The API, MCP and CLI can now act, and recommendations come with ready-to-paste rules
New read-and-write API keys let scripts and AI agents acknowledge alerts, add site events, suppress bots, resolve recommendations, manage segments and start crawls — every action recorded on the timeline — and each recommendation can be turned into the exact Cloudflare, CloudFront, nginx, Apache, Netlify, Vercel or robots.txt rule for your platform.
Keys with scopes. API keys are now read only by default. Create a read & write key under Organization → API Access when you want a script or an AI agent to take action. Every write is recorded as a site event on the timeline, naming the key, and writes have their own hourly limit.
What a read & write key can do, on the public API, the MCP server and the CLI: acknowledge an alert, add or delete a site event, suppress a bot from SEO error alerts (with an optional expiry, and an undo), resolve or re-open a recommendation, create, update or delete a segment, and start or cancel a crawl.
Deploy snippets. On the Recommendations page each list now has a Deploy panel that turns it into the exact rule for your platform — Cloudflare WAF expression, CloudFront Function, nginx or Apache block, Netlify or Vercel config, or a robots.txt fragment — with the caveats spelled out. Nothing is applied automatically; you review and paste.