Install AI Tools

B2C Commerce tools, documentation, and skills for your assistant.

Claude

Install the plugin Recommended

bash
claude plugin marketplace add SalesforceCommerceCloud/b2c-developer-tooling
claude plugin install b2c-dx-mcp@b2c-developer-tooling

Start a new Claude Code session. To install for the current project only, run it from your project directory with --scope project.

Manual MCP setup
bash
claude mcp add --transport stdio --scope user b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Start a new session. To configure the current project only, run it from your project directory with --scope project. See Claude Code MCP setup.

Claude Desktop setup

Codex

Install the plugin Recommended

bash
codex plugin marketplace add SalesforceCommerceCloud/b2c-developer-tooling
codex plugin add b2c-dx-mcp@b2c-developer-tooling

Start a new Codex session in your project. This setup also works with the Codex IDE extension and the ChatGPT Work desktop app.

Manual MCP setup
bash
codex mcp add b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Or add this to ~/.codex/config.toml (or $CODEX_HOME/config.toml if customized):

toml
[mcp_servers.b2c-dx-mcp]
command = "npx"
args = ["-y", "@salesforce/b2c-dx-mcp@latest"]

Start a new session. See Codex MCP configuration.

ChatGPT online setup

VS Code

Install the plugin Recommended

  1. Open the Command Palette (Cmd/Ctrl+Shift+P) and run Chat: Install Plugin from Source.
  2. Enter SalesforceCommerceCloud/b2c-developer-tooling.
  3. Select b2c-dx-mcp and follow the installation prompts.
  4. Start a new chat in GitHub Copilot.
Manual MCP setup

Add this to .vscode/mcp.json in your workspace:

json
{
  "servers": {
    "b2c-dx-mcp": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@salesforce/b2c-dx-mcp@latest"]
    }
  }
}

See VS Code MCP setup.

Copilot CLI setup

Cursor

Reload the MCP server in Cursor after installation.

Manual MCP setup

Add this to .cursor/mcp.json in your project:

json
{
  "mcpServers": {
    "b2c-dx-mcp": {
      "command": "npx",
      "args": ["-y", "@salesforce/b2c-dx-mcp@latest"]
    }
  }
}

For all projects, use ~/.cursor/mcp.json instead.

See Cursor's MCP documentation.

OpenCode

Add this to opencode.json in your project:

json
{
  "mcp": {
    "b2c-dx-mcp": {
      "type": "local",
      "command": ["npx", "-y", "@salesforce/b2c-dx-mcp@latest"],
      "enabled": true
    }
  }
}

Restart OpenCode. For all projects, use ~/.config/opencode/opencode.json. See OpenCode MCP setup.

Gemini

Run:

bash
gemini mcp add --scope user b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Start a new Gemini CLI session. To configure the current project only, run it from your project directory with --scope project. See Gemini CLI MCP setup.

No separate skills plugins needed.

Other clients and manual setup →
Skip to content
View as Markdown
View as Markdown

eCDN Commands ​

Commands for managing eCDN (embedded Content Delivery Network) for B2C Commerce storefronts.

For zone setup, DNS, and certificate requirements, see Salesforce's CDN Zones guide.

Global Flags ​

All eCDN commands support these flags:

FlagDescriptionEnvironment Variable
--tenant-idB2C Commerce tenant IDSFCC_TENANT_ID
--short-codeAPI short codeSFCC_SHORTCODE
--jsonOutput as JSON-

Zone Selection ​

Commands that operate on a specific zone use the --zone / -z flag:

FlagDescription
--zone, -zZone ID (32-char hex) or zone name

Zone names are resolved to IDs automatically via case-insensitive lookup.

Authentication ​

eCDN commands require OAuth authentication with these scopes:

Operation TypeRequired Scope
Read operationssfcc.cdn-zones
Write operationssfcc.cdn-zones.rw

For complete setup instructions, see the Authentication Guide.


