For the complete documentation index, see llms.txt. This page is also available as Markdown.

cfInfo

Cloudflare runtime enrichment data for an API endpoint.

Examples

type CfInfo {
  runtimeStatus: String
  requestCount: Float
  lastSeen: String
  matchType: String
  wafBlockCount: Float
  wafBotBlockCount: Float
  wafTopAttackerIps: [String]
  wafTopCountries: [String]
  wafAttackSources: [String]
  wafLastAttackAt: String
  zone: String
  host: String
  allMatchedZones: [String]
}

Fields

Field
Description
Supported fields

runtimeStatus String

Cloudflare runtime status: ACTIVE, INACTIVE, ZOMBIE, SHADOW

requestCount Float

Number of requests observed via Cloudflare in the last scan window

lastSeen String

ISO timestamp of the last request observed via Cloudflare

matchType String

How the endpoint was matched against CF traffic: EXACT, NORMALIZED, or UNMATCHED

wafBlockCount Float

Total number of WAF block events in the last 72 hours

wafBotBlockCount Float

Number of WAF blocks attributed to bot management (source='bm') in the last 72 hours

wafTopAttackerIps [String]

Top attacker IPs by frequency (up to 5) from WAF events in the last 72 hours

wafTopCountries [String]

Top attacking countries by frequency (up to 3) from WAF events in the last 72 hours

wafAttackSources [String]

WAF rule sources that triggered blocks (e.g. firewallrules, bm, ratelimit)

wafLastAttackAt String

ISO timestamp of the most recent WAF block event

zone String

Cloudflare zone name where this endpoint was observed (e.g. "example.com")

host String

Host header from CF traffic where this endpoint was matched (e.g. "API.example.com")

allMatchedZones [String]

All Cloudflare zone names that observed this endpoint — first entry is the primary match zone

References

Fields with this object:

Last updated