Agent report card
Can an agent use Cloudflare Developer Platform through API resource management?
Grade D: Only part of the applicable terms is machine-readable.
Cloudflare / active
Five-stage assessment
Where agent autonomy holds and where it breaks
First break: Evaluate
Evaluate
LimitedOnly part of the applicable terms is machine-readable.
An ARD declaration has not been established.
An agent can discover the product and funnel from the tested public entrypoints.
Eligibility can be decided from explicit public criteria.
Pricing or the absence of a charge is explicit and machine-readable.
Evidence and actions
ARD declaration unknown
missing: unknownAn ARD declaration has not been established.
Decidable eligibility
supported: freshEligibility can be decided from explicit public criteria.
Eligibility criteria and subscription terms are explicitly defined and decidable in the Self-Serve Subscription Agreement.
Machine discovery
supported: freshAn agent can discover the product and funnel from the tested public entrypoints.
The product API endpoints and account resource management methods are machine-discoverable via public API documentation.
Readable pricing
supported: freshPricing or the absence of a charge is explicit and machine-readable.
Pricing plans and rates for compute, storage, and developer services are explicitly stated and machine-readable on the plans page.
Structured terms limited
supported: freshOnly part of the applicable terms is machine-readable.
The service terms are provided in stable HTML format but lack structured machine-readable formats such as JSON or Schema.org legal metadata.
What would improve this stage
- Publish complete applicable terms in a stable machine-readable document.
Sign up
BlockedThe signup flow could not be operated by an agent.
A CAPTCHA blocks autonomous signup.
Whether phone verification is required has not been established.
A stable signup entrypoint is available.
A scoped, revocable machine identity flow is documented, including explicit human authorization boundaries.
Evidence and actions
CAPTCHA-free signup unavailable
supported: freshA CAPTCHA blocks autonomous signup.
The dashboard sign-up path was unavailable during testing due to a temporary dashboard error page.
Machine-operable signup unavailable
supported: freshThe signup flow could not be operated by an agent.
The sign-up form could not be operated because the Cloudflare Dashboard page was temporarily unavailable.
Phone-free signup unknown
supported: freshWhether phone verification is required has not been established.
Phone verification requirements could not be established as the sign-up page was temporarily unavailable.
Stable signup entrypoint
supported: freshA stable signup entrypoint is available.
The sign-up URL is a stable HTTP entrypoint that responds with Cloudflare Dashboard metadata.
Supported identity flow
supported: freshA scoped, revocable machine identity flow is documented, including explicit human authorization boundaries.
Cloudflare documents API tokens supporting scoped, revocable permissions across Account, User, or Zone resources with explicit human authorization in the dashboard.
What blocks agents
- The signup flow could not be operated by an agent.
- A CAPTCHA blocks autonomous signup.
What would improve this stage
- Expose labelled, deterministic controls and documented validation without requiring hidden human interaction.
- Provide a documented agent-safe verification path that does not require solving a CAPTCHA.
Pay
BlockedThe required checkout cannot be operated by an agent.
A supported payment rail has not been established.
Whether sales intervention is required has not been established.
The required price or no-charge status is explicit before commitment.
Evidence and actions
Explicit price
supported: freshThe required price or no-charge status is explicit before commitment.
Cloudflare provides explicit, transparent pricing for its plans and individual compute, storage, and developer platform services prior to sign-up commitment.
Machine-operable checkout unavailable
supported: freshThe required checkout cannot be operated by an agent.
Machine-operable checkout was unavailable as the Cloudflare Dashboard sign-up page was temporarily unavailable during testing.
Sales-free purchase unknown
supported: freshWhether sales intervention is required has not been established.
Whether sales-free purchase can be completed could not be determined because the dashboard sign-up interface was unavailable.
Supported payment rail unknown
supported: freshA supported payment rail has not been established.
Supported payment rails could not be verified because the sign-up page returned a temporary error.
What blocks agents
- The required checkout cannot be operated by an agent.
