SDK generator comparisons

Cloudflare Forge and Voxgig, compared

An open-source pipeline from the operator of one of the largest public APIs, released on 28 September 2026. What it promises is larger than what it holds so far.

Published by Voxgig, which makes one of the two tools compared here. Facts checked against the first-party sources linked below. Corrections go to info@voxgig.com. Every page in this section follows the same scope and method.

What Cloudflare Forge is#

Forge is an Apache 2.0 code generation pipeline that Cloudflare published on 28 September 2026, the same day it launched cf, a command-line tool covering more than 3,000 operations of the Cloudflare API. Cloudflare describes Forge as a schema-first framework: a core that resolves OpenAPI 3.x documents into a typed schema model, applies JSONPath-based overlays, and runs transformers that each turn one artifact into another and can be chained.

The scale it was built for is the point. Cloudflare's API has more than 3,500 operations across hundreds of services written in Rust, Go, TypeScript and Python, and its public SDKs were generated by Stainless, whose hosted generator has been winding down since May 2026. Forge runs in CI on each team's API repository, lints every change, and produces preview builds of the CLI, the documentation and the SDKs with that change highlighted, to install and try before merging.

What the repository held on 28 September 2026 is narrower than the announcement: the core package, a TypeScript SDK transformer that its README calls a standalone generator, an Astro-based documentation renderer, and workspace packages for Python, Go, Java, PHP, C#, Ruby, Rust, Swift and a second TypeScript build. All of them wrap Fern. The TypeScript transformer repairs the definition, then runs Fern's TypeScript generator 3.80.1 in a patched Docker image, in shards, and adds Cloudflare's own runtime files. The workspaces run fern generate --local with Fern's Apache 2.0 generator images pinned in a generators.yml. So every SDK Forge produces is Fern's output, arranged and patched by Forge. No CLI transformer is among the published packages: the cf CLI's command generator lives in cf's own repository. Docker is required for full generation, and the install is pnpm add @cloudflare/forge.

The rest is stated intent. Cloudflare says more on its SDKs is coming soon, naming TypeScript, Rust, Python, Go, PHP and Terraform. It describes Cap'n Web bindings, MCP servers, TanStack Query bindings and Zod or Valibot schemas as outputs the chaining design makes possible. Planned inputs are AsyncAPI, GraphQL, Cap'n Proto and Protobuf; today the input is OpenAPI. Cloudflare's own words are that Forge is early in its life.

What Cloudflare Forge does that Voxgig does not#

Capabilities Cloudflare Forge has that Voxgig does not, in enough detail to evaluate them.

Transformers that chain: outputs made from outputs

Forge's unit is a transformer that takes one artifact and emits another. Transformers chain, so a generated SDK can be the input to a generated CLI, and a CLI's command tree the input to documentation or an MCP server. Cloudflare says users control the chain themselves, and the cf CLI is the first output built this way. Voxgig generates its six surfaces from one semantic model in one pass, and a surface cannot be fed to another surface. For a team that wants to derive a new artifact from a generated one rather than from the model, Forge's shape is the more general of the two.

Preview builds of every change, in CI, at 3,500 operations

The pipeline runs on each API team's repository. It lints the change to the OpenAPI document, then builds the CLI, the docs and the SDKs with only that change highlighted, so the author can install the preview and try it before merging. This is the workflow of a company with hundreds of services contributing to one API. No other tool on this site ships it. Voxgig runs when you run it, on your machine or in your CI, and reports drift through doctor; it has no notion of a per-change preview build.

Cloudflare's own generation problem, worked in the open

The most useful thing about Forge in its first week is where it comes from. The operator of a public API with more than 3,500 operations had its SDKs generated by a hosted service that is winding down. Rather than buy another service, it has built its own pipeline and published it under Apache 2.0. Its first output is already readable: the TypeScript SDK inside the cf CLI, committed to cf's public repository and compared below with a Voxgig SDK for the same API. The public SDKs and the API documentation are still to come. Voxgig has no first-party API of that size, and its output is judged from the SDK Catalog.

Fern's generators, driven from a pipeline you own

All nine language workspaces in the repository, TypeScript included, run Fern's open-source generators, pinned by version, with Fern's settings for nullable schemas, enum handling, and parameter order already chosen. A Forge user starts with generators Fern has maintained for years, and improvements arrive on a version bump. Fern's CLI asks for a Fern API key to verify the organization during local generation, and Forge's script does not supply one, so that check is met from your environment. Voxgig's targets are its own, so their quality is Voxgig's alone to answer for, in both directions.

