Cloudflare MCP Server
Official Cloudflare MCP server: the agent drives the whole Cloudflare API by searching the spec and running code
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Manages live Cloudflare cloud infrastructure
- Requires OAuth or an API token with resource permissions
- Can change DNS, Workers, firewall and other products
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/cloudflare-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport http cloudflare-api https://mcp.cloudflare.com/mcpOr add to the file .mcp.json, in the project
{
"mcpServers": {
"cloudflare-api": {
"type": "http",
"url": "https://mcp.cloudflare.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"cloudflare-api": {
"url": "https://mcp.cloudflare.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Run in a terminal
code --add-mcp '{"name":"cloudflare-api","type":"http","url":"https://mcp.cloudflare.com/mcp"}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"cloudflare-api": {
"type": "http",
"url": "https://mcp.cloudflare.com/mcp"
}
}
}If the file already exists, add the server inside the servers key.
Run in a terminal
codex mcp add cloudflare-api --url https://mcp.cloudflare.com/mcpOr add to the file ~/.codex/config.toml, for all projects
[mcp_servers.cloudflare-api]
url = "https://mcp.cloudflare.com/mcp"If the file already exists, append the block to the end.
Run in a terminal
gemini mcp add -s user -t http cloudflare-api https://mcp.cloudflare.com/mcpOr add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"cloudflare-api": {
"httpUrl": "https://mcp.cloudflare.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"cloudflare-api": {
"serverUrl": "https://mcp.cloudflare.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"cloudflare-api": {
"type": "streamableHttp",
"url": "https://mcp.cloudflare.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"cloudflare-api": {
"type": "streamable-http",
"url": "https://mcp.cloudflare.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"cloudflare-api": {
"type": "remote",
"url": "https://mcp.cloudflare.com/mcp"
}
}
}If the file already exists, add the server inside the mcp key.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"cloudflare-api": {
"url": "https://mcp.cloudflare.com/mcp"
}
}
}If the file already exists, add the server inside the context_servers key.
Add an MCP server at https://mcp.cloudflare.com/mcp with type http to your client config. Authorize via OAuth in the browser or set a Cloudflare bearer token with the required permissions.
Other ways from the author
{
"mcpServers": {
"cloudflare-api": {
"type": "http",
"url": "https://mcp.cloudflare.com/mcp"
}
}
}Remote HTTP server. First connection opens Cloudflare OAuth login.
This is third-party code. Review the repository files before installing.
What it does
The server gives the agent the full Cloudflare API without dumping thousands of schemas into context. Instead of one tool per endpoint across roughly 2500 endpoints, it exposes three tools: search the docs, search the API spec, and execute code that calls cloudflare.request(). The spec stays on the server and only the execution result comes back, so token usage stays small. You can manage Workers, KV, R2, D1, Pages, DNS, firewall, load balancers and other products, and query the GraphQL Analytics API.
Who it is for. For devops engineers and developers who run their infrastructure on Cloudflare and want to manage it from an agent.
Good fit when
- You manage Cloudflare resources from an agent: Workers, DNS, KV, R2, D1
- You need the whole Cloudflare API without bloating context
- You need analytics via the GraphQL API
Not a fit when
- You have no Cloudflare account or rights to the resources
- You do not want to give an agent access to live cloud infrastructure
- Your client cannot use a remote MCP over HTTP
Example request
List all my Workers and add an A record for api.example.com pointing to 192.0.2.1Limitations
This is a remote HTTP server, so you need a client that supports that transport. A Cloudflare account is required: OAuth login with permission selection, or an API token for CI and automation. Tokens with client IP filtering are not currently supported. Disabling code mode via codemode=false sharply increases token usage.
How to disable. Remove the cloudflare-api entry from your MCP client config and revoke the API token or OAuth access in the Cloudflare dashboard.
MCP
- Transport
- http
- Authentication
- OAuth
| Environment variables | |
|---|---|
| Bearer Token secret | Cloudflare API token for login without OAuth, for CI and automation |
Security check
- Manages live Cloudflare cloud infrastructure
- Requires OAuth or an API token with resource permissions
- Can change DNS, Workers, firewall and other products
README in short
The README describes a code mode server: instead of a tool per endpoint the agent gets docs, search and execute and writes JavaScript to work with the spec and call cloudflare.request(). It includes a token cost comparison table, connection configs for OAuth and API token, and a GraphQL Analytics API example. It lists the server URL https://mcp.cloudflare.com/mcp and how to disable code mode. Apache-2.0 licensed.
FAQ
How does it save context?
The API spec lives on the server. The agent writes code to find and call the right endpoints, and only the execution result returns to context.
Can I skip OAuth?
Yes. For CI and automation create an API token in the Cloudflare dashboard and pass it as a bearer token.
Related
An MCP server built into the Netdata agent: metrics, logs, alerts and live process, service and container data for an AI assistant
GitHub's official MCP server: code, issues, pull requests, Actions and security alerts straight from the agent
Agent Skills for Google products
Agent Skills for Google products and technologies
Official Google skill collection for working with Google Cloud, BigQuery, GKE, ads and analytics from an agent
AWS's official MCP server suite: docs, IaC, containers, serverless, databases, cost and monitoring