Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk4 min

How to Query Cloudflare Data with SQL and Connect BI Tools

Cloudflare has separate SQL APIs for product analytics and Worker-written data. Learn how to query each and connect the documented Grafana integration.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare has two distinct SQL routes: the Analytics SQL API for Cloudflare analytics and observability datasets, and the Workers Analytics Engine SQL API for custom data written by Workers. Pick the route that matches your data, authenticate with an API token, and check the SQL limits before connecting a BI client. Cloudflare documents a Grafana integration for Workers Analytics Engine; that does not mean every BI tool has a supported native connector.

Choose the Cloudflare SQL endpoint that matches your data

Cloudflare describes its general SQL API as a way to “query Cloudflare analytics and observability datasets with SQL.” It covers available Cloudflare product and account or zone analytics datasets. Workers Analytics Engine is different: it stores custom datapoints written by your Worker and is queried through an account-specific endpoint.

Route What you query Endpoint Important distinction
Analytics SQL API Cloudflare analytics and observability datasets available to your account or zone https://api.cloudflare.com/client/v4/analytics/sql Requires an authorized account or zone scope, a schema-qualified dataset, and a lower time bound. The supported SQL surface is constrained.
Workers Analytics Engine SQL API Custom datasets populated by Workers https://api.cloudflare.com/client/v4/accounts/<account_id>/analytics_engine/sql Uses a separate endpoint and dataset model. Rows include a sample interval, which can affect aggregations.

These are not interchangeable database endpoints. Establish whether the records you need come from Cloudflare’s product analytics or from events your Worker explicitly writes, then use the corresponding API reference.

Run a query against the Analytics SQL API

Check access and dataset availability

Create an API token with the permissions required for the relevant analytics product and scope. Analytics read access alone may not grant access to every product dataset. Dataset and field availability can vary with plan and permissions. Consult Cloudflare’s SQL API overview and getting-started guide for current requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Send a JSON POST request

Cloudflare recommends JSON POST for this API. A request includes a SQL query and may include parameter values, scope, and time range. The query must select from one schema-qualified dataset. For example, the request shape is:

curl -X POST 'https://api.cloudflare.com/client/v4/analytics/sql' 
  -H 'Authorization: Bearer YOUR_API_TOKEN' 
  -H 'Content-Type: application/json' 
  --data '{
    "query": "SELECT ... FROM schema.dataset WHERE ...",
    "params": {},
    "scope": {"...": "..."},
    "time_range": {"start": "...", "end": "..."}
  }'

This is a request template, not a runnable query: replace the ellipses with a dataset, valid fields, and actual scope and time values from the relevant Cloudflare dataset. The request-level scope must specify exactly one account or zone tag. The time range requires a start and may include an end; bounds are inclusive. Cloudflare documents parameterized JSON requests in its query API reference.

  • Use params for values supplied at runtime rather than concatenating user-provided values into SQL text.
  • Set tenancy in either request-level scope or SQL predicates, not both.
  • Set the time constraint in either request-level time_range or a SQL time predicate, not both.
  • Use a lower time bound; do not assume an unbounded query is accepted.

Check the SQL before using a BI-generated query

The general Analytics SQL API is read-only and supports a documented subset, not arbitrary ClickHouse SQL. Common selection, filtering, grouping, ordering, and aggregation patterns are supported, but joins, unions, general subqueries, window functions, and data modification or definition statements are among the unsupported constructs. Review Cloudflare’s SQL language reference and test the exact query shape generated by your BI tool. A tool that emits unsupported SQL may need a simpler query or a different data-access approach.

Query data written to Workers Analytics Engine

Instrument and populate a dataset first

Workers Analytics Engine is for custom events and measurements written by a Worker, not a substitute endpoint for Cloudflare’s general analytics datasets. Define a dataset binding in the Worker configuration and write datapoints consistently; Cloudflare creates the dataset when data is first written. See the Workers Analytics Engine SQL API documentation for the endpoint and query details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Account for sampling in calculations

Analytics Engine rows include a timestamp and _sample_interval. When sampling is in effect, a row can represent multiple events. Cloudflare’s examples adjust count and average calculations using that interval. Do not interpret a plain row count or average as an event-level statistic without applying the documented sampling treatment. The exact calculation depends on the metric and query; follow the examples and schema guidance in Cloudflare’s SQL API documentation.

Connect Grafana to Workers Analytics Engine

Cloudflare’s documented Grafana route uses the Altinity ClickHouse plugin to query Workers Analytics Engine. Configure the plugin with the account-specific endpoint and a custom bearer-token header. The documented integration is specific to this service and plugin; the available official guidance does not establish equivalent native setup recipes for every BI tool.

  1. Install or enable the Altinity ClickHouse data source plugin in Grafana.
  2. Set the connection URL to https://api.cloudflare.com/client/v4/accounts/<account_id>/analytics_engine/sql, replacing <account_id> with your Cloudflare account ID.
  3. Configure the custom HTTP header Authorization with value Bearer YOUR_API_TOKEN. Keep the token secret and restrict its permissions appropriately.
  4. Use the plugin to issue a query against the Analytics Engine dataset and verify the results against its schema, including sampling behavior.

Use Cloudflare’s Grafana integration guide for the current plugin settings and prerequisites.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use the CLI for developer workflows, not as a BI connector

Cloudflare’s CLI offers cf sql query for running SQL queries and cf sql datasets for listing datasets. This can help developers inspect available data and validate a query before adapting it for a dashboard. It is a command-line workflow, not a BI connector.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before relying on a dashboard

  • Confirm whether the data belongs to the general Analytics SQL API or a Worker-written Analytics Engine dataset.
  • Verify the token’s product permissions, account or zone scope, and the dataset and fields available to that identity.
  • For the general API, ensure the query has one schema-qualified dataset and an applicable lower time bound, and keep request-level scope and time range from duplicating SQL predicates.
  • Check generated SQL against the relevant service’s supported query surface; do not assume a BI tool’s generic ClickHouse mode guarantees compatibility.
  • For Analytics Engine, validate whether sampling applies and use sampling-aware calculations.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.