Free agency tools / Cloudflare Rules Tester

See which Cloudflare rule fires — and why

Paste your Cloudflare firewall, WAF or custom rule expressions, describe a request, and this tool evaluates each rule top to bottom — showing the first rule that matches and highlighting exactly which part of the expression fired. Everything runs in your browser; nothing is uploaded.

Rules

One rule per block, separated by a blank line. Optional # name and @action lines per rule; the rest is the expression.

Mock request

Supported fields, operators & functions

Fields

  • http.host
  • http.request.uri.path
  • http.request.uri.query
  • http.request.uri / http.request.full_uri
  • http.request.method
  • http.user_agent
  • http.referer
  • ip.src
  • ip.src.country / ip.geoip.country
  • cf.threat_score
  • ssl

Operators

  • eq ne (== !=)
  • lt le gt ge (< <= > >=)
  • contains
  • matches / ~ (regex)
  • in { … } (values or IP CIDRs)
  • and or not (&& || !)

Functions

  • lower(x) upper(x)
  • len(x)
  • starts_with(x, "…")
  • ends_with(x, "…")
  • concat(a, b, …)

How it works

  1. 1Paste your Cloudflare rule expressions — copy them straight from the dashboard's Expression Editor. Separate multiple rules with a blank line; add an optional # name and @action line to each.
  2. 2Fill in the mock request: host, path, method, client IP, country, user agent, threat score and so on.
  3. 3Hit Evaluate. The tool parses each expression and checks it against the request, top to bottom.
  4. 4The first matching rule is highlighted as the one that fires; expand any rule to see which sub-condition was true or false and the actual value each field resolved to.

Frequently asked

Does my data leave the browser?

No. The parser and evaluator run entirely on this page — your rules and the request values are never sent to any server.

Which Cloudflare rule types does this cover?

Anything written in Cloudflare's Rules language expression syntax — custom firewall rules, WAF custom rules, and the fields shared by rate-limiting and transform rules. It evaluates the expression logic; it does not run Cloudflare Managed Ruleset signatures.

How is 'which rule fires' decided?

Rules are evaluated in the order you paste them, and the first one whose expression matches the request is reported as the one that fires — the same top-to-bottom order Cloudflare applies to custom rules. Every rule still shows its own match result so you can see overlaps.

Why does my expression say it can't parse?

The tool supports the common fields, operators and functions listed under the editor. Very new fields, list/$-references, or managed-ruleset-only constructs aren't modelled — simplify the expression to the supported subset to test its logic.

Does it match IP ranges?

Yes. ip.src in { 198.51.100.0/24 } does real IPv4 CIDR matching, and eq/ne compare exact addresses.

Related tools