cloudflare-mcp
Provides tools for managing DNS records and Cloudflare Tunnels in a Cloudflare zone.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@cloudflare-mcplist all DNS records"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
cloudflare-mcp
A tiny TypeScript MCP server to manage a Cloudflare zone through the Cloudflare API: DNS records, cloudflared tunnels and Email Routing. Zone-agnostic: point it at any zone via env vars.
Requirements
Node.js 18+
A Cloudflare API token. Permissions by feature:
DNS tools →
Zone:DNS:Edit(+Zone:Readto resolve the zone by name)Tunnel tools →
Account:Cloudflare Tunnel:Edit(+Account:Account Settings:Readto auto-resolve the account id)Email Routing rules →
Zone:Email Routing Rules:Edit(:Readis enough for the read-only tools)Email Routing destinations →
Account:Email Routing Addresses:Edit
Related MCP server: Cloudflare MCP Server
Configuration
Variable | Description |
| Cloudflare API token (see permissions above) |
| The 32-char hex Zone ID or the zone name (e.g. |
| Optional. Account id for tunnel tools. Auto-resolved from the token if omitted (needs |
Copy .env.example to .env and fill it in. Never commit .env.
Scripts
npm install
npm run build # emit dist/
npm run dev # tsx src/index.ts (stdio)
npm start # node dist/index.jsTools
Tool | Description |
| List all DNS records in the zone (optional |
| Get a record by exact id, or by a name that resolves to exactly one record |
| Create a record (type, name, content, proxied, priority for MX, ttl, comment). Only A/AAAA/CNAME are proxied by default |
| Update content/proxy by exact id, or by a name plus optional type that resolves to exactly one record |
| Delete by exact id, or by a name plus optional type that resolves to exactly one record |
| List cloudflared tunnels in the account |
| Create a remotely-managed tunnel (idempotent by name); returns its run token |
| Get the run token for an existing tunnel |
| Set a tunnel's public-hostname ingress (hostname → local service) |
| Delete a tunnel by name |
| Whether Email Routing is enabled on the zone |
| Enable Email Routing; Cloudflare adds and locks its MX/SPF/DKIM records |
| The records routing needs and any problem Cloudflare sees with them |
| Disable routing and remove its records ( |
| List routing rules — which |
| Forward an address on the zone to a verified destination |
| Delete a rule by address or tag |
| Turn a rule on or off without deleting it |
| Drop, or forward to a verified destination, mail no rule matches |
| List the account's destination addresses and whether each is verified |
| Add a destination address (Cloudflare emails it a verification link) |
| Remove a destination address from the account |
Stand up a tunnel end-to-end
tunnel_create name=my-dev → returns id + token
tunnel_configure name=my-dev hostname=dev.example.com service=http://localhost:8770
dns_create type=CNAME name=dev.example.com content=<id>.cfargotunnel.com
# then run it locally (no cert.pem needed):
# TUNNEL_TOKEN=<token> cloudflared tunnel runForward an address end-to-end
email_destination_add email=you@gmail.com → verification link sent (click it)
email_rule_create address=hello destination=you@gmail.com
email_rules_list → confirm hello@example.com → you@gmail.comA destination must be verified before a rule can forward to it, and the zone
needs Email Routing enabled: email_routing_enable adds the MX/SPF/DKIM
records, email_routing_dns confirms they are in place.
Token scopes: Account · Email Routing Addresses (destinations) and
Zone · Email Routing Rules (rules, enable/disable) live in different scopes;
granting one in the wrong scope returns Authentication error (code 10000)
while everything else keeps working.
Safety semantics
DNS: names are not record identities.
dns_get,dns_update, anddns_deleteaccept an exact recordid(preferred), or a name that resolves to exactly one record; ambiguous names are rejected instead of selecting the first result. For updates/deletes, passtypewhen it is needed to make the name unique.Tunnels:
tunnel_configureandtunnel_ingressreplace the current ingress configuration. They refuse to replace existing hostname routes unlessreplace_existing=trueis passed explicitly.Email Routing:
email_rule_createchecks existing literal recipient rules and refuses to create a duplicate instead of adding another forwarding rule.email_rule_deleteandemail_rule_set_enabledrefuse an address that more than one rule matches; pass the exact tag.email_routing_disablerequiresconfirm=true.
Example (via an MCP client)
dns_list → all records
dns_get name=app.example.com → inspect one record
dns_create type=CNAME name=dev.example.com content=<tunnel-id>.cfargotunnel.com
dns_update name=dev.example.com proxied=true
dns_delete name=old.example.comUse as an MCP server
Point your MCP client at the built or dev entrypoint over stdio, passing the two env vars. Example (generic MCP config):
{
"command": "npx",
"args": ["-y", "tsx", "/absolute/path/to/cloudflare-mcp/src/index.ts"],
"env": {
"CLOUDFLARE_API_TOKEN": "<your-token>",
"CLOUDFLARE_ZONE_ID": "example.com"
}
}License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Read devices, users, keys, ACLs and DNS for a tailnet; manage devices, routes and auth keys.
Manage Koru Shield DNS filtering: profiles, rules, categories, schedules, and logs.
List Civo instances, Kubernetes clusters, networks and DNS; reboot instances, add rules.
Manage Cronitor monitors and send telemetry pings — list, inspect, create, update, delete.
Related MCP Servers
- AlicenseBqualityDmaintenanceExposes Cloudflare DNS, security, redirects and zone-settings functionality as structured tools that AI assistants like Claude Desktop can invoke directly.1841 npmMIT
- AlicenseAqualityCmaintenanceEnables AI assistants to manage Cloudflare resources through natural language, including DNS records, zone management, Workers KV storage, cache purging, and analytics. Supports comprehensive Cloudflare operations with secure API token authentication.132MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to interact with the Cloudflare REST API for managing DNS records, zones, and other Cloudflare resources.MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to manage Cloudflare DNS records, including listing zones and records, and creating, updating, or deleting DNS records.41 npmMIT