{"name":"io.github.itunified-io/cloudflare","slug":"itunified-io-cloudflare","title":"Cloudflare MCP Server","description":"Cloudflare MCP Server — 84 tools for DNS, Tunnels, WAF, Zero Trust, R2, KV & Workers","url":"https://mcp.market/server/itunified-io-cloudflare","rating":null,"grade":"C","score":65,"certified":false,"status":"active","category":"devtools","tags":["devtools"],"presence":{"score":11,"stars":null,"forks":null,"downloads_week":143,"last_push_at":null,"license":"AGPL-3.0-only"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/itunified-io/mcp-cloudflare","website":null,"version":"2026.4.10","remotes":[],"packages":[{"registryType":"npm","identifier":"@itunified.io/mcp-cloudflare","version":"2026.4.10-1","runtimeHint":"npx","transport":{"type":"stdio"},"environmentVariables":[{"description":"Cloudflare API Token with appropriate permissions","name":"CLOUDFLARE_API_TOKEN"},{"description":"Cloudflare Account ID (required for account-level operations)","name":"CLOUDFLARE_ACCOUNT_ID"}]}],"tools":[{"name":"cloudflare_account_info","description":"Get Cloudflare account details (account name, ID, settings). No zone_id needed.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_cache_purge","description":"Purge cached files from Cloudflare's edge. Purge specific URLs (files), cache tags, URL prefixes, or everything.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_certificate_get","description":"Get details of a specific SSL/TLS certificate pack including hosts, status, validity, and issuer.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_certificate_list","description":"List SSL/TLS certificate packs for a zone. Shows all certificates including Universal SSL, Advanced, and custom uploads.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_ddos_analytics","description":"Query DDoS attack analytics for a zone using Cloudflare GraphQL Analytics. Returns aggregated attack traffic data.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_dns_create","description":"Create a new DNS record in a zone.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_dns_delete","description":"Delete a DNS record from a zone.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_dns_export","description":"Export all DNS records for a zone in BIND zone file format. Returns raw text.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_dns_get","description":"Get a single DNS record by its record ID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_dns_import","description":"Import DNS records from a BIND zone file. Sends the file content as multipart/form-data.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_dns_list","description":"List DNS records for a zone. Optionally filter by type, name, content, or proxied status.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_dns_search","description":"Search DNS records by name pattern. Returns all records whose name contains the given string.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_dns_update","description":"Update an existing DNS record (full replacement via PUT).","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_dnssec_disable","description":"DESTRUCTIVE: Disable DNSSEC for a zone. Also remove the DS record at your domain registrar to avoid DNS resolution failures.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_dnssec_enable","description":"DESTRUCTIVE: Enable DNSSEC for a zone. After enabling, you must add the DS record at your domain registrar for DNSSEC to become fully active.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_dnssec_status","description":"Get the DNSSEC status for a zone.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_ip_access_create","description":"Create an IP access rule for a zone. Targets can be a specific IP, CIDR range, ASN, or country code.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_ip_access_delete","description":"Delete an IP access rule from a zone by its rule ID.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_ip_access_list","description":"List IP access rules (firewall rules) for a zone. Filter by mode (block, challenge, whitelist, js_challenge).","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_kv_delete","description":"Delete a key from a Workers KV namespace.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_kv_list_keys","description":"List keys stored in a Workers KV namespace. Supports prefix filtering and cursor-based pagination.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_kv_namespace_create","description":"Create a new Workers KV namespace in the account.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_kv_namespace_delete","description":"DESTRUCTIVE: Delete a Workers KV namespace by its ID. This removes all keys in the namespace.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_kv_namespace_list","description":"List all Workers KV namespaces in the account.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_kv_read","description":"Read the value of a key from a Workers KV namespace. Returns the raw string value.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_kv_write","description":"Write a value to a key in a Workers KV namespace. Optionally set a TTL for automatic expiration.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_r2_bucket_create","description":"Create a new R2 storage bucket. Name must be 3-63 lowercase alphanumeric characters with hyphens.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_r2_bucket_delete","description":"DESTRUCTIVE: Delete an R2 bucket. The bucket must be empty before deletion.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_r2_bucket_domain_add","description":"Attach a custom domain to an R2 bucket, enabling public access via that domain. The domain must belong to a zone in the same account. Cloudflare automatically creates a CNAME record.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_r2_bucket_domain_list","description":"List custom domains attached to an R2 bucket. Shows domain name, status, and zone info.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_r2_bucket_domain_remove","description":"Remove a custom domain from an R2 bucket. This disables public access via that domain.