@kodim/mcp-cloudflare-dns
# @kodim/mcp-cloudflare-dns
MCP server for managing and analyzing Cloudflare DNS — zones, records, analytics, and DNSSEC.
## Installation
### Claude Code
Add to your Claude Code MCP settings (`.claude/settings.local.json` or global settings):
```json
{
"mcpServers": {
"cloudflare-dns": {
"command": "npx",
"args": ["-y", "@kodim/mcp-cloudflare-dns"],
"env": {
"CLOUDFLARE_API_TOKEN": "your-cloudflare-api-token"
}
}
}
}
```
### Cursor / Other MCP Clients
```json
{
"mcpServers": {
"cloudflare-dns": {
"command": "npx",
"args": ["-y", "@kodim/mcp-cloudflare-dns"],
"env": {
"CLOUDFLARE_API_TOKEN": "your-cloudflare-api-token"
}
}
}
}
```
## Cloudflare API Token
Create an API token at [Cloudflare Dashboard](https://dash.cloudflare.com/profile/api-tokens).
**Required permissions:**
- **Zone** — Read
- **DNS** — Edit
- **Analytics** — Read (for analytics tools)
You can use the "Edit zone DNS" template as a starting point and add Analytics read permission.
## Tools
### Zones
| Tool | Description |
|------|-------------|
| `list_zones` | List all DNS zones. Filter by name, status. |
| `get_zone` | Get full details of a zone by ID. |
### DNS Records
| Tool | Description |
|------|-------------|
| `list_dns_records` | List records with filters (type, name, content, proxied, search, tag). |
| `get_dns_record` | Get details of a specific record. |
| `create_dns_record` | Create a record (A, AAAA, CNAME, MX, TXT, SRV, etc.). |
| `update_dns_record` | Partially update an existing record. |
| `delete_dns_record` | Permanently delete a record. |
### Bulk Operations
| Tool | Description |
|------|-------------|
| `batch_dns_records` | Create, update, and delete multiple records in one call. |
| `export_dns_records` | Export all records in BIND format (for backups). |
| `import_dns_records` | Import records from BIND format content. |
### Analytics
| Tool | Description |
|------|-------------|
| `get_dns_analytics` | Summary metrics: query count, response times, cache stats. |
| `get_dns_analytics_by_time` | Time-series analytics with configurable intervals. |
### DNSSEC
| Tool | Description |
|------|-------------|
| `get_dnssec_status` | Get DNSSEC status and DS record details. |
| `update_dnssec_status` | Enable or disable DNSSEC. |
## Development
```bash
# Install dependencies
npm install --ignore-scripts
# Build
npm run build
# Watch mode
npm run watch
# Test with MCP Inspector
CLOUDFLARE_API_TOKEN=your-token npm run dev
```
## License
MIT
TDQS
Scored across 14 tools
Each tool has a clear, distinct purpose: zone lookups, DNS record CRUD, batch operations, import/export, analytics (summary vs. time-series), and DNSSEC management. No two tools overlap ambiguously.
All tool names follow a consistent verb_noun pattern in snake_case: get_, list_, create_, update_, delete_, batch_, export_, import_, and two get_dns_ analytics variants. Conventions are uniform and predictable.
14 tools is well within the ideal 3-15 range for a domain-specific MCP server. Each tool covers a meaningful aspect of Cloudflare DNS management without redundancy or bloat.
The tool surface covers core DNS operations comprehensively: zone listing/detail, full DNS record CRUD, batch edits, BIND import/export, analytics, and DNSSEC. Minor gaps include no create_zone or update_zone, but these are peripheral for a DNS-focused server.