Cloudflare MCP Server
Cloudflare MCP Server — 84 tools for DNS, Tunnels, WAF, Zero Trust, R2, KV & Workers
143 downloads/wk
Reviews
Write oneNobody has reviewed Cloudflare MCP Server yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Cloudflare MCP Server tools (95, 32 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
cloudflare_account_infoGet Cloudflare account details (account name, ID, settings). No zone_id needed.
cloudflare_cache_purgePurge cached files from Cloudflare's edge. Purge specific URLs (files), cache tags, URL prefixes, or everything.
cloudflare_certificate_getGet details of a specific SSL/TLS certificate pack including hosts, status, validity, and issuer.
cloudflare_certificate_listList SSL/TLS certificate packs for a zone. Shows all certificates including Universal SSL, Advanced, and custom uploads.
cloudflare_ddos_analyticsQuery DDoS attack analytics for a zone using Cloudflare GraphQL Analytics. Returns aggregated attack traffic data.
cloudflare_dns_createwrite actionCreate a new DNS record in a zone.
cloudflare_dns_deletewrite actionDelete a DNS record from a zone.
cloudflare_dns_exportExport all DNS records for a zone in BIND zone file format. Returns raw text.
cloudflare_dns_getGet a single DNS record by its record ID.
cloudflare_dns_importImport DNS records from a BIND zone file. Sends the file content as multipart/form-data.
cloudflare_dns_listList DNS records for a zone. Optionally filter by type, name, content, or proxied status.
cloudflare_dns_searchSearch DNS records by name pattern. Returns all records whose name contains the given string.
cloudflare_dns_updatewrite actionUpdate an existing DNS record (full replacement via PUT).
cloudflare_dnssec_disableDESTRUCTIVE: Disable DNSSEC for a zone. Also remove the DS record at your domain registrar to avoid DNS resolution failures.
cloudflare_dnssec_enableDESTRUCTIVE: Enable DNSSEC for a zone. After enabling, you must add the DS record at your domain registrar for DNSSEC to become fully active.
cloudflare_dnssec_statusGet the DNSSEC status for a zone.
cloudflare_ip_access_createwrite actionCreate an IP access rule for a zone. Targets can be a specific IP, CIDR range, ASN, or country code.
cloudflare_ip_access_deletewrite actionDelete an IP access rule from a zone by its rule ID.
cloudflare_ip_access_listList IP access rules (firewall rules) for a zone. Filter by mode (block, challenge, whitelist, js_challenge).
cloudflare_kv_deletewrite actionDelete a key from a Workers KV namespace.
cloudflare_kv_list_keysList keys stored in a Workers KV namespace. Supports prefix filtering and cursor-based pagination.
cloudflare_kv_namespace_createwrite actionCreate a new Workers KV namespace in the account.
cloudflare_kv_namespace_deletewrite actionDESTRUCTIVE: Delete a Workers KV namespace by its ID. This removes all keys in the namespace.
cloudflare_kv_namespace_listList all Workers KV namespaces in the account.
cloudflare_kv_readRead the value of a key from a Workers KV namespace. Returns the raw string value.
cloudflare_kv_writewrite actionWrite a value to a key in a Workers KV namespace. Optionally set a TTL for automatic expiration.
cloudflare_r2_bucket_createwrite actionCreate a new R2 storage bucket. Name must be 3-63 lowercase alphanumeric characters with hyphens.
cloudflare_r2_bucket_deletewrite actionDESTRUCTIVE: Delete an R2 bucket. The bucket must be empty before deletion.
cloudflare_r2_bucket_domain_addAttach a custom domain to an R2 bucket, enabling public access via that domain. The domain must belong to a zone in the same account. Cloudflare automatically creates a CNAME record.
cloudflare_r2_bucket_domain_listList custom domains attached to an R2 bucket. Shows domain name, status, and zone info.
cloudflare_r2_bucket_domain_removewrite actionRemove a custom domain from an R2 bucket. This disables public access via that domain.
cloudflare_r2_bucket_getGet details of an R2 bucket including creation date and location.
cloudflare_r2_bucket_listList all R2 buckets in the account. Supports filtering by name and pagination.
cloudflare_r2_object_deletewrite actionDelete an object from an R2 bucket.
cloudflare_r2_object_getGet metadata of an object in an R2 bucket (size, etag, content type, last modified). Does not return object body.
cloudflare_r2_object_listList objects in an R2 bucket. Supports prefix filtering, delimiter for directory-like listing, and pagination.
