English | 日本語
A command-line tool for Cloudflare Web Analytics. Query page views, visitors, referrers, and more from your terminal.
- Summary dashboard — Total PV/visits with top pages, referrers, and countries
- Dimension queries — Pages, referrers, countries, devices, browsers
- Timeseries — Daily PV/visits over a date range
- Multi-site support — Manage multiple sites with
--site-tag - Flexible output — Human-readable tables, JSON (
--json), or TSV (--plain) - Path filtering — Filter analytics by URL path pattern
- Pages operations — Inspect projects/deployments and publish static builds
- DNS operations — List records, dry-run changes, and safely upsert exact matches
npm install -g cloudflare-analytics-cliSet your Cloudflare credentials as environment variables:
export CLOUDFLARE_API_TOKEN="your-api-token"
export CLOUDFLARE_ACCOUNT_ID="your-account-id"
export CFA_SITE_TAG="your-default-site-tag" # optionalYour API token needs Account Analytics: Read permission. DNS operations additionally require Zone: Read / DNS: Edit.
# Summary for today
cfa summary
# Summary for a date range
cfa summary --from 2026-03-01 --to 2026-03-22
# Top pages
cfa pages --from 2026-03-01 --to 2026-03-22 --limit 20
# Top referrers
cfa referrers --from 2026-03-01 --to 2026-03-22
# Country breakdown
cfa countries --from 2026-03-01 --to 2026-03-22
# Device types
cfa devices --from 2026-03-01 --to 2026-03-22
# Browser breakdown
cfa browsers --from 2026-03-01 --to 2026-03-22
# Daily timeseries
cfa timeseries --from 2026-03-01 --to 2026-03-22
# Filter by path
cfa pages --filter "/lp/*" --from 2026-03-01 --to 2026-03-22
# List registered sites
cfa sites
# Test authentication
cfa auth test
# Refresh and use the local Wrangler OAuth session
cfa auth wrangler-refresh
cfa auth test --wrangler-auth
# Explicitly use a Global API Key for another account
cfa auth test --global-api-key --email [email protected]
# List Cloudflare Pages projects and recent deployments
cfa deployments projects
cfa deployments list --project my-project
# Deploy a static build to the production branch
cfa deployments deploy --project my-project --directory dist --branch master
# Store a Pages secret from stdin, then list encrypted secret names
printf '%s' "$SECRET_VALUE" | cfa deployments secret-put \
--project my-project --key API_TOKEN --environment production
cfa deployments secret-list --project my-project --environment production
# Show or set Functions fail open / closed (set applies to production and preview together)
cfa deployments fail-open --project my-project --wrangler-auth --expect closed # exit 2 unless production and preview are both closed
cfa deployments fail-open --project my-project --wrangler-auth --set closed
# List DNS records
cfa dns list --zone example.com --type TXT
cfa dns list --zone example.com --type TXT --wrangler-auth
cfa dns list --zone example.com --type TXT --global-api-key --email [email protected]
# Preview a DNS change, then apply it
cfa --json dns upsert --zone example.com --type TXT --name example.com \
--content 'v=spf1 include:_spf.google.com ~all' --match-content-prefix 'v=spf1' --ttl 1 --dry-run
cfa --json dns upsert --zone example.com --type TXT --name example.com \
--content 'v=spf1 include:_spf.google.com ~all' --match-content-prefix 'v=spf1' --ttl 1
# JSON output (for scripting)
cfa --json summary --from 2026-03-01 --to 2026-03-22
# TSV output (for piping)
cfa --plain pages --from 2026-03-01 --to 2026-03-22 | head -5Updating an existing TXT record requires --match-content-prefix. This preserves unrelated same-name records such as domain-verification TXT values.
--wrangler-auth calls the official wrangler auth token --json command internally, supporting both plaintext credentials and the OS keyring without printing the OAuth token. Wrangler refreshes expired tokens automatically. API-token and API-key environment variables are removed from the child process so the stored OAuth session is selected explicitly. DNS and authentication checks do not require CLOUDFLARE_ACCOUNT_ID.
--global-api-key --email <address> sends CLOUDFLARE_API_KEY as X-Auth-Key. It cannot be combined with Bearer/OAuth selection, and the secret is never printed.
| Option | Description |
|---|---|
--json |
Output in JSON format |
--plain |
Output in TSV format (for piping) |
--site-tag <tag> |
Specify site tag (overrides CFA_SITE_TAG) |
--from <YYYY-MM-DD> |
Start date (default: today) |
--to <YYYY-MM-DD> |
End date (default: today) |
--limit <N> |
Number of results (default: 10) |
--filter <path> |
Path filter pattern (e.g. /lp/*) |
| Variable | Required | Description |
|---|---|---|
CLOUDFLARE_API_TOKEN |
Conditional | Cloudflare API Token; omit when using --wrangler-auth |
CLOUDFLARE_API_KEY |
Conditional | Global API Key used only with --global-api-key |
CLOUDFLARE_ACCOUNT_ID |
Conditional | Required for account analytics and Pages operations; not for DNS/auth checks |
CFA_SITE_TAG |
No | Default site tag |
import { CfaClient, loadConfig } from "cloudflare-analytics-cli";
const config = loadConfig();
const client = new CfaClient(config);
const summary = await client.getSummary({
siteTag: "your-site-tag",
dateRange: { from: "2026-03-01", to: "2026-03-22" },
});
console.log(`Total PV: ${summary.pageviews}`);git clone https://github.com/tackeyy/cloudflare-analytics-cli.git
cd cloudflare-analytics-cli
npm install --ignore-scripts
npm run build
npm testMIT