Skip to main content
Glama
README.md
# BlazingCDN MCP Server

Official [Model Context Protocol](https://modelcontextprotocol.io) server for [BlazingCDN](https://blazingcdn.com). Lets AI agents (Claude, Cursor, Windsurf and any other MCP client) manage your CDN: list and configure resources, purge and warm up cache, query traffic metrics, manage custom domains, cloud storage and the Video CDN.

BlazingCDN is a CDN for video, software & sports media — best for videos, streaming (HLS/DASH), software distribution, games and updates, images, audio, archives and other large files. Built for high-volume projects pushing **5 TB+ per month**.

## Highlights

- **52 tools** covering Anycast CDN, cache operations, metrics, custom domains, Cloud Storage and Video CDN
- **Safe by default** — starts in read-only mode (plus cache purge/warmup); create/update and delete operations are opt-in via environment flags
- **No install required** — runs with `npx`
- Talks directly to the BlazingCDN API (`wapi.blazingcdn.com`) with your API token; nothing else sits in between

## Getting an account and API token

1. **Sign up at [blazingcdn.com](https://blazingcdn.com/)** — every new account starts with a **14-day trial**. The trial is time-limited only: there is no free traffic included, traffic used during the trial is billed at the regular **$5/TB** rate.
2. **Top up your balance** with at least **$10** right after signing up so your account doesn't go negative while you test.
3. **Create an API access token**: in the [BlazingCDN panel](https://client.blazingcdn.com/api) open **API** → *create new API credentials* (or `POST /api/v1/access_tokens`).

### Pricing (Flex plan)

After the trial you are on the pay-as-you-go Flex plan with a **$25/month minimum, which covers your first 5 TB**. Traffic is billed on a progressive scale:

| Monthly traffic | Price per TB |
|---|---|
| First 5 TB | $5.00 |
| 5–25 TB | $4.50 |
| 25–100 TB | $4.00 |
| 100–500 TB | $3.50 |
| 500–1000 TB | $3.00 |
| 1000–1500 TB | $2.50 |

All plans include custom domains, unlimited requests, origin shield, URL signatures, free SSL and geo allow/block lists — no per-feature surcharges. **Pushing more than 100 TB/month?** [Contact BlazingCDN](https://blazingcdn.com/sign-up-contact-form/) to request custom volume pricing.

## Quick start

### Claude Desktop — one-click install (no terminal needed)

Download the latest `.mcpb` bundle from [Releases](https://github.com/BlazingCDN/BlazingCDN-MCP/releases/latest) and double-click it — Claude Desktop asks for your API token and shows two checkboxes: **Allow changes** (create and change CDN settings) and **Allow deleting** (custom domains and Video CDN resources). Both are off by default, so the server starts read-only. Node.js is not required.

### Claude Code

```bash
claude mcp add blazingcdn --env BLAZINGCDN_API_TOKEN=your-token -- npx -y @blazingcdn/mcp
```

### Claude Desktop / Cursor / Windsurf

Add to your MCP configuration (`claude_desktop_config.json`, `.cursor/mcp.json`, etc.):

```json
{
  "mcpServers": {
    "blazingcdn": {
      "command": "npx",
      "args": ["-y", "@blazingcdn/mcp"],
      "env": {
        "BLAZINGCDN_API_TOKEN": "your-token"
      }
    }
  }
}
```

Running from GitHub instead of npm also works: replace `"args"` with `["-y", "github:BlazingCDN/BlazingCDN-MCP"]`.

## Configuration

| Environment variable | Required | Description |
|---|---|---|
| `BLAZINGCDN_API_TOKEN` | yes | API access token (Bearer) |
| `BLAZINGCDN_API_URL` | no | API base URL, default `https://wapi.blazingcdn.com` |
| `BLAZINGCDN_ALLOW_WRITE` | no | `1` enables create/update tools |
| `BLAZINGCDN_ALLOW_DELETE` | no | `1` enables delete tools (`delete_custom_domain`, `delete_vcdn_resource`) |

### Permission model

| Mode | Tools | What agents can do |
|---|---|---|
| default | 29 | Read everything + purge/warm up cache |
| `BLAZINGCDN_ALLOW_WRITE=1` | 50 | …plus create/update CDN resources, domains, buckets, Video CDN |
| …`+ BLAZINGCDN_ALLOW_DELETE=1` | 52 | …plus delete custom domains and vCDN resources |

Deleting CDN resources (pull zones), buckets, external storages, accounts or users is **not implemented at all** — those operations cannot be triggered through this server in any mode.

### When a feature is switched off

Every setting this server can change is also a switch in the [customer panel](https://client.blazingcdn.com). If you ask for something that is off on your resource — image processing, HLS/DASH support, origin shield — the agent tells you exactly where to flip it (`client.blazingcdn.com/anycast_cdn/<resource_id>/<tab>`), or, with `BLAZINGCDN_ALLOW_WRITE=1`, offers to turn it on for you and waits for your confirmation.

## Tools

### Anycast CDN
| Tool | Description |
|---|---|
| `list_cdn_resources` | List all CDN resources (pull zones) |
| `get_cdn_resource` | Full settings of one resource |
| `purge_cache` | Purge everything or specific URLs; works per-resource or across resources by URL |
| `warmup_cache` | Pre-fetch paths into the cache (per compression method) |
| `get_cdn_metrics` | Bandwidth, cache hit, requests, HTTP codes, traffic — by day/hour/minute, filter by region/domain |
| `get_prometheus_metrics` | Prometheus-format metrics for monitoring |
| `create_cdn_resource` ✏️ | Create a pull zone (origin, bucket or external storage) |
| `update_cdn_resource` ✏️ | TTLs, compression, origin shield, HTTPS, access protection, HLS/DASH, image processing, Locations Mode, … |
| `bulk_update_cdn_resources` ✏️ | Same settings on several resources |
| `update_cdn_locations` ✏️ | Per-path cache rules and image presets (needs Locations Mode `extended`) |

### Domains & DNS
| Tool | Description |
|---|---|
| `list_custom_domains` / `search_custom_domains` | Domains of a resource / match domains account-wide |
| `list_system_dns_zones` | System DNS zones for CDN hostnames |
| `add_custom_domain` ✏️ / `update_custom_domain` ✏️ | Attach domains, manage SSL (auto SSL / certificate) |
| `delete_custom_domain` 🗑️ | Remove a custom domain |

### Cloud Storage
`list_buckets`, `get_bucket`, `get_bucket_metrics`, `get_storage_info`, `create_bucket` ✏️, `update_bucket` ✏️, `list_external_storages`, `get_external_storage`, `create_external_storage` ✏️, `update_external_storage` ✏️, `test_external_storage_connection` ✏️

A bucket used as a CDN resource origin must be of type `cdn` — `create_bucket` creates that type by default (`private` buckets cannot be attached to a pull zone). Pass `protocol: "s3"` for an S3-compatible bucket; the protocol cannot be changed after creation.

### Video CDN
`list_vcdn_resources`, `get_vcdn_resource`, `get_vcdn_statistics` (totals, timeseries, by domain, top domains, HTTP codes, bandwidth, cache/storage), `list_vcdn_domains`, `get_vcdn_domain`, `list_vcdn_files`, `get_vcdn_files_total`, `list_ftp_logins`, `list_auto_imports`, `get_vcdn_proxy`, `get_vcdn_ftp_settings`, `get_vcdn_settings`, `create_vcdn_resource` ✏️, `update_vcdn_resource` ✏️, `create_vcdn_domain` ✏️, `update_vcdn_domain` ✏️, `upload_vcdn_file` ✏️, `manage_auto_import` ✏️, `update_vcdn_proxy` ✏️, `update_vcdn_ftp_settings` ✏️, `manage_ftp_login` ✏️, `update_vcdn_settings` ✏️, `delete_vcdn_resource` 🗑️

### Docs & pricing
`search_docs` — search BlazingCDN documentation and product pages.
`estimate_traffic_cost` — calculate the monthly Flex-plan cost for a given traffic volume (progressive tiers, offline).