Zone Management ​

b2c ecdn zones list ​

List all CDN zones for a tenant.

bash
b2c ecdn zones list --tenant-id zzxy_prd

Output ​

ColumnDescription
NameZone name
IDZone ID
StatusZone status
TypeZone type (storefront)

b2c ecdn zones create ​

Create a new storefront CDN zone.

bash
b2c ecdn zones create --tenant-id zzxy_prd --domain-name example.com
b2c ecdn zones create --tenant-id zzxy_prd --domain-name store.example.com --json

Flags ​

FlagDescriptionRequired
--domain-name, -dDomain name for the storefront zoneYes

Cache Management ​

b2c ecdn cache purge ​

Purge cached content from the CDN by path or cache tag. At least one of --path or --tag must be supplied.

bash
# Purge a single path (format: hostname/path)
b2c ecdn cache purge --zone my-zone --path "www.example.com/products"

# Purge by cache tag (repeatable)
b2c ecdn cache purge --zone my-zone --tag product-123 --tag category-456

# Wildcard path purge
b2c ecdn cache purge --zone my-zone --path "www.example.com/dw/image/v2/realm_instance/*" --json

Flags ​

FlagDescription
--path, -pPath to purge in hostname/path format
--tag, -tCache tag to purge (repeatable)

Rate Limiting ​

b2c ecdn rate-limit list ​

List rate limiting rules for a zone.

bash
b2c ecdn rate-limit list --zone my-zone
b2c ecdn rate-limit list --zone my-zone --extended
b2c ecdn rate-limit list --zone my-zone --json

b2c ecdn rate-limit get ​

Get a single rate limiting rule by ID.

bash
b2c ecdn rate-limit get --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e
b2c ecdn rate-limit get --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e --json

b2c ecdn rate-limit create ​

Create a rate limiting rule.

bash
b2c ecdn rate-limit create --zone my-zone --description "Rate limit /checkout" --expression '(http.request.uri.path matches "^/checkout")' --characteristics cf.unique_visitor_id --action block --period 60 --requests-per-period 50 --mitigation-timeout 600
b2c ecdn rate-limit create --zone my-zone --description "Rate limit /checkout" --expression '(http.request.uri.path matches "^/checkout")' --characteristics cf.unique_visitor_id --action block --period 60 --requests-per-period 50 --mitigation-timeout 600 --json

Flags ​

FlagDescriptionRequired
--descriptionRule descriptionYes
--expressionExpression defining when to evaluate the ruleYes
--characteristicsComma-separated request grouping keysYes
--actionMitigation actionYes
--periodRate window in seconds (10, 60, 120, 300, 600)Yes
--requests-per-periodMax requests allowed within the periodYes
--mitigation-timeoutAction duration in seconds (0, 60, 120, 300, 600, 3600, 86400)Yes
--counting-expressionOptional expression for what requests to countNo
--enabled / --no-enabledEnable/disable ruleNo
--position-beforeInsert before another rule IDNo
--position-afterInsert after another rule IDNo

b2c ecdn rate-limit update ​

Update fields of an existing rate limiting rule.

bash
b2c ecdn rate-limit update --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e --requests-per-period 100 --mitigation-timeout 120
b2c ecdn rate-limit update --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e --action managed_challenge --no-enabled
b2c ecdn rate-limit update --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e --requests-per-period 100 --mitigation-timeout 120 --json

b2c ecdn rate-limit delete ​

Delete a rate limiting rule.

bash
b2c ecdn rate-limit delete --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e --force
b2c ecdn rate-limit delete --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e --force --json

Custom Firewall Rules ​

Manage custom firewall rules for a zone. Custom rules let you block, challenge, log, or otherwise act on requests that match a Cloudflare-style expression. Rules are evaluated in order and the order can be updated as a whole through reorder.

b2c ecdn firewall list ​

List custom firewall rules for a zone.

bash
b2c ecdn firewall list --zone my-zone
b2c ecdn firewall list --zone my-zone --extended
b2c ecdn firewall list --zone my-zone --limit 50
b2c ecdn firewall list --zone my-zone --json

Flags ​

FlagDescriptionRequired
--limitMaximum records per request (1–50)No
--offsetResult offset for paginationNo
--extendedInclude Expression and Last Updated columns (Rule ID is shown by default)No
--columnsComma-separated column namesNo

b2c ecdn firewall get ​

Get a single custom firewall rule by ID.