Overlays in JSONPath, in the core

Forge applies JSONPath-based overlays to the OpenAPI document before any transformer sees it. The fixes a team needs, a renamed operation, a hidden internal endpoint, a corrected type, live in a file beside the spec rather than in a fork of it. The OpenAPI Initiative's Overlay specification, which Speakeasy uses, works the same way; whether Forge's overlays are that format or its own is not stated in the README. Voxgig's equivalent is the semantic model, which is edited after extraction rather than patched before it.

Side by side#

No partial ticks and no asterisks. If a tool has a feature, the table says it has it. Where a row would need a paragraph to be true, it is a paragraph somewhere else on this page instead of a row here.

Cloudflare ForgeVoxgig
LicenseApache 2.0MIT
Account neededNo Forge account. Every language runs through Fern's CLI and generators in Docker, and Fern documents an API key check for local generationNo
Status on the checked dateEarly in its life, in Cloudflare's words. Generates the cf CLI inside CloudflareIn use, with 600+ generated SDKs in the catalog
Language targets9: TypeScript, Python, Go, Java, PHP, C#, Ruby, Rust and Swift, all through Fern's generators23 language targets, 20 bundled plus Dart, Haskell and Lean from the langpack
Non-SDK outputA documentation renderer. The cf CLI is generated inside Cloudflare, with no CLI transformer published. MCP servers, Terraform, TanStack Query and Cap'n Web named as coming or possibleCLI, MCP Server, Agent Skills, REPL, Semantic Model, and documentation editions through docgen
InputsOpenAPI 3.x. AsyncAPI, GraphQL, Cap'n Proto and Protobuf plannedOpenAPI
CustomizationJSONPath overlays on the spec, and your own transformersModel, templates, components, features, targets, packages
Regenerating over your editsA custom directory kept through Fern's .fernignore, shown for its TypeScript SDK. Not described for the restThree-way diff-merge, plus a doctor command
RuntimeNode with pnpm, plus DockerNode
Behind itCloudflare, using it for its own APIOne small company, trading since 2018

One API, two SDKs#

Cloudflare's first SDK from Forge covers the whole API and is private to its cf CLI. Voxgig's build of the same API is 34 SDKs, one per product area, so the comparison here is of the DNS operations, against the DNS SDK. The two come from different editions of Cloudflare's definition. Both were run against a mock of the DNS slice on the same four steps as the other pairs: list, load, create, and remove. Last measured 29 September 2026.

Cloudflare Forge

The SDK inside cf 1.0.0-beta.5

The TypeScript SDK Cloudflare generated with Forge for its cf CLI: Fern's TypeScript generator 3.80.1, run and patched by Forge's TypeScript transformer. It covers the whole API, and it is bundled into the CLI, so nothing outside cf can import it.

Voxgig

voxgig-sdk/cloudflare-dns-sdk

One of 34 Voxgig SDKs that together cover the whole API, built from the DNS slice of the definition: eight targets from one run. A repository to build from, not a published package.

The definition: Cloudflare's definition, in two editions. cf pins Forge's repaired openapi.forge.json at 6b0fb3c, with 3,458 operations. The Voxgig SDKs come from cloudflare/api-schemas at commit d9edc9e, with 2,260 paths and 3,605 operations, of which the DNS slice is 41 paths and 76 operations. Its source.

Why Cloudflare is 34 Voxgig SDKs

Cloudflare's API is one OpenAPI document of 26 MB: 2,260 paths, 3,605 operations and 6,926 schemas, in cloudflare/api-schemas. Generated as one Voxgig SDK, it would produce more than 100 MB of model JSON, past GitHub's 100 MB limit for a single file.

So the Voxgig build splits the definition by product area into 34 slices, each a complete OpenAPI document of its own, and generates an SDK from each. Every operation is in exactly one slice, and together the slices cover all 2,260 paths and 3,605 operations. The split is a script run over one commit of the definition, so anyone can repeat it.

The DNS SDK stands in for all 34 here. At 76 operations it sits in the middle of the slices, which run from 12 to 303, and it covers one product end to end. Each slice is its own SDK with its own client, so an application that uses DNS and Workers takes two, where Cloudflare's SDK is one client for everything.

