s public API into a large command tree. An agent can search that tree, inspect the expected input for generated API commands, run a command, and parse structured output. In plain English, the agent has fewer reasons to guess. A developer can ask an agent to create a D1 database in an isolated test account. The agent can first discover the command: ```bash cf cli search "create D1 database" ``` Then inspect the generated API command’s input and output shape: ```bash cf schema d1 create ``` Then check the command’s help and, when supported, preview the actual API request: ```bash cf d1 create --help cf d1 create --name my-database --dry-run ``` Only after the preview matches the request should the real command run. If the command has no dry-run option, keep it approval-gated or test it only in the isolated account. ## Do this - Start in an isolated test account that has no production resources. - Give the agent a least-privilege token restricted to the required account, zone, and permissions. Do not reuse a full-account administrator token. - Make command search and `--help` part of the agent’s written workflow. Use schema inspection for generated API commands and dry run where the command supports it. - Require the agent to show the proposed request and affected resource before destructive, billable, or deployment actions. - Verify the resulting resource after the command runs. A successful process exit is not enough. - Keep deploys, deletions, domain changes, billing changes, and production secrets behind explicit approval. ## Do not do this - Do not install `cf`, hand it a broad token, and say, “Clean up our Cloudflare account.” - Do not treat a project directory, named CLI profile, or JSON output as a security boundary. The token’s permissions determine what the agent can reach. - Do not trust exit code zero as proof that a destructive command happened. [Cloudflare’s agent documentation](https://developers.cloudflare.com/cf/agents/) says a noninteractive destructive command without `--force` can print “Aborted.” and still exit successfully. - Do not run `cf dev`, `cf build`, or `cf deploy` in an existing Wrangler project before migrating it. [Cloudflare warns](https://developers.cloudflare.com/cf/wrangler/migrate/) that the command may ignore the Wrangler configuration or fail. - Do not assume every Wrangler command is available. Cloudflare lists gaps, including `wrangler tail` and `wrangler secret put`. ## A safer agent instruction Do not say: > Set up Cloudflare for this app and deploy it. Say: > Use the `cf` CLI only in the isolated test account and only with the least-privilege token already provided. Search for the needed command and read `--help`. For generated API commands, inspect the schema. When supported, run `--dry-run` first. Show me the proposed request and explain every resource it will create, change, or delete. Do not deploy, delete, change DNS, reveal or rotate secrets, enable paid services, or use `--force` without my approval. After an approved command, query the resource again and return the resulting JSON as evidence. That instruction separates discovery, preview, approval, action, and verification. ## Why Maestro users care An agent can waste time and tokens when it has to search web documentation, guess flags, parse decorative terminal text, and retry errors. A discoverable CLI with schemas and structured output should reduce some of that friction. That is a design inference, not a measured result. Cloudflare has published its own usage telemetry and product behavior, but no independent reliability or token-savings benchmark for `cf` is cited here. The tool also gives one process a large surface area. The cost of a wrong instruction can grow from a failed command to changed infrastructure. The useful pattern is simple: give the agent a tool it can understand, a credential with limited reach, and a required preview when the command supports one. ## Should you replace Wrangler? Not yet by default. Use Wrangler for a production project that already depends on it. Try `cf` in an isolated test account when an agent needs API coverage beyond Wrangler. If you choose to migrate, commit or stash your work first. Run Cloudflare’s migration dry run, inspect the generated configuration and any `TODO` comments, then test the project before changing production workflows. Cloudflare says Wrangler will receive maintenance support for 18 months after `cf` leaves beta. The clock has not started while `cf` remains in open beta. ## One thing to try Give a coding agent access to an isolated test account and one harmless job: list that account’s D1 databases with `cf`. Require it to find the command with `cf cli search`, read `--help`, run the command, and return the JSON result. If it cannot explain each step, do not expand its permissions. ## The bottom line Cloudflare did not make infrastructure safe for autonomous agents. It made its command line easier for agents to understand. That matters. The winning workflow is still not “let the agent run everything.” It is “let the agent discover and preview where possible, then prove what happened.” ## Sources considered - [Cloudflare: Agents are writing nearly half our code. So we built them a CLI.](https://blog.cloudflare.com/cloudflare-cf-cli-launch/) - [Cloudflare documentation: Build with Agents](https://developers.cloudflare.com/cf/agents/) - [Cloudflare documentation: Migrate from Wrangler](https://developers.cloudflare.com/cf/wrangler/migrate/) - [Cloudflare documentation: Command reference](https://developers.cloudflare.com/cf/wrangler/reference/) *Published October 1, 2026 · Tags: Cloudflare, Developer Tools, Coding Agents, CLI, DevOps*