Cloudflare's API lives at https://api.cloudflare.com/client/v4. Every response has the same envelope: success, errors, messages, and result.
Create an API token at My Profile → API Tokens with only the permissions you need (e.g. Zone → DNS → Edit). Send it as Authorization: Bearer <token>. In the examples it's written {{CLOUDFLARE_API_TOKEN}}. A zone id is on the zone's Overview page, or from the list-zones call.
Full reference: https://developers.cloudflare.com/api/
Whether the token is valid and active.
curl https://api.cloudflare.com/client/v4/user/tokens/verify \
-H "Authorization: Bearer {{CLOUDFLARE_API_TOKEN}}"
The domains the token can see, with their zone ids.
curl "https://api.cloudflare.com/client/v4/zones?per_page=20" \
-H "Authorization: Bearer {{CLOUDFLARE_API_TOKEN}}"
Filter with type= or name=.
curl https://api.cloudflare.com/client/v4/zones/{{ZONE_ID}}/dns_records \
-H "Authorization: Bearer {{CLOUDFLARE_API_TOKEN}}"
ttl: 1 means automatic. proxied routes traffic through Cloudflare.
curl -X POST https://api.cloudflare.com/client/v4/zones/{{ZONE_ID}}/dns_records \
-H "Authorization: Bearer {{CLOUDFLARE_API_TOKEN}}" \
-H "Content-Type: application/json" \
-d '{"type": "A", "name": "test", "content": "192.0.2.1", "ttl": 1, "proxied": false}'
Specific URLs. {"purge_everything": true} clears the whole zone.
curl -X POST https://api.cloudflare.com/client/v4/zones/{{ZONE_ID}}/purge_cache \
-H "Authorization: Bearer {{CLOUDFLARE_API_TOKEN}}" \
-H "Content-Type: application/json" \
-d '{"files": ["https://example.com/styles.css"]}'