Skip to main content
Glama
oborseth

Official Porkbun MCP Server

Set Cloudflare Zone Settings

set_cloudflare_zone_settings
DestructiveIdempotent

Update Cloudflare zone settings for a moved domain, including SSL, HTTPS rewrites, TLS version, development mode, and cache level, with a dry run option.

Instructions

Change Cloudflare zone settings for a moved domain. Only an allowlist is editable (ssl, always_use_https, automatic_https_rewrites, min_tls_version, development_mode, cache_level) — WAF/firewall/security controls are deliberately not exposed. Prefer ssl full over flexible: flexible makes Cloudflare fetch the origin over plain HTTP, a downgrade the visitor cannot see. CLOUDFLARE_REAUTHORIZE_REQUIRED means the stored authorization lacks this permission — surface the connectUrl and ask the customer to reconnect. Supports dry_run.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
sslNoTLS mode between Cloudflare and the origin. `full` is the safe default.
domainYesDomain whose zone settings to change.
dry_runNo
cache_levelNo
min_tls_versionNo
always_use_httpsNo
development_modeNoTemporarily bypass Cloudflare's cache.
automatic_https_rewritesNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.39.4

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already flag this as a destructive, idempotent, non-open-world mutation; the description adds substantial context beyond that: the exact editable allowlist, the deliberate omission of security controls, the HTTP-downgrade risk of `flexible` ssl, dry_run support, and a specific error-code remediation flow.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Dense but every clause carries information: scope, exclusion, preference, error handling, dry_run. Front-loaded with the verb and allowlist, though the em-dash run-on makes it slightly harder to scan than a clean multi-sentence form.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a mutation tool with no output schema, the description covers what can change, what cannot, safety preferences, and auth failure recovery, with annotations carrying the destructive/idempotent profile. Only the dry_run behavior and the response/result of a change remain unstated.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 38%, but the description names all six editable settings and the ssl enum rationale, which maps to the actual parameters and compensates for most of the gap. dry_run is mentioned only as 'Supports dry_run' without explaining its semantics, leaving one loose end.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Change) plus resource (Cloudflare zone settings) and immediately scopes it to an allowlist of six named settings while explicitly excluding WAF/firewall/security controls. This distinguishes it cleanly from siblings get_cloudflare_zone_settings, set_cloudflare_proxy, and the record-level tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives actionable guidance on picking ssl values (prefer `full` over `flexible`) and on handling CLOUDFLARE_REAUTHORIZE_REQUIRED by surfacing connectUrl. It lacks an explicit statement of when to use this vs. the read-only get_cloudflare_zone_settings or when to prefer a record-level tool, so it stops short of full routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools