Skip to content
Start here

Get latest annotations

GET/radar/annotations

Retrieves the latest annotations.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Accepted Permissions (at least one required)
User Details WriteUser Details Read
Query ParametersExpand Collapse
asn: optional number

Filters results by Autonomous System. Specify a single Autonomous System Number (ASN) as integer.

bot: optional string

Filters results by bot.

maxLength100
ca: optional string

Filters results by certificate authority.

maxLength100
dataSource: optional "ALL" or "AI_BOTS" or "AI_GATEWAY" or 22 more

Filters results by data source.

One of the following:
"ALL"
"AI_BOTS"
"AI_GATEWAY"
"BGP"
"BOTS"
"CONNECTION_ANOMALY"
"CT"
"DNS"
"DNS_MAGNITUDE"
"DNS_AS112"
"DOS"
"EMAIL_ROUTING"
"EMAIL_SECURITY"
"FW"
"FW_PG"
"HTTP"
"HTTP_CONTROL"
"HTTP_CRAWLER_REFERER"
"HTTP_ORIGINS"
"IQI"
"LEAKED_CREDENTIALS"
"NET"
"ROBOTS_TXT"
"SPEED"
"WORKERS_AI"
dateEnd: optional string

End of the date range (inclusive). Alternative to dateRange; provide together with dateStart.

formatdate-time
dateRange: optional string

Filters results by a relative date range ending at the current time. Use <n>d for days (up to 364d) or <n>w for weeks (up to 52w), e.g. 7d. Append control to request the equivalent previous period for comparison: the comparison window is shifted back by the current window’s length rounded up to a whole number of weeks, so it keeps the same weekday alignment and does not overlap the current window (e.g. 3dcontrol covers days -10 to -7, 7dcontrol covers days -14 to -7, 28dcontrol covers days -56 to -28, and 10dcontrol covers days -24 to -14). Mutually exclusive with dateStart/dateEnd.

dateStart: optional string

Start of the date range (inclusive). Alternative to dateRange; provide together with dateEnd.

formatdate-time
eventType: optional "EVENT" or "GENERAL" or "OUTAGE" or 3 more

Filters results by event type. EVENT is a legacy alias for GENERAL.

One of the following:
"EVENT"
"GENERAL"
"OUTAGE"
"PARTIAL_PROJECTION"
"PIPELINE"
"TRAFFIC_ANOMALY"
format: optional "JSON" or "CSV"

Format in which results will be returned.

One of the following:
"JSON"
"CSV"
geoId: optional string

Filters results by geolocation. Refer to GeoNames.

maxLength100
limit: optional number

Limits the number of objects returned in the response.

exclusiveMinimum
minimum0
location: optional string

Filters results by location. Specify an alpha-2 location code.

maxLength2
minLength2
log: optional string

Filters results by certificate log.

maxLength100
offset: optional number

Skips the specified number of objects before fetching the results.

minimum0
origin: optional string

Filters results by origin.

maxLength100
outageCause: optional "BLOCKING" or "CABLE_CUT" or "CYBERATTACK" or 14 more

Filters results by outage cause.

One of the following:
"BLOCKING"
"CABLE_CUT"
"CYBERATTACK"
"DNS"
"FIRE"
"GOVERNMENT_DIRECTED"
"MAINTENANCE"
"MECHANICAL"
"MILITARY_ACTION"
"MISCONFIGURATION"
"NATURAL_DISASTER"
"NETWORK_PROBLEM"
"POWER_OUTAGE"
"SOFTWARE"
"TECHNICAL_PROBLEM"
"UNKNOWN"
"WEATHER"
outageType: optional "NATIONWIDE" or "REGIONAL" or "NETWORK" or "PLATFORM"

Filters results by outage type.

One of the following:
"NATIONWIDE"
"REGIONAL"
"NETWORK"
"PLATFORM"
query: optional string

Filters results by a free-text match on the annotation description, id, or linked entities (location, ASN, origin).

maxLength100
tags: optional array of "ADM1" or "ADM2" or "API_TRAFFIC" or 93 more

Filters results by annotation tag. Matches annotations carrying at least one of the given tags.