Voxgig SDKWhat it coversPathsOperations
cloudflare-access-sdkAccess: applications, identity providers, policies, certificates, groups, seats, bookmarks and service tokens93167
cloudflare-account-management-sdkAccount and zone administration: profiles, settings, tags, activation, holds and environments2444
cloudflare-ai-sdkWorkers AI, AI Gateway, AI Search, AutoRAG and Vectorize115175
cloudflare-application-delivery-sdkCache, purge, Argo, speed, origins, custom pages, managed headers and URL normalization3979
cloudflare-application-security-sdkPage Shield, upload scanning, token validation, leaked credentials, fraud detection and challenges3869
cloudflare-billing-sdkUsage, invoices, receipts, payment methods, plans, entitlements and subscriptions3655
cloudflare-cloudforce-one-sdkCloudforce One threat operations: requests, findings, reports, intelligence and investigations193285
cloudflare-content-monetization-sdkPay-per-crawl and pay-per-use configuration and reporting2133
cloudflare-d1-sdkD1 databases, queries, backups and import812
cloudflare-developer-platform-sdkArtifacts, feature flags, bulk operations, snippets and platform readiness3045
cloudflare-dlp-sdkData Loss Prevention: profiles, datasets, patterns and detection entries75129
cloudflare-dns-sdk compared hereDNS records, settings, analytics, DNS firewall, DNSSEC and secondary DNS4176
cloudflare-email-security-sdkEmail routing rules, addresses and email security settings79139
cloudflare-identity-sdkIAM, members, roles, organizations, tokens, OAuth clients, SCIM and SSO75131
cloudflare-images-sdkImage upload, variants, keys and delivery2437
cloudflare-load-balancing-sdkPools, monitors, health checks and steering policies3772
cloudflare-logpush-sdkLog jobs, destinations and log analytics4263
cloudflare-magic-sdkMagic Transit and Magic WAN: tunnels, routes, connectors, sites and interconnects76177
cloudflare-network-services-sdkAddressing, IP prefixes, connectivity, network monitoring, packet captures, Spectrum and Web3 gateways61112
cloudflare-observability-sdkAlerting, analytics, audit logs, diagnostics, RUM, request tracing and reporting5378
cloudflare-pages-sdkPages projects, deployments, domains and build configuration1726
cloudflare-queues-sdkQueues, consumers and producers1728
cloudflare-r2-sdkR2 buckets, Sippy, notification rules, lifecycle policies and the R2 catalog4369
cloudflare-radar-sdkRadar: traffic, attacks, BGP, DNS, HTTP and quality insights279279
cloudflare-realtime-sdkRealtime sessions, calls, Media over QUIC and signed URLs5281
cloudflare-registrar-sdkDomain registration, contacts, transfers and WHOIS2126
cloudflare-security-intelligence-sdkAbuse reports, botnet feeds, brand protection, threat intelligence, Security Center and URL scanning128169
cloudflare-ssl-sdkCertificates, custom certificates, keyless SSL, origin CA, client certificates and TLS settings4892
cloudflare-stream-sdkVideo upload, live inputs, encoding, playback, watermarks, subtitles and analytics3150
cloudflare-waf-sdkManaged rulesets, firewall rules, rate limits, filters, bot management and page rules85172
cloudflare-waiting-rooms-sdkWaiting rooms, events, rules, settings and status1124
cloudflare-workers-sdkWorkers, KV, Durable Objects, builds, browser rendering, containers, Hyperdrive, Pipelines and workflows192303
cloudflare-zero-trust-sdkZero Trust Gateway: policies, proxy endpoints, audit rules, categories and DEX151262
cloudflare-zone-settings-sdkZone settings: performance, transformations, Zaraz, image resizing, fonts and protocol behavior2546

What each SDK does

Cloudflare ForgeVoxgig
DNS operations callable68 of 76. Four deprecated analytics operations are skipped on purpose, and four nameserver-set operations postdate its definition75 of 76. The record PATCH has no method
Mock scenario on DNS records4 of 4 steps right1 of 4 right. The documented auth was rejected, list read 0 records, and load and create returned Cloudflare's envelope instead of the record
AuthA bearer API token, from an option or CLOUDFLARE_API_TOKENThe key goes in X-Auth-Email, the header for an account's email address, so the documented auth fails. Switching it off and sending Authorization as a header works
Cloudflare's response envelopeUnwrapped by runtime files Cloudflare adds to Fern's outputUnwrapped for 2 of the 76 operations. The other 74 return { success, errors, messages, result } as the entity's data
RetriesTwo retries on 408, 429, 502, 503 and 504, POST included, with backoff to 60 secondsNot in this build, which includes only the test feature
Timeouts60 seconds per attempt, client-wide or per callNot in this build
PaginationNone for DNS. List returns one page and its result_infoNot in this build
Idempotency keysNone. A retried POST goes out again without a keyNot in this build
Rate limits429 retried, honoring Retry-After or X-RateLimit-ResetNot in this build
LoggingOpt-in and silent by default, with auth headers redactedNot in this build
Offline test modeNone. You can inject your own fetchA mock transport seeded with your data, which the generated tests run on
MetricsNoneNot in this build
CancellationAn AbortSignal per callA signal stops stream() between items. With no timeout in this build, nothing aborts a request in flight
HooksNo hook API. A custom fetch, fetcher, header supplier or auth providerCustom features that hook every stage of a call
ErrorsOne generic CloudflareApiError for every DNS method, with the status, body and request IDOne error class per SDK, carrying the HTTP status and a notFound flag

What the code is

Cloudflare ForgeVoxgig
PackageNone. The SDK is bundled, minified, into the cf CLI on npmNot published. You build it from the repository
What one SDK coversThe whole API: 3,173 reachable methodsDNS: 76 operations, one of 34 SDKs
TypeScript source26.5 MB in 22,037 files for the whole API. The DNS resources and types are 0.41 MB in 501 files0.59 MB in 97 files, 0.17 MB of it the operation model in Config.ts
Runtime dependenciesNoneNone
Languages from this buildTypeScriptTypeScript, Python, PHP, Go, Ruby and Lua, plus a Go CLI and a Go MCP server
ShapeNested resource clients, such as client.dns.records, with one request object per call for path, query and body fields43 entities, such as DnsRecord, several named after response schemas, such as DnsRecordsDnsResponseCollection
TypesA request interface per operation and a type per schema. The DNS record type holds only the schema's metadata half, so record.name does not compileAn interface per entity, from the response schema, which here is the envelope: DnsRecord is { id, result }, and a create with the record's own fields does not compile
TestsNot run here: the SDK is not a package330 of 331 generated TypeScript tests pass. The other is skipped, for a feature this build does not include

The same calls in each, in TypeScript. Both samples type-check under strict mode against the SDK they name.

The SDK inside cf 1.0.0-beta.5
// cf imports its SDK through a package-private alias. Nothing outside cf can.
import { CloudflareApiClient } from '#sdk'

const client = new CloudflareApiClient({ apiToken: process.env.CLOUDFLARE_API_TOKEN })

const page = await client.dns.records.list({ zone_id: 'zone_123', per_page: 100 })
const record = await client.dns.records.get({ zone_id: 'zone_123', dns_record_id: 'rec_123' })
const created = await client.dns.records.create({
  zone_id: 'zone_123',
  body: { type: 'A', name: 'www.example.com', content: '198.51.100.4', ttl: 3600, proxied: false },
})
await client.dns.records.delete({ zone_id: 'zone_123', dns_record_id: 'rec_123' })
voxgig-sdk/cloudflare-dns-sdk
import { CloudflareDnsSDK } from '@voxgig-sdk/cloudflare-dns-sdk'

// The generated auth sends the key as X-Auth-Email, so switch it off and send
// the API token as a plain header.
const client = new CloudflareDnsSDK({
  auth: null,
  headers: { authorization: 'Bearer ' + process.env.CLOUDFLARE_API_TOKEN },
})

const records = await client.DnsRecord().list({ zone_id: 'zone_123' })
const record = await client.DnsRecord().load({ zone_id: 'zone_123', id: 'rec_123' })
// DnsRecordCreateData is the response envelope, so the record's own fields
// need a cast.
const created = await client.DnsRecord().create({
  zone_id: 'zone_123',
  type: 'A',
  name: 'www.example.com',
  content: '198.51.100.4',
  ttl: 3600,
  proxied: false,
} as any)
await client.DnsRecord().remove({ zone_id: 'zone_123', id: 'rec_123' })