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_r2_bucket_get","description":"Get details of an R2 bucket including creation date and location.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_r2_bucket_list","description":"List all R2 buckets in the account. Supports filtering by name and pagination.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_r2_object_delete","description":"Delete an object from an R2 bucket.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_r2_object_get","description":"Get metadata of an object in an R2 bucket (size, etag, content type, last modified). Does not return object body.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_r2_object_list","description":"List objects in an R2 bucket. Supports prefix filtering, delimiter for directory-like listing, and pagination.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_rate_limit_get","description":"Get details of a specific rate limiting rule including threshold, period, action, and match conditions.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_rate_limit_list","description":"List all rate limiting rules for a zone with pagination.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_rate_limit_status","description":"Check Cloudflare API rate limit consumption. Returns current limit, remaining requests, and reset time from response headers.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_security_events","description":"Query recent security/firewall events for a zone using Cloudflare GraphQL Analytics.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_security_insights","description":"List Security Center insights (configuration issues, vulnerabilities, misconfigurations) for the account. Requires CLOUDFLARE_ACCOUNT_ID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_security_insights_severity_count","description":"Get Security Center insight counts grouped by severity (low, moderate, critical). Quick overview without fetching all issues. Requires CLOUDFLARE_ACCOUNT_ID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_security_level_get","description":"Get the current security level setting for a zone (off, essentially_off, low, medium, high, under_attack).","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_security_level_set","description":"DESTRUCTIVE: Update the security level for a zone. Changes affect live traffic immediately. Use 'under_attack' only during active DDoS attacks.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_ssl_setting_get","description":"Get the current SSL/TLS encryption mode for a zone (off, flexible, full, strict).","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_ssl_setting_set","description":"DESTRUCTIVE: Set the SSL/TLS encryption mode for a zone. Changes affect live traffic immediately. 'strict' is recommended for production.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_ssl_verification","description":"Get SSL/TLS verification status for a zone. Shows certificate validation progress, hostname coverage, and brand check status.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_tls_setting_get","description":"Get the minimum TLS version setting for a zone (1.0, 1.1, 1.2, or 1.3).","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_tls_setting_set","description":"DESTRUCTIVE: Set the minimum TLS version for a zone. Changes affect live traffic immediately. Higher versions are more secure but may break older clients.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_token_verify","description":"Validate the configured Cloudflare API token and check its permissions.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_tunnel_config_get","description":"Get the ingress configuration for a Cloudflare Tunnel.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_tunnel_config_update","description":"Update the ingress configuration for a Cloudflare Tunnel.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_tunnel_create","description":"Create a new Cloudflare Tunnel. A secure 32-byte tunnel secret is automatically generated.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_tunnel_delete","description":"Delete a Cloudflare Tunnel by its ID. This action cannot be undone.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_tunnel_get","description":"Get details for a specific Cloudflare Tunnel by its ID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_tunnel_list","description":"List Cloudflare Tunnels for the account. Optionally filter by name or deleted status.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_tunnel_token","description":"Get the connector token for a Cloudflare Tunnel. This JWT token is used by cloudflared to authenticate with the Cloudflare edge. Store securely — treat as a credential.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_under_attack_status","description":"Check whether a zone is currently in 'Under Attack' mode. Returns the current security level and whether DDoS protection is maximized.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_waf_create_custom_rule","description":"Add a new custom WAF firewall rule to a zone. Uses Cloudflare Rules Language for the expression.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_waf_delete_custom_rule","description":"Delete a custom WAF firewall rule from a zone ruleset.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_waf_get_ruleset","description":"Get a specific WAF ruleset by ID, including all rules within the ruleset.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_waf_list_custom_rules","description":"List all custom WAF firewall rules for a zone (http_request_firewall_custom phase entrypoint).","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_waf_list_rulesets","description":"List all WAF rulesets for a zone (managed, custom, rate-limiting, etc.).","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_web_analytics_create","description":"Create/enable a Web Analytics (RUM) site. Enables privacy-first, cookie-free analytics beacon auto-injection for the specified hostname.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_web_analytics_delete","description":"Delete a Web Analytics (RUM) site and stop collecting analytics.