✏️ requires `BLAZINGCDN_ALLOW_WRITE=1` · 🗑️ requires `BLAZINGCDN_ALLOW_DELETE=1`

## Example prompts

- *"What's my CDN bandwidth this month, broken down by day?"*
- *"Purge `/images/*` on the blazingcdn.com resource"*
- *"Create a CDN resource for origin https://example.com and attach cdn.example.com with auto SSL"*
- *"Show HTTP 5xx rates for the last 24 hours per region"*
- *"Warm up /video/intro.mp4 with brotli compression"*
- *"How much would 190 TB/month cost on BlazingCDN?"*
- *"Turn on image processing for the shop-images resource and give me a 200×200 thumbnail URL for /images/iphone.jpg"*

## HTTP transport (self-hosting)

The server also speaks Streamable HTTP for remote deployments:

```bash
BLAZINGCDN_ALLOW_WRITE=1 npx -y @blazingcdn/mcp --transport http --port 8462
```

In HTTP mode the server is stateless and each request must carry the caller's BlazingCDN API token as `Authorization: Bearer <token>` (an env `BLAZINGCDN_API_TOKEN` acts as fallback). Put it behind TLS (reverse proxy) before exposing it anywhere.

## Development

```bash
npm install
npm test        # vitest
npm run build   # tsc -> dist/
npx @modelcontextprotocol/inspector node dist/index.js   # interactive inspector
```

## Privacy Policy

The server collects nothing: no telemetry, no analytics, no third-party calls. Your API token stays in process memory and is sent only to the BlazingCDN API over HTTPS. Full policy: [PRIVACY.md](PRIVACY.md) · service-level data handling: [BlazingCDN Legal Information](https://blazingcdn.com/legal-information/).

## Security notes

- The API token is read from the environment and sent only to `BLAZINGCDN_API_URL`; it is never logged. No middleman, no telemetry.
- Read-only by default; destructive operations (zone/bucket/account deletion) are not implemented in any mode.
- Tool output is truncated at 60 KB to keep agent contexts healthy.
- API requests time out after 30 s (file uploads: 5 min).

Full threat model, limitations and recommendations: [SECURITY.md](SECURITY.md).

## License

[MIT](LICENSE) © BlazingCDN

TDQS

A3.5/5.0

Scored across 29 tools

Disambiguation4/5

Most tools target a distinct resource type or action, such as listing vs getting vs searching. The only real ambiguities are list_custom_domains versus search_custom_domains and get_vcdn_files_total versus list_vcdn_files, but their descriptions sufficiently clarify the difference.

Naming Consistency4/5

The dominant pattern is verb_noun with snake_case, using list_ and get_ consistently for most resources. Minor deviations like list_ftp_logins and list_auto_imports omitting the vcdn_ prefix, and using 'statistics' instead of 'metrics', keep it from being perfectly consistent.

Tool Count3/5

29 tools is above the ideal 3-15 range and feels heavy, but the server covers multiple product families: Anycast CDN, Video CDN, Cloud Storage, external storage, docs, and pricing. Several settings getters could likely be consolidated, so the count is borderline rather than clearly excessive.

Completeness2/5

The toolset is strong for read-only inspection, metrics, cache operations, and cost estimation, but it lacks create/update/delete tools for resources, buckets, domains, external storages, and settings. Agents can diagnose and purge/warm caches but cannot perform full CDN configuration changes, which is a significant lifecycle gap.

Maintenance

ActivityMaintained
ResponsivenessUnresponsive