bash
b2c ecdn firewall get --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e
b2c ecdn firewall get --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e --json

b2c ecdn firewall create ​

Create a custom firewall rule.

bash
b2c ecdn firewall create --zone my-zone --description "Block /admin" \
  --expression '(http.request.uri.path matches "^/admin")' --actions block

b2c ecdn firewall create --zone my-zone --description "Challenge bots" \
  --expression 'cf.threat_score gt 30' --actions managed_challenge --no-enabled

b2c ecdn firewall create --zone my-zone --description "Insert before existing" \
  --expression '(http.host eq "old.example.com")' --actions block \
  --before 2c0fc9fa937b11eaa1b71c4d701ab86e

Flags ​

FlagDescriptionRequired
--descriptionRule descriptionYes
--expressionExpression that determines when the rule appliesYes
--actionsComma-separated list of actions applied by the ruleYes
--enabled / --no-enabledEnable/disable rule (default true)No
--beforeInsert before another rule ID (mutually exclusive with --after)No
--afterInsert after another rule ID (mutually exclusive with --before)No

b2c ecdn firewall update ​

Update fields of an existing custom firewall rule. Provide at least one update field; the command rejects empty patches so accidental no-op runs do not look like successes.

bash
b2c ecdn firewall update --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e \
  --description "Updated copy"

b2c ecdn firewall update --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e \
  --actions managed_challenge --no-enabled

b2c ecdn firewall delete ​

Delete a custom firewall rule. Requires --force outside of --json mode. Routes through the destructive-action safety guard so an in-flight policy or confirmation prompt has the chance to intercept before any HTTP call.

bash
b2c ecdn firewall delete --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e --force
b2c ecdn firewall delete --zone my-zone --rule-id 2c0fc9fa937b11eaa1b71c4d701ab86e --force --json

b2c ecdn firewall reorder ​

Update the evaluation order of all custom firewall rules. Provide either --rule-ids (comma-separated, in the desired order) or --rule-ids-file (path to a JSON file containing a string array). Reordering is treated as a destructive action and so requires --force outside of --json mode.

bash
b2c ecdn firewall reorder --zone my-zone \
  --rule-ids ffffe61cf25e4ec49c34b029ff3060f7,2c0fc9fa937b11eaa1b71c4d701ab86e --force

b2c ecdn firewall reorder --zone my-zone --rule-ids-file ./order.json --force

order.json example:

json
["ffffe61cf25e4ec49c34b029ff3060f7", "2c0fc9fa937b11eaa1b71c4d701ab86e"]

Certificate Management ​

b2c ecdn certificates list ​

List certificates for a zone.

bash
b2c ecdn certificates list --zone my-zone

b2c ecdn certificates add ​

Add a certificate to a zone.

bash
b2c ecdn certificates add --zone my-zone --hostname www.example.com --type custom --certificate-file ./cert.pem --private-key-file ./key.pem

Flags ​

FlagDescriptionRequired
--hostnameCustom hostnameYes
--typeCertificate type (custom, automatic; default automatic)No
--certificate-filePath to certificate PEM fileConditional (required for custom)
--private-key-filePath to private key PEM fileConditional (required for custom)
--bundle-methodBundle method for custom certificate chain verificationNo

b2c ecdn certificates update ​

Update a certificate.

bash
b2c ecdn certificates update --zone my-zone --certificate-id abc123 --certificate-file ./new-cert.pem --private-key-file ./new-key.pem

Flags ​

FlagDescriptionRequired
--certificate-idCertificate ID to updateYes
--hostname, -hHostname for the certificateNo
--typeCertificate type (custom, automatic)No
--certificate-filePath to certificate PEM fileNo
--private-key-filePath to private key PEM fileNo
--bundle-methodBundle method for custom certificate chain verificationNo

b2c ecdn certificates delete ​

Delete a certificate.

bash
b2c ecdn certificates delete --zone my-zone --certificate-id abc123

Flags ​

FlagDescription
--force, -fSkip confirmation prompt

b2c ecdn certificates validate ​

Validate a custom hostname certificate.