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_web_analytics_get","description":"Get details of a specific Web Analytics (RUM) site by ID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_web_analytics_list","description":"List all Web Analytics (RUM) sites for the account. Returns site IDs, hostnames, and creation dates.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_web_analytics_stats","description":"Query Web Analytics traffic stats for a zone. Returns page views, visits, and bandwidth grouped by time.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_worker_analytics","description":"Query Workers invocation analytics (time-series). Returns per-script metrics including requests, errors, subrequests, and CPU time percentiles ordered by time.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_worker_delete","description":"DESTRUCTIVE: Delete a Workers script by name. This action cannot be undone.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_worker_deploy","description":"Deploy a Workers script. Creates or updates the named script with the provided source code.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_worker_deploy_project","description":"Deploy a multi-file Workers project using wrangler. Runs 'npx wrangler deploy' in the given project directory.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_worker_list","description":"List all Workers scripts deployed in the account.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_worker_route_create","description":"Create a Workers route that maps a URL pattern to a Worker script for a zone.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_worker_route_list","description":"List all Workers routes for a zone. Routes map URL patterns to Worker scripts.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_worker_secret_delete","description":"Delete a secret from a Workers script by name.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_worker_secret_list","description":"List all secrets bound to a Workers script. Only secret names are returned, not values.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_worker_secret_set","description":"Set a secret for a Workers script. Creates or updates the named secret. The secret value is NOT echoed in the response for security.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_worker_usage","description":"Query Workers usage summary (per-script aggregated). Returns scripts ranked by total request count, with error rates and CPU time percentiles.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_zone_get","description":"Get zone details including status, nameservers, and plan.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_zone_health","description":"Check the health of a zone: combines zone status, DNSSEC configuration, and SSL mode into a single health report.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_zone_list","description":"List all Cloudflare zones with pagination. Optionally filter by status or name.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_zone_setting_get","description":"Get a specific zone setting by name (e.g., 'ssl', 'security_level', 'minify').","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_zone_setting_update","description":"Update a specific zone setting (e.g., change SSL mode, security level).","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_zt_create_app","description":"Create a new Zero Trust Access application. Protects a domain with identity-based access control.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_zt_create_idp","description":"Create a new identity provider (IdP) for Zero Trust Access. Supports GitHub, Google, SAML, OIDC, Azure AD, Okta, and one-time PIN.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_zt_create_policy","description":"Create an access policy for a Zero Trust Access application. Policies define who can access the application.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_zt_delete_app","description":"DESTRUCTIVE: Delete a Zero Trust Access application. This removes the application and all its associated policies.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_zt_delete_idp","description":"DESTRUCTIVE: Delete an identity provider (IdP) from Zero Trust Access.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_zt_delete_policy","description":"DESTRUCTIVE: Delete an access policy from a Zero Trust Access application.","write_action":true,"price_micros":0,"input_schema":null},{"name":"cloudflare_zt_gateway_status","description":"Get the Zero Trust Gateway (DNS/HTTP filtering) configuration status for the account.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_zt_get_app","description":"Get details for a specific Zero Trust Access application by its ID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_zt_list_apps","description":"List all Zero Trust Access applications for the account.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_zt_list_idps","description":"List all identity providers (IdPs) configured for Zero Trust Access on the account.","write_action":false,"price_micros":0,"input_schema":null},{"name":"cloudflare_zt_list_policies","description":"List all access policies attached to a Zero Trust Access application.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":65,"grade":"C","scanned_at":"2026-09-27T22:35:50.701Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-27T22:35:50.728Z","components":{"code":{"score":25,"max":25,"notes":["45 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":3,"max":15,"notes":["repository not readable: repo not found"]},"identity":{"score":2,"max":10,"notes":["no repository or website to verify"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"@itunified.io/mcp-cloudflare","version":"2026.4.10-1","found":true,"license":"AGPL-3.0-only","hasInstallScripts":false,"dependencyCount":3,"publishedAt":"2026-04-10T06:39:51.157Z","repositoryUrl":"git+https://github.com/itunified-io/mcp-cloudflare.git","weeklyDownloads":143}],"repo":{"found":false,"owner":"itunified-io","repo":"mcp-cloudflare","error":"repo not found"},"icon":{"url":null,"source":"none"},"presence":{"stars":null,"forks":null,"downloadsWeek":143,"license":"AGPL-3.0-only","lastPushAt":null,"score":11}}}},"grade_history":[],"reviews":[]}