What building and running both found

  • Cloudflare's SDK is Fern's TypeScript output. Forge's transformer repairs the definition, patches Fern's Docker image, runs it in three shards and adds two runtime files, one of which unwraps Cloudflare's response envelope.
  • It is private to the cf CLI: bundled and minified, with no export and no type declarations. The public Cloudflare SDKs Forge is meant to produce were not out on the checked date.
  • Its DNS record type holds only the metadata half of the record schema, an allOf that Fern generated in part, so record.name, type and content do not compile, although the values are there at run time.
  • Voxgig's model misses Cloudflare's envelope for 74 of the 76 DNS operations. List reads 0 records, load and create return the envelope, and the create type asks for result instead of the record's fields.
  • Voxgig's auth takes the first scheme of the definition's first security requirement, X-Auth-Email, which carries an email address, not a key. A user following the README gets a 401.
  • The 34 Cloudflare SDKs include only the test feature, so none of them retries, times out or logs. The eight other pairs on this site show what the standard set adds.
  • Voxgig has no method for the record PATCH, because apidef models a PATCH beside a PUT as a sixth operation and sdkgen generates five. Cloudflare's SDK calls it edit.

Which one to choose#

Choose Cloudflare Forge when

  • You want to build on the pipeline a large API operator is putting its own SDKs and CLI through, and you can wait for the parts that are still promised.
  • Your problem is the pipeline rather than the generator: previews per change, linting in CI, one artifact chained from another, across many teams contributing to one API.
  • You already use Fern's generators and want to run them from a pipeline you own, with Cloudflare maintaining the wrappers and the compatibility fixes.
  • You need a pluggable place to put a transformer of your own, for an output no generator ships.

Choose Voxgig when

  • You need SDKs in more languages than the nine in Forge's repository, or one neither has, since adding a Voxgig target is a supported extension.
  • You want a CLI, an MCP Server, Agent Skills and a REPL that already exist, generated from one model, rather than named as future outputs of a chain.
  • You want retries, idempotency, pagination, caching and tracing generated with the same options in every language. Forge's SDKs carry what Fern's generator gives each language, with Cloudflare's runtime patches on top in TypeScript.
  • You want regeneration to preserve your edits by construction. Forge shows a custom directory kept through Fern's .fernignore for its TypeScript SDK and does not describe the rest.
  • You would rather not depend on a project in its first month, whoever publishes it.

Limits of this comparison#

  • Forge was published on 28 September 2026, so its facts will move faster than any other tool's on this site. The comparison did not run Forge: the SDK pair examines the SDK Cloudflare generated with it for the cf CLI, beside a Voxgig SDK for the same API.
  • Where the announcement and the repository differ in scope, the repository is what exists and the post is what is intended. Both will move.
  • All nine SDK languages come from Fern's generators, TypeScript included: the transformer the README calls a standalone generator runs Fern's TypeScript generator in Docker. Their quality is Fern's, compared on the Fern page, and Postman's ownership of Fern applies to them as much here as there.
  • On the checked date the one SDK Cloudflare had generated with Forge was private: the TypeScript SDK bundled into the cf CLI, which cannot be imported. The announcement says the public SDKs and the API documentation will follow in the coming months.
  • The SDK pair compares one SDK for the whole API with one of 34 Voxgig SDKs, each covering a product area, and the two come from different editions of Cloudflare's definition. The comparison is of the DNS operations only, in TypeScript, against a mock of the definition.

Corrections go to info@voxgig.com or an issue on the generator repository. A correction changes the page and moves its checked date; corrections from Cloudflare Forge's own team carry the most weight.

Cloudflare Forge documentation#

First-party sources for the claims on this page. Where they disagree with it, they are the authority.

The other comparisons#

  • OpenAPI GeneratorThe community generator most APIs have shipped an SDK from at least once.
  • SpeakeasyCommercial SDK generation whose generator became AGPL-3.0 open source in September 2026.
  • FernSDKs and a documentation site from one definition. Part of Postman since January 2026.
  • StainlessThe generator behind many of the best-known AI SDKs. Its hosted product is winding down.
  • APIMaticThe longest-running commercial generator here, and the only one that converts between description formats.
  • liblabSDK generation shaped as a release pipeline. Part of Postman since November 2025.
  • KiotaMicrosoft's client generator, built so you do not need a separate SDK per API.
  • Hey APIThe TypeScript ecosystem's generator, with a Python generator in early development.

All comparisons, the ground rules, and the wider field

Read the generated code#

The generator is MIT and open, and the catalog holds 600+ generated SDKs readable without installing anything.

Voxgig SDK GeneratorTalk to Voxgig

Get the Voxgig dispatch

Short notes on building SDKs, CLIs, MCP Servers, and REPLs for API-first teams, plus the occasional Fireside episode pick.

By signing up you agree to our Terms of use.