bash
b2c ecdn certificates validate --zone my-zone --custom-hostname-id abc123

Security Settings ​

b2c ecdn security get ​

Get security settings for a zone.

bash
b2c ecdn security get --zone my-zone

Output ​

Displays settings including:

  • Security level
  • Always-use-HTTPS state
  • TLS 1.3 state
  • WAF (OWASP) state
  • HSTS configuration (enabled, include subdomains, max age, preload)

b2c ecdn security update ​

Update security settings for a zone. Provide only the flags you want to change.

bash
b2c ecdn security update --zone my-zone --security-level medium
b2c ecdn security update --zone my-zone --always-use-https
b2c ecdn security update --zone my-zone --tls13 --waf

Flags ​

FlagDescriptionOptions
--security-levelZone security leveloff, essentially_off, low, medium, high, under_attack
--always-use-https / --no-always-use-httpsRedirect all HTTP requests to HTTPS—
--tls13 / --no-tls13Enable TLS 1.3—
--waf / --no-wafEnable WAF (OWASP) protection—
--hsts-enabled / --no-hsts-enabledEnable HSTS—
--hsts-include-subdomains / --no-hsts-include-subdomainsInclude subdomains in HSTS—
--hsts-max-ageHSTS max age in secondsinteger
--hsts-preload / --no-hsts-preloadEnable HSTS preload—

Speed Settings ​

b2c ecdn speed get ​

Get speed optimization settings.

bash
b2c ecdn speed get --zone my-zone

b2c ecdn speed update ​

Update speed optimization settings. Each flag accepts a string value (typically on/off); omitted flags default to off in the request body.

bash
b2c ecdn speed update --zone my-zone --brotli on
b2c ecdn speed update --zone my-zone --http3 on --early-hints on
b2c ecdn speed update --zone my-zone --polish lossy --webp on

Flags ​

FlagDescriptionOptions
--brotliBrotli compressionon, off
--http2-prioritizationHTTP/2 prioritizationon, off
--http2-to-originHTTP/2 to originon, off
--http3HTTP/3on, off
--early-hintsEarly hintson, off
--webpWebP image format supporton, off
--polishImage polish leveloff, lossless, lossy

WAF (Web Application Firewall) ​

WAF v1 Commands ​

b2c ecdn waf groups list ​

List WAF v1 rule groups.

bash
b2c ecdn waf groups list --zone my-zone

b2c ecdn waf groups update ​

Update a WAF v1 group.

bash
b2c ecdn waf groups update --zone my-zone --group-id abc123 --mode on
FlagDescriptionOptions
--modeGroup modeon, off
--actionAction for the WAF groupblock, challenge, monitor, default

b2c ecdn waf rules list ​

List WAF v1 rules in a group.

bash
b2c ecdn waf rules list --zone my-zone --group-id abc123

b2c ecdn waf rules get ​

Get details of a WAF v1 rule.

bash
b2c ecdn waf rules get --zone my-zone --rule-id abc123

b2c ecdn waf rules update ​

Update a WAF v1 rule.

bash
b2c ecdn waf rules update --zone my-zone --rule-id abc123 --action block

Flags ​

FlagDescriptionOptionsRequired
--rule-idWAF rule ID to update—Yes
--actionAction for the WAF ruleblock, challenge, monitor, disable, defaultYes

WAF v2 Commands ​

b2c ecdn waf rulesets list ​

List WAF v2 rulesets.

bash
b2c ecdn waf rulesets list --zone my-zone

b2c ecdn waf rulesets update ​

Update a WAF v2 ruleset.

bash
b2c ecdn waf rulesets update --zone my-zone --ruleset-id abc123 --action block

b2c ecdn waf managed-rules list ​

List WAF v2 managed rules.

bash
b2c ecdn waf managed-rules list --zone my-zone

b2c ecdn waf managed-rules update ​

Update a WAF v2 managed rule.

bash
b2c ecdn waf managed-rules update --zone my-zone --rule-id abc123 --action block

OWASP Settings ​

b2c ecdn waf owasp get ​

Get OWASP ModSecurity package settings.

