CF ActivityPub MCP
Allows administering a CF ActivityPub Next instance through its administration API, exposing 30 tools to manage accounts and moderation (approve, silence, suspend, delete, verify), abuse reports, federation rules (domain blocks, instance registry, relays), content policy (licenses, custom emojis, announcements), instance settings and registration policy, media cache, email blocks, and the moderation audit log.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@CF ActivityPub MCPlist the open reports on my instance and show the most recent one"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
CF ActivityPub MCP
English | Español
A remote Model Context Protocol server that lets AI assistants administer a CF ActivityPub instance through its administration API — fully hosted on Cloudflare Workers.
Overview
CF ActivityPub MCP is the administration companion for CF ActivityPub Next, the Mastodon-compatible ActivityPub server built for Cloudflare Workers.
Point it at your instance with the same ADMIN_TOKEN operator secret, connect any MCP-capable assistant, and manage accounts, reports, federation rules, relays, media cache, settings and more through natural conversation. The worker:
Exposes the full administration surface as 30 well-described MCP tools.
Speaks Streamable HTTP (
/mcp, JSON responses) and an SSE-shaped endpoint (/sse) for clients that require it.Requires its own bearer token (
MCP_AUTH_TOKEN) on every MCP request, independent from the instance token.Publishes a public landing page and a
/healthJSON report with live metrics.Runs with Cloudflare observability (traces, logs and real-time issues) enabled.
Deploys to a custom domain with a single
wrangler deploy.
The MCP never stores instance data: every tool call is a thin, authenticated proxy to the CF ActivityPub admin API, which keeps its own audit trail.
Related MCP server: BYOB MCP Server
Architecture
Layer | Technology |
Runtime | Cloudflare Workers |
MCP transport | Agents SDK |
Protocols | Streamable HTTP + SSE response shaping, JSON-RPC 2.0 |
Authentication | Bearer token ( |
Upstream | CF ActivityPub admin API ( |
Observability | Workers Logs, Traces and Issues |
Language | TypeScript, Zod schemas |
Endpoints
Path | Method | Auth | Description |
| GET | Public | Landing page with live health metrics |
| GET | Public | JSON health report (worker + instance) |
| POST | Bearer | Streamable HTTP MCP endpoint; JSON by default, SSE when needed |
| POST | Bearer | SSE-shaped MCP endpoint for SSE-first clients |
| OPTIONS | Public | CORS preflight handled by the MCP handler |
Modern protocol revisions (2026-07-28) receive JSON responses; legacy clients are served through the stateless compatibility lane. The deprecated HTTP+SSE session transport (a long-lived GET /sse stream plus POST /messages) is intentionally not implemented — point legacy clients at /mcp (or use a proxy such as mcp-remote).
Requirements
A deployed CF ActivityPub Next instance with
ADMIN_TOKENconfigured (wrangler secret put ADMIN_TOKENin that project).A Cloudflare account with the domain you want to use.
Node.js 20+ and npm.
Quick start
# 1. Install dependencies
npm install
# 2. Configure the instance URL (and optionally the custom domain)
# Edit `vars` in wrangler.jsonc: ACTIVITYPUB_URL=https://social.example.com
# 3. Create the two secrets
npx wrangler secret put ADMIN_TOKEN # same value as the instance's ADMIN_TOKEN
npx wrangler secret put MCP_AUTH_TOKEN # openssl rand -hex 32
# 4. Local development
npm run dev
# 5. Deploy
npm run deployFor local development, copy .dev.vars.example to .dev.vars and fill in both tokens.