What would improve this stage
- Expose documented, labelled checkout controls or an agent-compatible commerce interface.
Provision
LimitedOnly part of the provisioning lifecycle exposes machine-readable status.
Automatic activation has not been established.
A bounded provisioning delay has not been established.
Usable credentials or delegated access are delivered through a documented flow.
Evidence and actions
Automatic activation unknown
supported: freshAutomatic activation has not been established.
Automatic provisioning activation parameters or automated completion guarantees are not established in the provided API reference endpoint list.
Bounded provisioning delay unknown
supported: freshA bounded provisioning delay has not been established.
The API troubleshooting documentation does not document or define a bounded provisioning completion delay guarantee.
Credential delivery
supported: freshUsable credentials or delegated access are delivered through a documented flow.
Cloudflare provides a documented API token generation flow delivering secret API token credentials directly upon creation.
Machine-readable provisioning status limited
supported: freshOnly part of the provisioning lifecycle exposes machine-readable status.
Cloudflare API token verification endpoints return machine-readable JSON status indicating terminal status states like 'active'.
What would improve this stage
- Expose deterministic provisioning progress, terminal states, errors, cancellation, and reconciliation where applicable.
Operate
ReadyA documented API or tool interface is available for operation.
An agent protocol interface has not been established.
Authentication is documented and usable within an agent authorization boundary.
Limits, structured errors, retry behavior, and idempotency semantics are documented where applicable.
Credential rotation, revocation, retry, and recovery paths are documented within delegated authority.
Evidence and actions
Agent protocol interface unknown
missing: unknownAn agent protocol interface has not been established.
API or tool access
supported: freshA documented API or tool interface is available for operation.
Cloudflare provides a documented REST API with endpoints to list accounts and manage various platform resources.
Delegated recovery
supported: freshCredential rotation, revocation, retry, and recovery paths are documented within delegated authority.
Cloudflare documents API token management including creation, verification, rolling (rotation), restriction, and revocation.
Documented limits and errors
supported: freshLimits, structured errors, retry behavior, and idempotency semantics are documented where applicable.
Cloudflare documents API rate limits, troubleshooting token errors, and standard error response structures.
Usable authentication
supported: freshAuthentication is documented and usable within an agent authorization boundary.
Cloudflare supports API Tokens with Bearer authentication and granular permission scopes for agent access.
What works
- Operate: A documented API or tool interface is available for operation.
What blocks agents
- Evaluate: Only part of the applicable terms is machine-readable.
- Sign up: The signup flow could not be operated by an agent.
- Pay: The required checkout cannot be operated by an agent.
- Provision: Only part of the provisioning lifecycle exposes machine-readable status.
Improve the report
Correct it, rerun it, or improve the funnel
Every request carries the exact profile revision, projection, declaration, and Catalog release.
Method, policy, and immutable identifiers
Complete, fresh evidence for the core service lifecycle first applies hard stage severity, then grades the share of applicable evidenced signals that are constrained. Optional blocker probes affect the grade when established and remain visible as unknown when public evidence cannot establish them.
Any incomplete, contradictory, unsupported, or non-fresh required evidence produces an unrated profile. A failed Evaluate, Sign up, or Pay stage derives D; a failed Provision or Operate stage derives F; otherwise constrained-signal ratio derives A+ through C.
- Profile ID
- arp_01kzf0m4x62a9z5fqb4kvp1hme
- Revision
- sha256:42e8529be907412f63353afb87a6a0ad580798114eb369e8eb2634207cc75b80
- Projection
- sha256:d62df4a5ef19bc45c0e356522753d48386fd0b528dfd9746064a1851565ca518
- Policy
- service-lifecycle-2026-08-08-calibrated: sha256:334e56852b5c38e178fcea839cfba680fb82dd96693842d933776baed21d63df
- Base Catalog release
- sha256:5082ec07047a2324648f569d234cc64342ce2707b2f3d77fde8fc06af517cee6