bash
b2c ecdn waf owasp get --zone my-zone

b2c ecdn waf owasp update ​

Update OWASP package settings.

bash
b2c ecdn waf owasp update --zone my-zone --sensitivity high --action-mode challenge

Flags ​

FlagDescriptionOptionsRequired
--sensitivitySensitivity levellow, medium, high, offYes
--action-modeAction modesimulate, challenge, blockYes

WAF Migration ​

b2c ecdn waf migrate ​

Migrate a zone from WAF v1 to WAF v2.

bash
b2c ecdn waf migrate --zone my-zone

Logpush ​

b2c ecdn logpush ownership ​

Create a Logpush ownership challenge token for destination verification.

bash
b2c ecdn logpush ownership --zone my-zone --destination-path 's3://my-bucket/logs?region=us-east-1'

b2c ecdn logpush jobs list ​

List Logpush jobs.

bash
b2c ecdn logpush jobs list --zone my-zone

b2c ecdn logpush jobs create ​

Create a Logpush job.

bash
b2c ecdn logpush jobs create --zone my-zone \
  --name "HTTP logs" \
  --destination-path 's3://my-bucket/logs/{DATE}?region=us-east-1' \
  --log-type http_requests \
  --log-fields ClientRequestHost,ClientRequestMethod

Flags ​

FlagDescriptionRequired
--nameJob name (immutable after creation)Yes
--destination-pathDestination path, e.g. s3://bucket/path/{DATE}?region=us-east-1Yes
--log-typeType of logs: http_requests, firewall_events, page_shield_eventsYes
--log-fieldsComma-separated list of log fields to includeYes
--filterJSON filter expression for log selectionNo
--ownership-tokenOwnership challenge token for destination verificationNo

b2c ecdn logpush jobs get ​

Get Logpush job details.

bash
b2c ecdn logpush jobs get --zone my-zone --job-id 123456

b2c ecdn logpush jobs update ​

Update a Logpush job.

bash
b2c ecdn logpush jobs update --zone my-zone --job-id 123456 --enabled
b2c ecdn logpush jobs update --zone my-zone --job-id 123456 --no-enabled

b2c ecdn logpush jobs delete ​

Delete a Logpush job.

bash
b2c ecdn logpush jobs delete --zone my-zone --job-id 123456

Page Shield ​

Notifications (Organization Level) ​

b2c ecdn page-shield notifications list ​

List Page Shield notification webhooks.

bash
b2c ecdn page-shield notifications list --tenant-id zzxy_prd

b2c ecdn page-shield notifications create ​

Create a notification webhook.

bash
b2c ecdn page-shield notifications create --tenant-id zzxy_prd --webhook-url https://example.com/webhook --secret my-secret --zones zone1,zone2

b2c ecdn page-shield notifications delete ​

Delete a notification webhook.

bash
b2c ecdn page-shield notifications delete --tenant-id zzxy_prd --webhook-id abc123

Policies (Zone Level) ​

b2c ecdn page-shield policies list ​

List Page Shield policies.

bash
b2c ecdn page-shield policies list --zone my-zone

b2c ecdn page-shield policies create ​

Create a Page Shield policy.

bash
b2c ecdn page-shield policies create --zone my-zone --action allow --value script-src --expression 'http.request.uri.path contains "/trusted/"'

Flags ​

FlagDescriptionRequired
--actionPolicy action (allow, log)Yes
--valuePolicy value (e.g., script-src)Yes
--expressionPolicy expressionNo
--descriptionPolicy descriptionNo
--enabledEnable policyNo

b2c ecdn page-shield policies get ​

Get a Page Shield policy.

bash
b2c ecdn page-shield policies get --zone my-zone --policy-id abc123

b2c ecdn page-shield policies update ​

Update a Page Shield policy.

bash
b2c ecdn page-shield policies update --zone my-zone --policy-id abc123 --enabled

b2c ecdn page-shield policies delete ​

Delete a Page Shield policy.

bash
b2c ecdn page-shield policies delete --zone my-zone --policy-id abc123

Scripts (Zone Level) ​

b2c ecdn page-shield scripts list ​

List detected scripts.