cloudflare_rate_limit_getGet details of a specific rate limiting rule including threshold, period, action, and match conditions.
cloudflare_rate_limit_listList all rate limiting rules for a zone with pagination.
cloudflare_rate_limit_statusCheck Cloudflare API rate limit consumption. Returns current limit, remaining requests, and reset time from response headers.
cloudflare_security_eventsQuery recent security/firewall events for a zone using Cloudflare GraphQL Analytics.
cloudflare_security_insightsList Security Center insights (configuration issues, vulnerabilities, misconfigurations) for the account. Requires CLOUDFLARE_ACCOUNT_ID.
cloudflare_security_insights_severity_countGet Security Center insight counts grouped by severity (low, moderate, critical). Quick overview without fetching all issues. Requires CLOUDFLARE_ACCOUNT_ID.
cloudflare_security_level_getGet the current security level setting for a zone (off, essentially_off, low, medium, high, under_attack).
cloudflare_security_level_setDESTRUCTIVE: Update the security level for a zone. Changes affect live traffic immediately. Use 'under_attack' only during active DDoS attacks.
cloudflare_ssl_setting_getGet the current SSL/TLS encryption mode for a zone (off, flexible, full, strict).
cloudflare_ssl_setting_setDESTRUCTIVE: Set the SSL/TLS encryption mode for a zone. Changes affect live traffic immediately. 'strict' is recommended for production.
cloudflare_ssl_verificationGet SSL/TLS verification status for a zone. Shows certificate validation progress, hostname coverage, and brand check status.
cloudflare_tls_setting_getGet the minimum TLS version setting for a zone (1.0, 1.1, 1.2, or 1.3).
cloudflare_tls_setting_setDESTRUCTIVE: Set the minimum TLS version for a zone. Changes affect live traffic immediately. Higher versions are more secure but may break older clients.
cloudflare_token_verifyValidate the configured Cloudflare API token and check its permissions.
cloudflare_tunnel_config_getGet the ingress configuration for a Cloudflare Tunnel.
cloudflare_tunnel_config_updatewrite actionUpdate the ingress configuration for a Cloudflare Tunnel.
cloudflare_tunnel_createwrite actionCreate a new Cloudflare Tunnel. A secure 32-byte tunnel secret is automatically generated.
cloudflare_tunnel_deletewrite actionDelete a Cloudflare Tunnel by its ID. This action cannot be undone.
cloudflare_tunnel_getGet details for a specific Cloudflare Tunnel by its ID.
cloudflare_tunnel_listList Cloudflare Tunnels for the account. Optionally filter by name or deleted status.
cloudflare_tunnel_tokenGet the connector token for a Cloudflare Tunnel. This JWT token is used by cloudflared to authenticate with the Cloudflare edge. Store securely — treat as a credential.
cloudflare_under_attack_statusCheck whether a zone is currently in 'Under Attack' mode. Returns the current security level and whether DDoS protection is maximized.
cloudflare_waf_create_custom_rulewrite actionAdd a new custom WAF firewall rule to a zone. Uses Cloudflare Rules Language for the expression.
cloudflare_waf_delete_custom_rulewrite actionDelete a custom WAF firewall rule from a zone ruleset.
cloudflare_waf_get_rulesetGet a specific WAF ruleset by ID, including all rules within the ruleset.
cloudflare_waf_list_custom_rulesList all custom WAF firewall rules for a zone (http_request_firewall_custom phase entrypoint).
cloudflare_waf_list_rulesetsList all WAF rulesets for a zone (managed, custom, rate-limiting, etc.).
cloudflare_web_analytics_createwrite actionCreate/enable a Web Analytics (RUM) site. Enables privacy-first, cookie-free analytics beacon auto-injection for the specified hostname.
cloudflare_web_analytics_deletewrite actionDelete a Web Analytics (RUM) site and stop collecting analytics.
cloudflare_web_analytics_getGet details of a specific Web Analytics (RUM) site by ID.
cloudflare_web_analytics_listList all Web Analytics (RUM) sites for the account. Returns site IDs, hostnames, and creation dates.
cloudflare_web_analytics_statsQuery Web Analytics traffic stats for a zone. Returns page views, visits, and bandwidth grouped by time.
cloudflare_worker_analyticsQuery Workers invocation analytics (time-series). Returns per-script metrics including requests, errors, subrequests, and CPU time percentiles ordered by time.
cloudflare_worker_deletewrite actionDESTRUCTIVE: Delete a Workers script by name. This action cannot be undone.
