← Back to directory
C

Cloudflare MCP Server

Official
Token-efficient access to the Cloudflare API.
Category
Dev Tools #272 of 438
Stars
★ 936 Very popular
Transport
Streamable HTTP
Runtime
Hosted (no local runtime)
Credentials
API key / credential required
License
Apache-2.0
Last commit
Tools
3
49FMRS · D

The source identifies this as an official remote MCP server maintained by Cloudflare. It covers a large portion of the Cloudflare API while using Code Mode to reduce context usage. Configure Token permissions carefully before use.

Strongest · Setup experience 13/20 Weakest · Security and permissions 7/20

Reliability
8/20
Security and permissions
7/20
Maintenance
8/20
Documentation
13/20
Setup experience
13/20
Why each score
Reliability 8/20
The README describes a plausible initialization flow with docs, search, and execute tools, including endpoint discovery followed by API execution. However, no cached manifest, source files, tests, or CI evidence are provided, so declared behavior, error handling, dependency control, and edge cases cannot be verified. Points are deducted accordingly.
Security and permissions 7/20
The README documents OAuth and user/account API tokens, recommends configuring only needed permissions, and states that generated code runs in isolated Workers. It also discloses external Cloudflare API access. There is no evidence of enforced least privilege, confirmation for dangerous writes, request scoping, data isolation, or controlled error disclosure; the examples include resource creation and DNS modification. Points are deducted for these gaps.
Maintenance 8/20
The repository is not archived, declares an Apache-2.0 license, and has identifiable Cloudflare ownership context. There is no source evidence of releases, commit cadence, dependency updates, issue response, maintenance commitments, or a security-response channel, so only a modest score is justified.
Documentation 13/20
The README includes the remote MCP URL, OAuth/API-token setup, code-mode versus non-code-mode behavior, tool descriptions, token-cost comparisons, product coverage, a GraphQL example, and several limitations. The manifest is unavailable, while parameter constraints, error behavior, permission mapping, troubleshooting, and version compatibility are underdocumented, so full marks are not justified.
Setup experience 13/20
A remote URL can be connected directly, with a recommended OAuth path, an API-token alternative, and JSON configuration examples. No user-managed runtime is required, making the primary setup path clear. Users still need to prepare Cloudflare credentials and permissions; account-ID auto-detection conditions, client compatibility, common failure handling, and production deployment details are incomplete, so points are deducted.

Static review · not runListed 2026-08-14

Read the FMRS scoring method →

Fit and risk

What it can accessRuns commands or codeUses the networkChanges third-party account data

Best for

  • Developers and operators managing Cloudflare resources through an agent.
  • Users who need access to many Cloudflare API endpoints with low context usage.
  • CI/CD and automation workflows.

Not for

  • Users who do not use the Cloudflare API.
  • Users who require a locally run stdio server.
  • Users unable to grant the required Cloudflare permissions.

Required permissions

  • OAuth connections require Cloudflare authorization and selected permissions.
  • API Tokens must include the Cloudflare permissions required for the intended operations.
  • Account Tokens need Account Resources : Read to allow automatic account ID detection.

Risks and side effects

  • A Token with write permissions can create or modify Cloudflare resources through API operations.
  • Disabling Code Mode registers about 2,500 API endpoints as individual tools and substantially increases token cost.
  • API Tokens with Client IP Address Filtering enabled are currently unsupported.
  • An incorrect account ID or insufficient permissions can cause requests to fail or target the wrong account.

Setup

Before you start

Runtime:Hosted (no local runtime)

Add the provided JSON configuration to a client that supports remote HTTP MCP servers, then connect to https://mcp.cloudflare.com/mcp. On first connection, use OAuth to authorize and select permissions, or provide a Cloudflare API Token. API Tokens are suitable for CI/CD and automation. To expose individual endpoint tools, append ?codemode=false to the URL.

MCP config · JSON
{"mcpServers":{"cloudflare-api":{"type":"http","url":"https://mcp.cloudflare.com/mcp"}}}

Works in clients that read an "mcpServers" key. For clients such as VS Code that use a different key, the configurator below converts it.

.vscode/mcp.json
{
  "servers": {
    "cloudflare-api": {
      "type": "http",
      "url": "https://mcp.cloudflare.com/mcp"
    }
  }
}

Goes in your project's .vscode/mcp.json (VS Code uses a "servers" key).

Terminal
claude mcp add --transport http cloudflare-api https://mcp.cloudflare.com/mcp

Run it in a terminal; replace any <…> placeholders with your own values first.

Check that it works

After connecting to https://mcp.cloudflare.com/mcp, check the client's tool list for docs, search, and execute; or ask "List all my Workers" — a returned Workers list proves auth and connectivity.

Troubleshooting

  1. Verify that the MCP URL is https://mcp.cloudflare.com/mcp.
  2. For OAuth, confirm that authorization was completed and the required permissions were selected.
  3. For API Tokens, verify the Token permissions; for automatic account ID detection with an Account Token, confirm Account Resources : Read is included.
  4. Confirm that Client IP Address Filtering is not enabled on the API Token.
  5. The user-token example requires account_id; Account Tokens can have the account ID auto-detected.
  6. Use ?codemode=false only when needed for composition with other Code Mode systems.

Things to try

Once connected, you can ask your AI assistant things like:

  • List all my Workers
  • Create a KV namespace called 'my-cache'
  • Add an A record for api.example.com pointing to 192.0.2.1
  • Search the Cloudflare docs for R2 details

Tools 3

docs read-only
Search Cloudflare developer documentation.
search read-only
Write JavaScript to query the API specification for endpoints.
execute writes
Write JavaScript to call the Cloudflare API, including the GraphQL Analytics API.

Use cases

List Workers.
Create a KV namespace.
Add an A record for a domain.
Query the Cloudflare GraphQL Analytics API.
Search Cloudflare developer documentation.

Overview

Cloudflare MCP Server provides access to the Cloudflare API through Code Mode and can search Cloudflare developer documentation. The API specification remains on the server while the agent writes JavaScript to search endpoints and execute API requests. Supported products include Workers, KV, R2, D1, Pages, DNS, Firewall, Load Balancers, Stream, Images, AI Gateway, Vectorize, Access, and Gateway.

Similar servers

Context7 80 · B

Upstash's official server providing up-to-date third-party library docs for AI coding assistants

★ 62.9k · Tools 2 Compare with this →

Source revision d5d326e5d4dd Data synced 2026-10-11 Read the FMRS scoring method