cloudflare-mcp
Provides tools for managing Cloudflare zones, DNS records, and cache purging, plus a passthrough to any Cloudflare API v4 endpoint.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@cloudflare-mcplist DNS records for example.com"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
cloudflare-mcp
A zero-dependency Model Context Protocol server for Cloudflare. It exposes typed tools for DNS, zones, and cache, plus a universal passthrough to any Cloudflare API v4 endpoint. Destructive operations are gated behind an explicit confirmation.
Single file, no npm dependencies, Node 18+.
Design
Most infrastructure MCP servers pull in a framework, a build step, and a tree of transitive dependencies. This one is a single index.mjs — small enough to read in full and audit before granting write access to your DNS. Two decisions shape it:
Typed convenience tools over a universal escape hatch. Cloudflare's API v4 has hundreds of endpoints; wrapping all of them is pointless churn. The common paths (DNS and cache) get first-class tools with schemas;
cf_requestcovers everything else, so a caller is never blocked by a missing wrapper.Confirmation on destructive actions.
cf_dns_deleteandcf_purge_cache { everything: true }return a refusal unlessconfirm: trueis passed. The refusal comes back as structured data rather than an exception, so the caller can see why and retry deliberately.
Zone arguments accept either a domain name (example.com) or a 32-character zone id; names are resolved to ids and cached per process.
Related MCP server: cloudflare-api-mcp
Tools
Tool | Purpose | Confirm |
| Call any Cloudflare API v4 endpoint ( | — |
| Verify the API token and report its status | — |
| List all zones with ids and status | — |
| List DNS records for a zone | — |
| Create a DNS record | — |
| Update a DNS record by id (PATCH — changed fields only) | — |
| Delete a DNS record by id | required |
| Purge specific | required (everything) |
Configuration
Create an API token at https://dash.cloudflare.com/profile/api-tokens with the scopes you need — typically:
Zone → DNS → Edit
Zone → Zone → Read
Zone → Cache Purge → Purge
Provide it via the environment or a local .env (copy .env.example):
CLOUDFLARE_API_TOKEN=...
CLOUDFLARE_ACCOUNT_ID= # optional — scopes cf_list_zones to one accountPrecedence: process environment, then .env in the working directory, then .env beside index.mjs.
Client setup
Claude Code:
claude mcp add cloudflare -- npx @habib1/cloudflare-mcpAny client that reads a JSON config:
{
"mcpServers": {
"cloudflare": {
"command": "npx",
"args": ["@habib1/cloudflare-mcp"],
"env": { "CLOUDFLARE_API_TOKEN": "..." }
}
}
}From a local clone, use "command": "node" with an absolute path to index.mjs.
Examples
// Point a subdomain at a host, proxied through Cloudflare
cf_dns_create { "zone": "example.com", "type": "A", "name": "app", "content": "203.0.113.10", "proxied": true }
// List MX records
cf_dns_list { "zone": "example.com", "type": "MX" }
// Delete a record — confirmation required
cf_dns_delete { "zone": "example.com", "id": "...", "confirm": true }
// Anything without a dedicated wrapper — e.g. read a zone's SSL setting
cf_request { "method": "GET", "path": "/zones/{zone_id}/settings/ssl" }Operational notes
Reads and verification never require confirmation. Writes happen on request; the reliable pattern is to write, then re-read with cf_dns_list to confirm. Deletes and full-cache purges return { "refused": ... } unless confirm: true is passed.
Scope the token to only the zones and permissions required — the server can do exactly what the token allows, and no more.
Development
npm run smokeSpawns the server, drives the JSON-RPC handshake, and checks the tool surface. Passes without a token; additionally exercises cf_verify when CLOUDFLARE_API_TOKEN is set.
License
This server cannot be deployed
Maintenance
Related MCP Connectors
Validates domain email MX records and DNS status via Cloudflare DNS-over-HTTPS.
11Read devices, users, keys, ACLs and DNS for a tailnet; manage devices, routes and auth keys.
Deploy and manage applications, databases, domains, and git repos
Manage repositories, users, releases, and automate GitHub workflows
Related MCP Servers
- AlicenseBqualityDmaintenanceExposes Cloudflare DNS, security, redirects and zone-settings functionality as structured tools that AI assistants like Claude Desktop can invoke directly.1841 npmMIT
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to interact with the Cloudflare REST API for managing DNS records, zones, and other Cloudflare resources.MIT
- AlicenseBqualityBmaintenanceA local stdio MCP server that provides 69 tools for Cloudflare REST API v4, including DNS, Zones, Workers, KV, R2, D1, Pages, Queues, Tunnels, SSL, WAF, Email Routing, Logpush and Workers AI, authenticated by a single API token.6931 npm3MIT
- AlicenseAqualityCmaintenanceCloudflare DNS MCP server. Manage zones, DNS records, cache, and page rules from Claude, Cursor, Codex, or any MCP-compatible AI assistant.10MIT