Configuration
Plain-text variables (vars in wrangler.jsonc)
Variable | Required | Description |
| Yes | Public base URL of the CF ActivityPub instance, e.g. |
| No | Name reported by the MCP server (default |
| No | Version reported by the MCP server (default |
| No | Comma-separated Host allowlist for the MCP endpoints. Localhost and |
| No | Comma-separated browser Origin allowlist, or |
Secrets (wrangler secret put)
Secret | Description |
| The operator secret of the CF ActivityPub instance. Grants full administrator access to its API |
| Bearer token that MCP clients must present on |
Authentication
Two independent credentials are involved:
MCP clients → this worker. Every request to
/mcpor/ssemust includeAuthorization: Bearer <MCP_AUTH_TOKEN>. Requests are rejected with401otherwise, and the endpoint is closed with503when the secret is not configured. Token comparison hashes both values before comparing to avoid timing leaks.This worker → the ActivityPub instance. Tool calls send
Authorization: Bearer <ADMIN_TOKEN>to the instance admin API. The instance validates it with its ownadmin-authlogic and writes every mutation to the moderation log.
Rotate each token independently: changing MCP_AUTH_TOKEN only affects MCP access; changing ADMIN_TOKEN must be done in both workers.
Connecting an MCP client
Claude Desktop (via mcp-remote)
{
"mcpServers": {
"cf-activitypub": {
"command": "npx",
"args": [
"mcp-remote",
"https://mcp.example.com/mcp",
"--header",
"Authorization: Bearer <MCP_AUTH_TOKEN>"
]
}
}
}Clients with native remote transport (Cursor, VS Code, others)
{
"mcpServers": {
"cf-activitypub": {
"url": "https://mcp.example.com/mcp",
"headers": {
"Authorization": "Bearer <MCP_AUTH_TOKEN>"
}
}
}
}Use https://mcp.example.com/sse instead of /mcp when a client explicitly requires an SSE endpoint.
MCP Inspector
npx @modelcontextprotocol/inspector
# Transport: Streamable HTTP
# URL: https://mcp.example.com/mcp
# Header: Authorization: Bearer <MCP_AUTH_TOKEN>Tools
The server exposes 30 tools, grouped by administrative domain. Destructive actions (delete, reject, suspend, demote, purge, clear_all, remove, dismiss) require an explicit confirm: true argument, so an assistant cannot destroy data by accident.
Overview and health
Tool | Description |
| Reachability and latency of the instance plus its public metadata |
| Full public instance payload (version, languages, limits, registration policy) |
| Combined summary: metadata, account/report/moderation/federation/relay totals and media cache stats |
Instance settings
Tool | Description |
| Rules, policies, languages and registration settings |
| Updates any subset of the settings above |
Accounts and moderation
Tool | Description |
| Search/filter local and remote accounts (status, role, locality, query) |
| One account with moderation flags, role and profile |
| approve, unapprove, reject, silence, unsilence, suspend, unsuspend, promote, demote, delete |
| Forces a |
| Federated search for accounts, statuses, hashtags and collections |
Reports
Tool | Description |
| Abuse reports with statuses, accounts and notes |
| One report ticket |
| resolve, dismiss, reopen, delete, add_note |
Federation
Tool | Description |
| Instance-wide domain blocks |
| block / unblock a domain (severity, media/report rejection, comments) |
| Federation registry with status filters |
| add, refresh, reset, suspend, unsuspend, purge |
| Subscribed ActivityPub relays |
| add, enable, disable, remove |
Content and policy
Tool | Description |
| License catalogue (FEP-6757) |
| add, update, delete |
| Custom emojis, including disabled ones |
| upload (URL or base64), enable/disable, delete |
| create / delete instance announcements |
Operations
Tool | Description |
| Cache statistics, most served entries and effective config |
| enforce_budget, purge |
| Blocked mailboxes (canonical email hashes) |
| block / unblock a mailbox |
| Audit trail with target/action filters |
| delete_entry, clear_all |
Known limitations
manage_reportwithaction: "add_note"needs an OAuth token owned by a local actor; the sharedADMIN_TOKENcannot author notes and the instance answers401.Announcement listing is actor-only on the instance, so this MCP can create and delete announcements but not list them.
The MCP never exposes the instance database directly; it is limited to what the admin API supports.
Health and landing page
GET /renders a public landing page linking to both repositories and showing live metrics (worker status, instance status, latency, active users, tool count).GET /healthreturns the same data as JSON, suitable for uptime monitors:
{
"status": "ok",
"service": { "name": "cf-activitypub-mcp", "version": "1.0.0", "tools": 30, "authentication": "bearer" },
"instance": { "url": "https://social.example.com", "reachable": true, "latency_ms": 42, "users": 128 }
}No secrets or administrative details are exposed by either endpoint.
