Cloudflare MCP Server

Official Cloudflare MCP server: the agent drives the whole Cloudflare API by searching the spec and running code

MCP serverOfficialEditors’ pick

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Manages live Cloudflare cloud infrastructure
  • Requires OAuth or an API token with resource permissions
  • Can change DNS, Workers, firewall and other products
All reasons and checks

cloudflare/mcp

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add mcp/cloudflare-mcp

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

This entry is high risk, so there is no one-click install. Review the code and add the config by hand.

Run in a terminal

claude mcp add --transport http cloudflare-api https://mcp.cloudflare.com/mcp

Or add to the file .mcp.json, in the project

{
  "mcpServers": {
    "cloudflare-api": {
      "type": "http",
      "url": "https://mcp.cloudflare.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Add to the file ~/.cursor/mcp.json, for all projects

{
  "mcpServers": {
    "cloudflare-api": {
      "url": "https://mcp.cloudflare.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.

Run in a terminal

code --add-mcp '{"name":"cloudflare-api","type":"http","url":"https://mcp.cloudflare.com/mcp"}'

Or add to the file .vscode/mcp.json, in the project

{
  "servers": {
    "cloudflare-api": {
      "type": "http",
      "url": "https://mcp.cloudflare.com/mcp"
    }
  }
}

If the file already exists, add the server inside the servers key.

Run in a terminal

codex mcp add cloudflare-api --url https://mcp.cloudflare.com/mcp

Or add to the file ~/.codex/config.toml, for all projects

[mcp_servers.cloudflare-api]
url = "https://mcp.cloudflare.com/mcp"

If the file already exists, append the block to the end.

Run in a terminal

gemini mcp add -s user -t http cloudflare-api https://mcp.cloudflare.com/mcp

Or add to the file ~/.gemini/settings.json, for all projects

{
  "mcpServers": {
    "cloudflare-api": {
      "httpUrl": "https://mcp.cloudflare.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Add to the file ~/.config/devin/mcp_config.json, for all projects

{
  "mcpServers": {
    "cloudflare-api": {
      "serverUrl": "https://mcp.cloudflare.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.

Formerly Windsurf.

Add to the file cline_mcp_settings.json, for all projects

{
  "mcpServers": {
    "cloudflare-api": {
      "type": "streamableHttp",
      "url": "https://mcp.cloudflare.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.

Add to the file .roo/mcp.json, in the project

{
  "mcpServers": {
    "cloudflare-api": {
      "type": "streamable-http",
      "url": "https://mcp.cloudflare.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

A fork of Roo Code, same .roo folders.

Add to the file opencode.json, in the project

{
  "mcp": {
    "cloudflare-api": {
      "type": "remote",
      "url": "https://mcp.cloudflare.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcp key.

Add to the file ~/.config/zed/settings.json, for all projects

{
  "context_servers": {
    "cloudflare-api": {
      "url": "https://mcp.cloudflare.com/mcp"
    }
  }
}

If the file already exists, add the server inside the context_servers key.

Checked against the repository on Sep 25, 2026, commit eb5db41.

Text for your agent

Add an MCP server at https://mcp.cloudflare.com/mcp with type http to your client config. Authorize via OAuth in the browser or set a Cloudflare bearer token with the required permissions.

Other ways from the author
{
  "mcpServers": {
    "cloudflare-api": {
      "type": "http",
      "url": "https://mcp.cloudflare.com/mcp"
    }
  }
}

Remote HTTP server. First connection opens Cloudflare OAuth login.

This is third-party code. Review the repository files before installing.

What it does

The server gives the agent the full Cloudflare API without dumping thousands of schemas into context. Instead of one tool per endpoint across roughly 2500 endpoints, it exposes three tools: search the docs, search the API spec, and execute code that calls cloudflare.request(). The spec stays on the server and only the execution result comes back, so token usage stays small. You can manage Workers, KV, R2, D1, Pages, DNS, firewall, load balancers and other products, and query the GraphQL Analytics API.

Who it is for. For devops engineers and developers who run their infrastructure on Cloudflare and want to manage it from an agent.

Good fit when

  • You manage Cloudflare resources from an agent: Workers, DNS, KV, R2, D1
  • You need the whole Cloudflare API without bloating context
  • You need analytics via the GraphQL API

Not a fit when

  • You have no Cloudflare account or rights to the resources
  • You do not want to give an agent access to live cloud infrastructure
  • Your client cannot use a remote MCP over HTTP

Example request

List all my Workers and add an A record for api.example.com pointing to 192.0.2.1

Limitations

This is a remote HTTP server, so you need a client that supports that transport. A Cloudflare account is required: OAuth login with permission selection, or an API token for CI and automation. Tokens with client IP filtering are not currently supported. Disabling code mode via codemode=false sharply increases token usage.

How to disable. Remove the cloudflare-api entry from your MCP client config and revoke the API token or OAuth access in the Cloudflare dashboard.

MCP

Transport
http
Authentication
OAuth
Environment variables
Environment variables
Bearer Token
secret
Cloudflare API token for login without OAuth, for CI and automation

Security check

  • Manages live Cloudflare cloud infrastructure
  • Requires OAuth or an API token with resource permissions
  • Can change DNS, Workers, firewall and other products

README in short

The README describes a code mode server: instead of a tool per endpoint the agent gets docs, search and execute and writes JavaScript to work with the spec and call cloudflare.request(). It includes a token cost comparison table, connection configs for OAuth and API token, and a GraphQL Analytics API example. It lists the server URL https://mcp.cloudflare.com/mcp and how to disable code mode. Apache-2.0 licensed.

FAQ

How does it save context?

The API spec lives on the server. The agent writes code to find and call the right endpoints, and only the execution result returns to context.

Can I skip OAuth?

Yes. For CI and automation create an API token in the Cloudflare dashboard and pass it as a bearer token.

Editors’ pick

An MCP server built into the Netdata agent: metrics, logs, alerts and live process, service and container data for an AI assistant

MCP serverMedium riskNo VPN needed80.7KRepository stars
Editors’ pick

GitHub's official MCP server: code, issues, pull requests, Actions and security alerts straight from the agent

MCP serverHigh risk33.3KRepository stars

Agent Skills for Google products

Agent Skills for Google products and technologies

Editors’ pick

Official Google skill collection for working with Google Cloud, BigQuery, GKE, ads and analytics from an agent

SkillHigh risk20.5KRepository stars
Official

AWS's official MCP server suite: docs, IaC, containers, serverless, databases, cost and monitoring

MCP serverHigh risk9.7KRepository stars
Foxx AICloudflare MCP Server

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.