bash
b2c ecdn page-shield scripts list --zone my-zone

b2c ecdn page-shield scripts get ​

Get script details.

bash
b2c ecdn page-shield scripts get --zone my-zone --script-id abc123

MRT Rules ​

For the routing sequence and Business Manager options, see eCDN Rules for a Phased Headless Rollout.

b2c ecdn mrt-rules get ​

Get MRT ruleset for a zone.

bash
b2c ecdn mrt-rules get --zone my-zone

b2c ecdn mrt-rules create ​

Create MRT rules to route requests to a Managed Runtime environment.

bash
b2c ecdn mrt-rules create --zone my-zone --mrt-hostname customer-pwa.mobify-storefront.com --expressions '(http.host eq "example.com")' --descriptions "Route to PWA"

Flags ​

FlagDescriptionRequired
--mrt-hostnameManaged Runtime instance hostnameYes
--expressionsComma-separated rule expressionsYes
--descriptionsComma-separated rule descriptionsNo

b2c ecdn mrt-rules update ​

Update MRT ruleset hostname or add new rules.

bash
b2c ecdn mrt-rules update --zone my-zone --mrt-hostname new-customer-pwa.mobify-storefront.com

b2c ecdn mrt-rules delete ​

Delete an MRT ruleset and all rules.

bash
b2c ecdn mrt-rules delete --zone my-zone

Individual MRT Rules ​

b2c ecdn mrt-rules rules update ​

Update an individual MRT rule.

bash
b2c ecdn mrt-rules rules update --zone my-zone --ruleset-id abc123 --rule-id def456 --enabled

b2c ecdn mrt-rules rules delete ​

Delete an individual MRT rule.

bash
b2c ecdn mrt-rules rules delete --zone my-zone --ruleset-id abc123 --rule-id def456

mTLS Certificates (Organization Level) ​

Code upload certificates enable two-factor (mTLS) code upload to staging instances. Two kinds of certificate are involved:

  • A CA, registered with eCDN for your staging tenant. It only signs client certificates and is never used to connect.
  • Client certificates (.p12) signed by that CA, one for each CI pipeline or developer. The CLI sends these on code upload.

These commands require a staging tenant (_stg). Most users only need create --generate (or the guided setup) once, then issue for each additional pipeline or developer. For the complete step-by-step workflow, see Set Up Two-Factor Code Upload.

b2c ecdn mtls list ​

List mTLS certificates, including their expiry and associated code upload hostname.

bash
b2c ecdn mtls list --tenant-id zzxy_stg

b2c ecdn mtls create ​

Register a CA certificate for code upload. With --generate, this is the main way to set up two-factor code upload. It generates a CA, registers it, and issues a first client certificate (named by --client-name) from it. With --certificate-file and --private-key-file, it registers a CA you already have.

bash
# Generate a CA, upload it, and issue a first client certificate
b2c ecdn mtls create --tenant-id zzxy_stg --name code-upload --generate

# Generate into a specific directory with a named client certificate
b2c ecdn mtls create --tenant-id zzxy_stg --name code-upload --generate --out-dir ./certs --client-name jsmith

# Upload an existing CA
b2c ecdn mtls create --tenant-id zzxy_stg --name code-upload --certificate-file ./ca.pem --private-key-file ./ca.key

With --generate, the command writes ca.pem, ca.key, <client-name>.p12, and a .gitignore to the output directory (owner-only permissions), uploads the CA, and prints the dw.json settings for code upload. The CA files are written before the upload, so if the upload fails you can retry with --certificate-file and --private-key-file.

Uploaded CA certificates must be CA certificates valid for at most 1 year; the CLI checks this before uploading.