One of the following:
"ADM1"
"ADM2"
"API_TRAFFIC"
"ARC"
"AS"
"ASN"
"ATTACKS"
"AUTHOR"
"BANDWIDTH"
"BITRATE"
"BOT"
"BOT_CATEGORY"
"BOT_CLASS"
"BOT_KIND"
"BOT_OPERATOR"
"BROWSER"
"BROWSER_FAMILY"
"BYTES"
"CA"
"CACHE_HIT"
"CA_OWNER"
"CHECK_RESULT"
"CLIENT_TYPE"
"COMPROMISED"
"CONTENT_TYPE"
"CRAWL_PURPOSE"
"CRAWL_REFER_RATIO"
"DEVICE_TYPE"
"DKIM"
"DMARC"
"DNS"
"DNSSEC"
"DNSSEC_AWARE"
"DNSSEC_E2E"
"DOMAIN_CATEGORY"
"DURATION"
"EDNS"
"ENCRYPTED"
"ENTRY_TYPE"
"EXPIRATION_STATUS"
"HAS_IPS"
"HAS_MATCHING_ANSWER"
"HAS_WILDCARDS"
"HTTP_METHOD"
"HTTP_PROTOCOL"
"HTTP_VERSION"
"INDUSTRY"
"IP_VERSION"
"JITTER"
"KEY_AGREEMENT"
"LATENCY"
"LOCATION"
"LOCATION_LATENCY"
"LOG"
"LOG_API"
"LOG_OPERATOR"
"MALICIOUS"
"MANAGED_RULES"
"MITIGATION_PRODUCT"
"MODEL"
"NAMESERVER_LATENCY"
"ORIGIN"
"ORIGIN_AS"
"ORIGIN_LOCATION"
"ORIGIN_TARGET_LOCATION_PAIR"
"OS"
"PERCENTILE"
"POST_QUANTUM"
"PREFIX"
"PRODUCT"
"PROTOCOL"
"PROVIDER"
"PUBLIC_KEY_ALGORITHM"
"QUERY_TYPE"
"REFERER"
"REGION"
"RESPONSE_CODE"
"RESPONSE_STATUS"
"RESPONSE_STATUS_CATEGORY"
"RESPONSE_TTL"
"SIGNATURE_ALGORITHM"
"SPAM"
"SPF"
"SPOOF"
"SUCCESS_RATE"
"TARGET_LOCATION"
"TASK"
"THREAT_CATEGORY"
"TLD"
"TLD_DNS_MAGNITUDE"
"TLS_VERSION"
"UPDATE_TYPE"
"USER_AGENT"
"VALIDATION_LEVEL"
"VECTOR"
"VERTICAL"
tld: optional string

Filters results by top-level domain.

maxLength63
minLength2
ReturnsExpand Collapse
result: object { annotations }
annotations: array of object { id, asns, asnsDetails, 15 more }
id: string
asns: array of number
asnsDetails: array of object { asn, location, name }
asn: string
location: object { code, name }
code: string
name: string
name: string
dataSource: string
description: string
endDate: string
entities: array of object { entityName, entityType, entityValue }
entityName: string
entityType: string
entityValue: string
eventType: string
geoIds: array of string
linkedUrl: string
locations: array of string
locationsDetails: array of object { code, name }
code: string
name: string
origins: array of string
originsDetails: array of object { name, origin }
name: string
origin: string
outage: object { outageCause, outageType }
outageCause: string
outageType: string
scope: string
startDate: string
tags: array of string
success: boolean

Get latest annotations

curl https://api.cloudflare.com/client/v4/radar/annotations \
    -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
{
  "result": {
    "annotations": [
      {
        "id": "550",
        "asns": [
          189
        ],
        "asnsDetails": [
          {
            "asn": "189",
            "location": {
              "code": "US",
              "name": "United States"
            },
            "name": "LUMEN-LEGACY-L3-PARTITION"
          }
        ],
        "dataSource": "ALL",
        "description": "example",
        "endDate": "2022-09-08T10:00:28Z",
        "entities": [
          {
            "entityName": "GPTBot",
            "entityType": "BOT",
            "entityValue": "gptbot"
          }
        ],
        "eventType": "OUTAGE",
        "geoIds": [
          "2267057"
        ],
        "linkedUrl": "http://example.com",
        "locations": [
          "US"
        ],
        "locationsDetails": [
          {
            "code": "US",
            "name": "United States"
          }
        ],
        "origins": [
          "amazon-us-east-1"
        ],
        "originsDetails": [
          {
            "name": "us-east-1 Amazon Web Services",
            "origin": "amazon-us-east-1"
          }
        ],
        "outage": {
          "outageCause": "CABLE_CUT",
          "outageType": "NATIONWIDE"
        },
        "scope": "Colima, Michoacán, México",
        "startDate": "2022-09-06T10:00:28Z",
        "tags": [
          "string"
        ]
      }
    ]
  },
  "success": true
}
Returns Examples
{
  "result": {
    "annotations": [
      {
        "id": "550",
        "asns": [
          189
        ],
        "asnsDetails": [
          {
            "asn": "189",
            "location": {
              "code": "US",
              "name": "United States"
            },
            "name": "LUMEN-LEGACY-L3-PARTITION"
          }
        ],
        "dataSource": "ALL",
        "description": "example",
        "endDate": "2022-09-08T10:00:28Z",
        "entities": [
          {
            "entityName": "GPTBot",
            "entityType": "BOT",
            "entityValue": "gptbot"
          }
        ],
        "eventType": "OUTAGE",
        "geoIds": [
          "2267057"
        ],
        "linkedUrl": "http://example.com",
        "locations": [
          "US"
        ],
        "locationsDetails": [
          {
            "code": "US",
            "name": "United States"
          }
        ],
        "origins": [
          "amazon-us-east-1"
        ],
        "originsDetails": [
          {
            "name": "us-east-1 Amazon Web Services",
            "origin": "amazon-us-east-1"
          }
        ],
        "outage": {
          "outageCause": "CABLE_CUT",
          "outageType": "NATIONWIDE"
        },
        "scope": "Colima, Michoacán, México",
        "startDate": "2022-09-06T10:00:28Z",
        "tags": [
          "string"
        ]
      }
    ]
  },
  "success": true
}