Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
CLOUDFLARE_ZONE_IDNoOptional default zone ID when using the single global profile.
CLOUDFLARE_ACCOUNTSNoPrivate JSON array of explicit named profiles; no global credential/default inheritance.
CLOUDFLARE_API_TOKENNoPrivate Bearer API token; no Global API Key support.
CLOUDFLARE_AUDIT_LOGNoOptional private append-only metadata path.
CLOUDFLARE_READ_ONLYNo1/true hides/refuses every mutation.
CLOUDFLARE_ACCOUNT_IDNoOptional default account ID when using the single global profile.
CLOUDFLARE_TOKEN_FILENoAbsolute regular owner-only token-only file; max 64 KiB; takes precedence over CLOUDFLARE_API_TOKEN.
CLOUDFLARE_TOKEN_KINDNouser (default) or account; doctor verification route only.user
CLOUDFLARE_DEFAULT_ACCOUNTNoExact profile name; first profile default when omitted.
CLOUDFLARE_ALLOW_DESTRUCTIVENo0/false refuses confirmed mutations; otherwise enabled.
CLOUDFLARE_REQUEST_TIMEOUT_MSNoDefault 30000; integer 100–300000; no automatic retry.30000
CLOUDFLARE_MIN_REQUEST_INTERVAL_MSNoDefault 200; integer 0–10000; per profile/process.200

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
list_provider_accountsB

List all accounts you have ownership or verified access to. Read operation.

list_zonesA

Lists, searches, sorts, and filters your zones. Listing zones across more than 500 accounts is currently not allowed. Read operation.

get_zoneB

Retrieves detailed information about a specific zone identified by its zone ID.

Returns zone configuration, status, nameservers, and associated metadata. Read operation.

list_dns_recordsC

List, search, sort, and filter a zones' DNS records. Read operation.

get_dns_recordC

Retrieves details for a specific DNS record in the zone. Read operation.

create_dns_recordA

Create a new DNS record for a zone.

Notes:

  • A/AAAA records cannot exist on the same name as CNAME records.

  • NS records cannot exist on the same name as any other record type.

  • Domain names are always represented in Punycode, even if Unicode characters were used when creating the record. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

update_dns_recordB

Update an existing DNS record.

Notes:

  • A/AAAA records cannot exist on the same name as CNAME records.

  • NS records cannot exist on the same name as any other record type.

  • Domain names are always represented in Punycode, even if Unicode characters were used when creating the record. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

overwrite_dns_recordA

Overwrite an existing DNS record.

Notes:

  • A/AAAA records cannot exist on the same name as CNAME records.

  • NS records cannot exist on the same name as any other record type.

  • Domain names are always represented in Punycode, even if Unicode characters were used when creating the record. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

delete_dns_recordA

Permanently removes a DNS record from the zone. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

batch_dns_recordsB

Send a Batch of DNS Record API calls to be executed together.

Notes:

  • Although Cloudflare will execute the batched operations in a single database transaction, Cloudflare's distributed KV store must treat each record change as a single key-value pair. This means that the propagation of changes is not atomic. See the documentation for more information.

  • The operations you specify within the /batch request body are always executed in the following order:

    • Deletes

    • Patches

    • Puts

    • Posts Every change requires explicit confirmation; never repeat an unknown outcome automatically.

purge_cacheA

Deletes cached content in every Cloudflare data center and cache tier, including Cache Reserve. The next request for purged content is a cache MISS: Cloudflare fetches the full response from your origin and caches it again. Cloudflare does not serve purged content from cache again, even if your origin is unavailable.

To keep content cached and have Cloudflare revalidate it with your origin instead, use POST /zones/{zone_id}/invalidate_cache.

Choose what to purge

Send one of these fields in the request body:

  • files: specific URLs. If your cache key includes request headers, send each URL with the header values it was cached with.

  • tags: all content whose Cache-Tag response header contains one of the tags.

  • hosts: all content cached for the hostnames.

  • prefixes: all content whose URL starts with one of the prefixes.

  • purge_everything: all cached content in the zone.

Check the result

A 200 response with success: true means Cloudflare accepted the request. It does not confirm that any content was cached or removed. To check, request a purged URL and confirm that the CF-Cache-Status response header is MISS.

Availability and limits

Rate limits and the number of items you can send in one request depend on your plan. See Purge cache: availability and limits. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

get_zone_settingC

Fetch a single zone setting by name Read operation.

update_zone_settingB

Updates a single zone setting by the identifier Every change requires explicit confirmation; never repeat an unknown outcome automatically.

list_workersC

Fetch a list of uploaded Worker scripts. Read operation.

list_zone_rulesetsC

Fetches all rulesets at the zone level. Read operation.

get_zone_rulesetC

Fetches the latest version of a zone ruleset. Read operation.

get_zone_entrypointC

Fetches the latest version of the zone entry point ruleset for a given phase. Read operation.

create_zone_rulesetB

Creates a ruleset at the zone level. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

update_zone_rulesetA

Updates a zone ruleset, creating a new version. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

delete_zone_rulesetA

Deletes all versions of an existing zone ruleset. Every change requires explicit confirmation; never repeat an unknown outcome automatically.

list_page_rulesC

Fetches Page Rules in a zone. Read operation.

get_page_ruleB

Fetches the details of a Page Rule. Read operation.

list_accountsC

Local profile labels/default/auth method only. No provider IDs, credential values or paths. No network.

get_operation_schemaC

Complete selected current API input, path and query schema. Local metadata only.

preview_operationA

Validate a named operation and return its exact local method/path/query/body/profile. No request, auth validation or provider policy checks.

query_pagesB

Read at most five pages of a supported paginated named operation. Provider page metadata determines continuation; missing metadata stops with an explicit unknown continuation.

preview_dns_batchB

Local schema-validated DNS batch review capped at 50 actions. Digest binds exact JSON body, zone path and profile label; no account or DNS state read. Not a provider authorization grant.

apply_dns_batchA

Verify the reviewed digest and submit one exact native DNS batch with mandatory confirmation. Does not assert remote-state consistency or atomic DNS propagation; no retry.

analytics_queryB

One parsed GraphQL query only, with variables. No mutations, subscriptions or multiple operations. Permissions, dataset retention, sampling and query limits remain provider controlled.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

C2.9/5.0

Scored across 29 tools

Disambiguation3/5

Most tools target distinct Cloudflare resources and actions, but several overlapping pairs create confusion: update_dns_record vs overwrite_dns_record, batch_dns_records vs apply_dns_batch, preview_dns_batch vs preview_operation, and list_accounts vs list_provider_accounts. Descriptions help somewhat, but an agent could still misselect among batch/preview/apply tools.

Naming Consistency4/5

Nearly all tools use snake_case verb_noun naming such as create_dns_record, list_zones, and delete_zone_ruleset. Minor deviations like analytics_query and batch_dns_records slightly break the pattern, but the set remains predictable overall.

Tool Count2/5

With 29 tools, the server is heavy for a single MCP surface. While Cloudflare is a broad platform, the count exceeds the typical well-scoped range of 3-15 and includes several specialized or overlapping operations that could be consolidated.

Completeness3/5

DNS records and zone rulesets have strong CRUD coverage, but other apparent domains are incomplete: Page Rules only support get/list, Workers only list, and zones lack create/delete operations. These gaps are notable but not fatal for common DNS and ruleset workflows.

Maintenance

ActivityMaintained
ResponsivenessNo issues