Cloudflare API MCP Server
Official Cloudflare MCP server that exposes the entire Cloudflare API through just two tools, complemented by a dozen product-specific MCP servers.
- Skill Road
- Cloudflare API MCP Server
Categories
Description
Cloudflare runs a catalog of managed, hosted MCP servers for your own Cloudflare account. The central Cloudflare API MCP Server exposes over 2,500 API endpoints — spanning DNS, Workers, R2, Zero Trust, and more — through just two tools: search() and execute(). Instead of defining a separate tool for every endpoint, the language model writes JavaScript against a typed representation of the OpenAPI spec; the generated code runs inside an isolated Worker sandbox. Per Cloudflare, this "Code Mode" approach uses roughly 1,000 tokens regardless of how many endpoints exist, while a classic MCP server exposing every endpoint as a native tool would consume over a million tokens.
Additional product-specific MCP servers
Alongside the API server, Cloudflare offers around a dozen focused MCP servers for individual products, each reachable under its own subdomain, including: documentation (docs.mcp.cloudflare.com), Workers Bindings (bindings.mcp.cloudflare.com), observability/logs (observability.mcp.cloudflare.com), Radar for Internet traffic data (radar.mcp.cloudflare.com), sandbox containers (containers.mcp.cloudflare.com), browser rendering (browser.mcp.cloudflare.com), AI Gateway (ai-gateway.mcp.cloudflare.com), plus audit logs, DNS analytics, and GraphQL analytics.
Also: the Cloudflare Skills plugin
For Claude Code, Cursor, OpenCode, OpenAI Codex, and other agents that support the Agent Skills standard, the cloudflare/skills plugin bundles the MCP servers together with matching skills and slash commands for working with Cloudflare.
The Code Mode approach in detail
Classic MCP servers define a separate tool with a fixed signature for every action — with over 2,500 Cloudflare API endpoints, that wouldn't be practical within the model's context window. The Code Mode approach flips this: the model receives a typed, searchable representation of the entire API and writes JavaScript code itself, which runs inside an isolated Worker sandbox. For users, this means even very specific, multi-step Cloudflare tasks — such as "update every DNS record in a given zone and log the changes" — can be handled in a single tool call instead of chaining together many individual API calls.
Who the Cloudflare MCP servers fit
The servers are particularly useful for DevOps and infrastructure teams that already actively use Cloudflare for DNS, security, or Workers deployments and want to automate recurring configuration tasks. The product-specific servers also suit focused use cases: the Radar server, for example, for analyzing Internet traffic trends, or the observability server for searching logs during troubleshooting. For a one-off, simple configuration change via the regular Cloudflare dashboard, setting up an MCP client is usually not worth the effort.
Frequently asked questions
Do I need to set up all the product-specific servers at once? No, each server can be connected independently; for most tasks, the central API server or a single focused server is enough. Does access work without OAuth? Yes, for automation an API token is available as an alternative bearer token. Are the servers limited to Zero Trust accounts? No, they work with any Cloudflare account and, depending on permissions, cover DNS, Workers, R2, Zero Trust, and other products.
Requirements
A Cloudflare account plus an MCP client that supports remote servers over HTTP and OAuth. For CI/CD use, a Cloudflare API token with the required permissions is available as an alternative.
Installation instructions
Register the remote server in your MCP client:
{
"mcpServers": {
"cloudflare-api": { "url": "https://mcp.cloudflare.com/mcp" }
}
}
On the first connection, Cloudflare's OAuth dialog opens, where you select the permissions to grant the agent. For CI/CD automation, a Cloudflare API token (user or account token) can be used as a bearer token in the Authorization header instead of OAuth.
For Claude Code, the Skills plugin is an alternative that bundles the MCP servers together with contextual skills:
/plugin marketplace add cloudflare/skills
Authentication
OAuth authorization for your own Cloudflare account, triggered from the client, where you select the permissions to grant the agent. For automation, a Cloudflare API token (user or account token) can be used as a bearer token instead.
Required access permissions
Effective access matches the permissions selected during the OAuth flow or the scopes of the API token used. Via the Code Mode approach, the agent can in principle call any of the 2,500+ Cloudflare API endpoints, limited by those permissions — from read-only analytics access to write changes to DNS, Workers, or security rules.
Transmitted or stored data
Requests run through Cloudflare-hosted infrastructure at *.mcp.cloudflare.com. The JavaScript code generated by the language model executes inside an isolated Dynamic Worker sandbox and calls the Cloudflare API from there. Responses contain configuration and analytics data from your own Cloudflare account and are returned to the MCP client and its language model.
Security risks
Since the server can write to core infrastructure such as DNS, Workers, or Zero Trust rules within the granted permissions, a misdirected agent can cause real outages or security gaps (e.g. faulty DNS changes or loosened firewall rules). Grant only the permissions actually needed during the OAuth flow, use a narrowly scoped API token instead of full account access for automated workflows, and test write actions against production infrastructure in a staging environment first.
License and costs
- License
- Apache-2.0
- Cost
- free
The MCP servers themselves are usable without a separate license fee, and the source code is open source (Apache-2.0). A Cloudflare account is required; paid Cloudflare features and plans are billed independently of the MCP servers.
Alternatives
Not recorded yet.
At a glance
- Provider
- Cloudflare
- Status
- Official server
- Deployment
- Remote
- Current version
- Not recorded yet.
- GitHub stars
- 4,323
- Last reviewed
- 07.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Set up the Asana plugin for Claude Code
Create your own Asana OAuth app, install the Claude Code plugin, and connect to Asana's V2 MCP server via /asana-setup.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Setting up the Zernio MCP Server
Connect the Zernio MCP Server via OAuth or an API key, link social accounts, and deliberately safeguard write access to posts, inboxes, and ad campaigns.
28.09.2026