cloudflare_worker_deploywrite actionDeploy a Workers script. Creates or updates the named script with the provided source code.
cloudflare_worker_deploy_projectwrite actionDeploy a multi-file Workers project using wrangler. Runs 'npx wrangler deploy' in the given project directory.
cloudflare_worker_listList all Workers scripts deployed in the account.
cloudflare_worker_route_createwrite actionCreate a Workers route that maps a URL pattern to a Worker script for a zone.
cloudflare_worker_route_listList all Workers routes for a zone. Routes map URL patterns to Worker scripts.
cloudflare_worker_secret_deletewrite actionDelete a secret from a Workers script by name.
cloudflare_worker_secret_listList all secrets bound to a Workers script. Only secret names are returned, not values.
cloudflare_worker_secret_setSet a secret for a Workers script. Creates or updates the named secret. The secret value is NOT echoed in the response for security.
cloudflare_worker_usageQuery Workers usage summary (per-script aggregated). Returns scripts ranked by total request count, with error rates and CPU time percentiles.
cloudflare_zone_getGet zone details including status, nameservers, and plan.
cloudflare_zone_healthCheck the health of a zone: combines zone status, DNSSEC configuration, and SSL mode into a single health report.
cloudflare_zone_listList all Cloudflare zones with pagination. Optionally filter by status or name.
cloudflare_zone_setting_getGet a specific zone setting by name (e.g., 'ssl', 'security_level', 'minify').
cloudflare_zone_setting_updatewrite actionUpdate a specific zone setting (e.g., change SSL mode, security level).
cloudflare_zt_create_appwrite actionCreate a new Zero Trust Access application. Protects a domain with identity-based access control.
cloudflare_zt_create_idpwrite actionCreate a new identity provider (IdP) for Zero Trust Access. Supports GitHub, Google, SAML, OIDC, Azure AD, Okta, and one-time PIN.
cloudflare_zt_create_policywrite actionCreate an access policy for a Zero Trust Access application. Policies define who can access the application.
cloudflare_zt_delete_appwrite actionDESTRUCTIVE: Delete a Zero Trust Access application. This removes the application and all its associated policies.
cloudflare_zt_delete_idpwrite actionDESTRUCTIVE: Delete an identity provider (IdP) from Zero Trust Access.
cloudflare_zt_delete_policywrite actionDESTRUCTIVE: Delete an access policy from a Zero Trust Access application.
cloudflare_zt_gateway_statusGet the Zero Trust Gateway (DNS/HTTP filtering) configuration status for the account.
cloudflare_zt_get_appGet details for a specific Zero Trust Access application by its ID.
cloudflare_zt_list_appsList all Zero Trust Access applications for the account.
cloudflare_zt_list_idpsList all identity providers (IdPs) configured for Zero Trust Access on the account.
cloudflare_zt_list_policiesList all access policies attached to a Zero Trust Access application.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan45 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Install Cloudflare MCP Server in Claude Code, Cursor or VS Code
Runs npx -y @itunified.io/mcp-cloudflare on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add cloudflare -- npx -y @itunified.io/mcp-cloudflare
Cloudflare MCP Server: common questions
- Is Cloudflare MCP Server safe?
- With care: it is graded C, so read the findings first (65/100). Read the Cloudflare MCP Server safety report
- How do I install Cloudflare MCP Server?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Cloudflare MCP Server need an API key?
- No secret keys are declared. It reads 2 settings from the environment.
- Is Cloudflare MCP Server maintained?
- The latest release is v2026.4.10.
- What can I use instead of Cloudflare MCP Server?
- Servers from other publishers that do the same job: Porkbun (official) MCP server, Scrapling MCP Server and MCP server. Compare all Cloudflare MCP Server alternatives.
Alternatives to Cloudflare MCP Server
Same job from other publishers: the closest match first, then the best rated.
Porkbun (official)Official Porkbun MCP server: domains, DNS, SSL, hosting and Cloudflare via the Porkbun API.not reviewedEstablishedA
Scrapling MCP ServerWeb scraping with stealth HTTP, real browsers, and Cloudflare bypass. CSS selectors supported.not reviewedWidely usedA- MCPCloudflare MCP serversnot reviewedEstablishedA
Dados Abertos Senado BR MCPMCP server for Brazilian Federal Senate open data (legislative, administrative, e-Cidadania).not reviewedGrowingA
BorealHostAgent-native web hosting — deploy sites, manage DNS, register domains, scale infrastructurenot reviewedGrowingB