|
| 1 | +--- |
| 2 | +title: Configuration |
| 3 | +description: Create, update, and delete K2 streams, and configure their inputs, authentication, CORS, and retention. |
| 4 | +pcx_content_type: configuration |
| 5 | +products: |
| 6 | + - k2 |
| 7 | +sidebar: |
| 8 | + order: 5 |
| 9 | +--- |
| 10 | + |
| 11 | +import { Details } from "~/components"; |
| 12 | + |
| 13 | +K2 streams can be created, updated, and deleted with the REST API. |
| 14 | + |
| 15 | +To create, update, or delete streams, your API token needs the `K2 Config Write` permission. To get or list streams, it needs the `K2 Config Read` permission. |
| 16 | + |
| 17 | +{/* TODO: Add Dashboard and Wrangler instructions once they support K2 streams. */} |
| 18 | + |
| 19 | +## Stream settings |
| 20 | + |
| 21 | +| Setting | Type | Required | Default | Description | |
| 22 | +| ------------------- | ------- | -------- | ------------------- | ----------------------------------------------------------------------------------------------- | |
| 23 | +| `name` | string | Yes | None | 1 to 128 letters, numbers, or underscores. Must be unique in your account. Not case-sensitive. | |
| 24 | +| `retention_seconds` | integer | No | `604800` | How long K2 retains records, from `3600` (one hour) to `2592000` (30 days). | |
| 25 | +| `http` | object | Yes | None | Configures the HTTP input. Refer to [HTTP input](#http-input). | |
| 26 | +| `worker_binding` | object | No | `{ enabled: true }` | Configures the Workers binding input. Refer to [Workers binding input](#workers-binding-input). | |
| 27 | + |
| 28 | +At least one of `http` or `worker_binding` must be enabled. |
| 29 | + |
| 30 | +You cannot rename a stream after you create it. |
| 31 | + |
| 32 | +### Inputs |
| 33 | + |
| 34 | +An input is a way for producers to write records to a stream. K2 supports two inputs: |
| 35 | + |
| 36 | +- **HTTP:** Producers send records to the stream's `/produce` endpoint. |
| 37 | +- **Workers binding:** A Worker sends records through a binding. |
| 38 | + |
| 39 | +### HTTP input |
| 40 | + |
| 41 | +| Field | Type | Required | Description | |
| 42 | +| ---------------- | ---------------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------- | |
| 43 | +| `enabled` | boolean | Yes | Enables the `/produce` endpoint. | |
| 44 | +| `authentication` | boolean | No | Requires an API token with the `K2 Produce` permission to produce. If omitted or `false`, anyone with the stream endpoint can produce. | |
| 45 | +| `cors.origins` | array of strings | No | Origins allowed to produce from a browser. Refer to [CORS](#cors). | |
| 46 | + |
| 47 | +:::caution |
| 48 | +If you do not set `authentication` to `true`, the `/produce` endpoint is public. Anyone who knows the stream ID can write records to the stream. |
| 49 | +::: |
| 50 | + |
| 51 | +#### Authentication |
| 52 | + |
| 53 | +When `authentication` is `true`, producers using the HTTP API must send an API token in the |
| 54 | +`Authorization: Bearer <TOKEN>` header. The token must have permission to |
| 55 | +produce to K2 streams (`K2 Produce`) in the account that owns the stream. |
| 56 | + |
| 57 | +#### CORS |
| 58 | + |
| 59 | +Configure `cors.origins` to allow browsers to produce records from a web page. Each entry must be one of the following: |
| 60 | + |
| 61 | +- An `http://` or `https://` origin, such as `https://example.com`. Origins cannot include a path, query string, fragment, or credentials. |
| 62 | +- `*`, to allow any origin. If you use `*`, it must be the only entry. |
| 63 | + |
| 64 | +You can configure up to five origins. Each origin must be unique. |
| 65 | + |
| 66 | +### Workers binding input |
| 67 | + |
| 68 | +| Field | Type | Required | Description | |
| 69 | +| --------- | ------- | -------- | ------------------------------------------------------- | |
| 70 | +| `enabled` | boolean | Yes | Allows Workers to produce to the stream with a binding. | |
| 71 | + |
| 72 | +If you omit `worker_binding` when you create a stream, the Workers binding input is enabled. |
| 73 | + |
| 74 | +### Retention |
| 75 | + |
| 76 | +`retention_seconds` sets how long K2 retains records after it receives them. |
| 77 | +The value must be between `3600` (one hour) and `2592000` (30 days). The |
| 78 | +default is `604800` (seven days). |
| 79 | + |
| 80 | +K2 deletes expired records in the background. Records can remain readable for some time after their retention period ends, so do not rely on retention to remove data at an exact time. |
| 81 | + |
| 82 | +## Update a stream |
| 83 | + |
| 84 | +To change a stream's settings, send a `PATCH` request with the settings to change. You can update `retention_seconds`, `http`, and `worker_binding`. Include at least one of these fields. |
| 85 | + |
| 86 | +```sh |
| 87 | +curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/k2/streams/$STREAM_ID" \ |
| 88 | + --request PATCH \ |
| 89 | + --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \ |
| 90 | + --header "Content-Type: application/json" \ |
| 91 | + --data '{ |
| 92 | + "retention_seconds": 86400, |
| 93 | + "worker_binding": { "enabled": false } |
| 94 | + }' |
| 95 | +``` |
| 96 | + |
| 97 | +The response contains the updated stream: |
| 98 | + |
| 99 | +```json output |
| 100 | +{ |
| 101 | + "success": true, |
| 102 | + "errors": [], |
| 103 | + "messages": [], |
| 104 | + "result": { |
| 105 | + "id": "241fa65b438a4d539a19371f58bfdae0", |
| 106 | + "name": "orders", |
| 107 | + "retention_seconds": 86400, |
| 108 | + "endpoint": "https://241fa65b438a4d539a19371f58bfdae0.k2.cloudflarestorage.com", |
| 109 | + "http": { |
| 110 | + "enabled": true, |
| 111 | + "authentication": true |
| 112 | + }, |
| 113 | + "worker_binding": { |
| 114 | + "enabled": false |
| 115 | + }, |
| 116 | + "created_at": "2026-09-24T21:19:19.246Z", |
| 117 | + "modified_at": "2026-09-29T14:25:54.712Z" |
| 118 | + } |
| 119 | +} |
| 120 | +``` |
| 121 | + |
| 122 | +When you update an input, the new object replaces the existing one. For |
| 123 | +example, to add a CORS origin to the HTTP input, send the complete `http` |
| 124 | +object, including `enabled` and `authentication`. To disable an input, set it |
| 125 | +to `{ "enabled": false }`. You cannot disable both inputs. |
0 commit comments