Security
Fail closed. MCP endpoints refuse to serve when
MCP_AUTH_TOKENis missing.Least privilege. The MCP only knows the instance admin API; it cannot reach Cloudflare account resources.
Auditability. Every mutation performed through the MCP is recorded by the instance in its moderation log.
Confirmation guards. Destructive tools require
confirm: true; the model must be told explicitly.Constant-time token comparison. Candidate and expected tokens are hashed and compared with an XOR accumulator.
Origin/Host allowlists. Optional
MCP_ALLOWED_ORIGINS/MCP_ALLOWED_HOSTNAMESrestrict browser and Host access.Source maps.
upload_source_mapskeeps stack traces readable in the dashboard without shipping them to clients.
If you find a security issue, please open a private report through GitHub rather than a public issue.
Development
Script | Purpose |
| Start the local Workers dev server |
| Deploy to Cloudflare (custom domain from |
| Run the Vitest suite inside the Workers runtime |
| Watch mode |
| Strict TypeScript check |
| Regenerate |
Project structure
src/
index.ts Worker entry: routing, auth, endpoints
config.ts Environment parsing and defaults
auth.ts Bearer authentication and secret comparison
activitypub/
client.ts Authenticated client for the instance API
types.ts Shared API payload shapes
mcp/
server.ts MCP server factory and tool catalogue
context.ts Per-request tool context (lazy clients)
result.ts Tool result helpers
tools/ One module per administrative domain
web/
health.ts Health report collection
index-page.ts Public landing page renderer
test/
index.spec.ts Worker routes and MCP protocol tests
config.spec.ts Config and auth unit testsDeployment notes
Set
routes[0].patterninwrangler.jsoncto your subdomain (for examplemcp.example.com). Wrangler creates the DNS record and certificate automatically on deploy.Set
ACTIVITYPUB_URLto the public URL of your instance.Configure both secrets with
wrangler secret put.Run
npm run deploy, then openhttps://mcp.example.com/to verify the health metrics.Observability is already enabled: traces, logs and real-time issues are available in the Cloudflare dashboard under the worker's Observability tab.
The worker requires no Durable Objects, KV, R2 or D1 bindings — it is stateless and works entirely through the instance API.
License
MIT © 2026 manalejandro
CF ActivityPub MCP is not affiliated with Cloudflare, Inc. or the Mastodon project. The author is not responsible for the use of this software, nor for any charges Cloudflare may apply.
This server cannot be deployed
Maintenance
Related MCP Connectors
OAuth 2.1 short-link tools for AI agents with scoped tokens, approvals, audit logs, and revocation.
Self-hosted AI prompt library: prompts, collections, tags, teams, chains. 29 MCP tools for agents.
Hosted AI agents and workflows with app OAuth, human approval gates, and a run ledger.
The bridge from K2 agents through Wrangler to your master AI - safe, approval-gated Cloudflare ops.
Related MCP Servers
- AlicenseAqualityCmaintenanceEnables AI assistants to manage Cloudflare resources through natural language, including DNS records, zone management, Workers KV storage, cache purging, and analytics. Supports comprehensive Cloudflare operations with secure API token authentication.132MIT
- FlicenseNot gradedqualityDmaintenanceEnables AI agents to dynamically discover and invoke containerized tools that can be registered at runtime without redeployment. Built on Cloudflare Workers with scale-to-zero containers for secure, isolated tool execution.-
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to manage Coolify infrastructure including servers, applications, databases, deployments, and 80+ one-click services through 98 comprehensive tools for both cloud and self-hosted instances.MIT
- AlicenseNot gradedqualityDmaintenanceAn MCP server that gives AI agents full admin control over Discord servers with 59 tools for messaging, moderation, roles, channels, forums, reactions, files, and more, deployed on Cloudflare Workers.4MIT