Flags ​

FlagDescriptionDefault
--nameName (label) for the registered CA (required)
--certificate-filePath to PEM-encoded CA certificate file
--private-key-filePath to PEM-encoded CA private key file
--generateGenerate a new CA, register it, and issue a first client certificate from itfalse
--out-dirDirectory for generated filesmtls-certs
--client-nameName of the client certificate (.p12) issued from the new CA; this is the certificate used for code upload (for example the pipeline name, such as github-actions, or a Business Manager username)<name>-client
--p12-passphrasePassphrase for the generated .p12 (env: SFCC_MTLS_P12_PASSPHRASE)Random
--ca-common-nameCommon name for the generated CAStaging hostname if configured, else <name> CA
--ca-daysCA validity in days (maximum 365)365
--client-daysClient certificate validity in days (capped at the CA expiry)365
--forceOverwrite existing generated filesfalse

Provide either --generate or both --certificate-file and --private-key-file.


b2c ecdn mtls setup ​

A guided version of create --generate. It lists existing CAs, then prompts for the CA name (a label), the client certificate name, and the output directory, with a default for each. It generates and registers the CA and issues the client certificate from it. Finally, it offers to write the client certificate path and passphrase to dw.json, for uploading from this machine. Requires an interactive terminal.

bash
b2c ecdn mtls setup --tenant-id zzxy_stg

Flags ​

FlagDescriptionDefault
--p12-passphrasePassphrase for the generated .p12 (env: SFCC_MTLS_P12_PASSPHRASE)Random

The wizard updates the instance selected by --instance (or the active instance) in the dw.json given by --config (or ./dw.json).


b2c ecdn mtls issue ​

Issue a client certificate (.p12) signed by an existing CA, for a CI pipeline or developer. Runs locally; no API call or authentication is needed.

bash
b2c ecdn mtls issue --ca-cert-file ./mtls-certs/ca.pem --ca-key-file ./mtls-certs/ca.key --name jsmith
b2c ecdn mtls issue --ca-cert-file ca.pem --ca-key-file ca.key --name github-actions --output ./ci.p12 --days 90

Flags ​

FlagDescriptionDefault
--ca-cert-filePath to PEM-encoded CA certificate file (required)
--ca-key-filePath to PEM-encoded CA private key file (required)
--nameCommon name identifying the client (required; Business Manager username or API client ID recommended)
--output, -oOutput path for the .p12<name>.p12 next to the CA
--p12-passphrasePassphrase for the .p12 (env: SFCC_MTLS_P12_PASSPHRASE)Random
--daysValidity in days (capped at the CA expiry)365
--forceOverwrite an existing output filefalse

b2c ecdn mtls get ​

Get mTLS certificate details.

bash
b2c ecdn mtls get --tenant-id zzxy_stg --certificate-id abc123

b2c ecdn mtls delete ​

Delete an mTLS certificate and its associated code upload hostname. Client certificates issued by the deleted CA stop working.

bash
b2c ecdn mtls delete --tenant-id zzxy_stg --certificate-id abc123

Cipher Suites ​

b2c ecdn cipher-suites get ​

Get cipher suites configuration.

bash
b2c ecdn cipher-suites get --zone my-zone

b2c ecdn cipher-suites update ​

Update cipher suites settings.

bash
# Use a preset suite type
b2c ecdn cipher-suites update --zone my-zone --suite-type Modern

# Use custom ciphers
b2c ecdn cipher-suites update --zone my-zone --suite-type Custom --ciphers "ECDHE-ECDSA-AES128-GCM-SHA256,ECDHE-RSA-AES128-GCM-SHA256"

Flags ​

FlagDescriptionRequired
--suite-typeCipher suite type (Compatible, Modern, Custom, Legacy)Yes
--ciphersComma-separated cipher list (required for Custom)Conditional

Origin Headers ​

For setting the matching header in MRT and forwarding it from eCDN, follow Send the Access Control Header from eCDN to the MRT Origin.

b2c ecdn origin-headers get ​

Get origin header modification settings (MRT type).

bash
b2c ecdn origin-headers get --zone my-zone

b2c ecdn origin-headers set ​

Set or update origin header modification.

bash
b2c ecdn origin-headers set --zone my-zone --header-value my-secret-value
b2c ecdn origin-headers set --zone my-zone --header-value my-secret-value --header-name x-custom-header

Flags ​

FlagDescriptionRequired
--header-valueValue of the header to forward to originYes
--header-nameName of the header (cannot be changed for MRT origin)No

b2c ecdn origin-headers delete ​

Delete origin header modification.

bash
b2c ecdn origin-headers delete --zone my-zone