Setting up the Cloudflare MCP Server
Connect the Cloudflare API MCP Server via OAuth, add matching product-specific servers, and keep permissions tightly scoped.
- Skill Road
- Setting up the Cloudflare MCP Server
Published on 09.09.2026
Cloudflare runs a central API MCP server plus around a dozen product-specific MCP servers, all hosted and secured via OAuth.
Connecting the central API server
Register the remote server in your MCP client:
{
"mcpServers": {
"cloudflare-api": { "url": "https://mcp.cloudflare.com/mcp" }
}
}
On the first call, Cloudflare's OAuth dialog opens. Select the permissions the agent should receive there — grant only what's actually needed for the task at hand.
Adding product-specific servers
For targeted tasks, a focused server is often more useful than the broad API server, for example the documentation server (https://docs.mcp.cloudflare.com/mcp) for lookup questions, the observability server (https://observability.mcp.cloudflare.com/mcp) for logs and analytics, or the Radar server (https://radar.mcp.cloudflare.com/mcp) for Internet traffic data. Each product-specific server runs under its own subdomain and is registered by URL the same way.
Setting up with the Skills plugin
For Claude Code, Cursor, OpenCode, OpenAI Codex, and other agents with Agent Skills support, the cloudflare/skills plugin bundles the MCP servers with matching skills and slash commands. In Claude Code:
/plugin marketplace add cloudflare/skills
For automation: API token instead of OAuth
For CI/CD pipelines or recurring automated workflows, instead of interactive OAuth sign-in you can create a Cloudflare API token with narrowly scoped permissions and pass it as a bearer token in the Authorization header. Both user and account tokens are supported.
Keeping permissions tight
Within the granted permissions, the agent can access real production infrastructure — including DNS records, Workers deployments, and firewall and Zero Trust rules. For automated workflows, use a narrowly scoped token and try write actions against a staging environment before running them against production zones.
Verifying the setup
After connecting, test with a harmless, read-only task, such as "List my DNS records for domain X" or "Show me traffic analytics from the last 24 hours." Only allow write actions afterward.
Common setup issues
If the OAuth dialog doesn't open automatically, check whether the client is blocking pop-ups; the URL can usually be opened manually in that case. When installing the Skills plugin via the marketplace command, make sure Claude Code is updated to a current version, since older versions may not support the Agent Skills standard.
Combining multiple product-specific servers
For more complex workflows, several product-specific servers can be configured in parallel within the same client, for example the observability server for logs alongside the central API server for configuration changes. Each server needs its own unique name in the client configuration so the agent can clearly tell them apart.
Source: developers.cloudflare.com/agents/model-context-protocol/cloudflare/servers-for-cloudflare/ and github.com/cloudflare/mcp-server-cloudflare, checked on 2026-09-06.
Frequently asked questions
What is the difference between the API server and the product-specific servers?
The Cloudflare API MCP Server covers over 2,500 endpoints via search()/execute() and suits broad tasks. The product-specific servers (documentation, observability, Radar, and others) are more focused, often simpler for targeted queries, and each runs under its own subdomain.
Why does the API server use only two tools instead of one per endpoint?
With the so-called Code Mode approach, the language model writes JavaScript against a typed representation of the API instead of loading thousands of individual tool definitions. Per Cloudflare, this reduces token usage from over a million to roughly 1,000 tokens.
What does using the Cloudflare MCP servers cost?
The servers themselves are free and open source (Apache-2.0). A Cloudflare account is required; paid Cloudflare plans and features are billed independently of the MCP servers.
Can I use the servers without interactive sign-in?
Yes, for CI/CD and automation you can create a Cloudflare API token (user or account token) with the required permissions and pass it as a bearer token in the Authorization header instead of going through the OAuth dialog.
Which agents does the Cloudflare Skills plugin support?
Per Cloudflare, the plugin works with any agent that supports the Agent Skills standard, including Claude Code, Cursor, OpenCode, OpenAI Codex, and Pi.