Cloudflare MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CLOUDFLARE_ZONE_ID | No | Optional default zone ID when using the single global profile. | |
| CLOUDFLARE_ACCOUNTS | No | Private JSON array of explicit named profiles; no global credential/default inheritance. | |
| CLOUDFLARE_API_TOKEN | No | Private Bearer API token; no Global API Key support. | |
| CLOUDFLARE_AUDIT_LOG | No | Optional private append-only metadata path. | |
| CLOUDFLARE_READ_ONLY | No | 1/true hides/refuses every mutation. | |
| CLOUDFLARE_ACCOUNT_ID | No | Optional default account ID when using the single global profile. | |
| CLOUDFLARE_TOKEN_FILE | No | Absolute regular owner-only token-only file; max 64 KiB; takes precedence over CLOUDFLARE_API_TOKEN. | |
| CLOUDFLARE_TOKEN_KIND | No | user (default) or account; doctor verification route only. | user |
| CLOUDFLARE_DEFAULT_ACCOUNT | No | Exact profile name; first profile default when omitted. | |
| CLOUDFLARE_ALLOW_DESTRUCTIVE | No | 0/false refuses confirmed mutations; otherwise enabled. | |
| CLOUDFLARE_REQUEST_TIMEOUT_MS | No | Default 30000; integer 100–300000; no automatic retry. | 30000 |
| CLOUDFLARE_MIN_REQUEST_INTERVAL_MS | No | Default 200; integer 0–10000; per profile/process. | 200 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_provider_accountsB | List all accounts you have ownership or verified access to. Read operation. |
| list_zonesA | Lists, searches, sorts, and filters your zones. Listing zones across more than 500 accounts is currently not allowed. Read operation. |
| get_zoneB | Retrieves detailed information about a specific zone identified by its zone ID. Returns zone configuration, status, nameservers, and associated metadata. Read operation. |
| list_dns_recordsC | List, search, sort, and filter a zones' DNS records. Read operation. |
| get_dns_recordC | Retrieves details for a specific DNS record in the zone. Read operation. |
| create_dns_recordA | Create a new DNS record for a zone. Notes:
|
| update_dns_recordB | Update an existing DNS record. Notes:
|
| overwrite_dns_recordA | Overwrite an existing DNS record. Notes:
|
| delete_dns_recordA | Permanently removes a DNS record from the zone. Every change requires explicit confirmation; never repeat an unknown outcome automatically. |
| batch_dns_recordsB | Send a Batch of DNS Record API calls to be executed together. Notes:
|
| purge_cacheA | Deletes cached content in every Cloudflare data center and cache tier, including Cache Reserve. The next request for purged content is a cache To keep content cached and have Cloudflare revalidate it with your origin instead, use Choose what to purgeSend one of these fields in the request body:
Check the resultA Availability and limitsRate limits and the number of items you can send in one request depend on your plan. See Purge cache: availability and limits. Every change requires explicit confirmation; never repeat an unknown outcome automatically. |
| get_zone_settingC | Fetch a single zone setting by name Read operation. |
| update_zone_settingB | Updates a single zone setting by the identifier Every change requires explicit confirmation; never repeat an unknown outcome automatically. |
| list_workersC | Fetch a list of uploaded Worker scripts. Read operation. |
| list_zone_rulesetsC | Fetches all rulesets at the zone level. Read operation. |
| get_zone_rulesetC | Fetches the latest version of a zone ruleset. Read operation. |
| get_zone_entrypointC | Fetches the latest version of the zone entry point ruleset for a given phase. Read operation. |
| create_zone_rulesetB | Creates a ruleset at the zone level. Every change requires explicit confirmation; never repeat an unknown outcome automatically. |
| update_zone_rulesetA | Updates a zone ruleset, creating a new version. Every change requires explicit confirmation; never repeat an unknown outcome automatically. |
| delete_zone_rulesetA | Deletes all versions of an existing zone ruleset. Every change requires explicit confirmation; never repeat an unknown outcome automatically. |
| list_page_rulesC | Fetches Page Rules in a zone. Read operation. |
| get_page_ruleB | Fetches the details of a Page Rule. Read operation. |
| list_accountsC | Local profile labels/default/auth method only. No provider IDs, credential values or paths. No network. |
| get_operation_schemaC | Complete selected current API input, path and query schema. Local metadata only. |
| preview_operationA | Validate a named operation and return its exact local method/path/query/body/profile. No request, auth validation or provider policy checks. |
| query_pagesB | Read at most five pages of a supported paginated named operation. Provider page metadata determines continuation; missing metadata stops with an explicit unknown continuation. |
| preview_dns_batchB | Local schema-validated DNS batch review capped at 50 actions. Digest binds exact JSON body, zone path and profile label; no account or DNS state read. Not a provider authorization grant. |
| apply_dns_batchA | Verify the reviewed digest and submit one exact native DNS batch with mandatory confirmation. Does not assert remote-state consistency or atomic DNS propagation; no retry. |
| analytics_queryB | One parsed GraphQL query only, with variables. No mutations, subscriptions or multiple operations. Permissions, dataset retention, sampling and query limits remain provider controlled. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 29 tools
Most tools target distinct Cloudflare resources and actions, but several overlapping pairs create confusion: update_dns_record vs overwrite_dns_record, batch_dns_records vs apply_dns_batch, preview_dns_batch vs preview_operation, and list_accounts vs list_provider_accounts. Descriptions help somewhat, but an agent could still misselect among batch/preview/apply tools.
Nearly all tools use snake_case verb_noun naming such as create_dns_record, list_zones, and delete_zone_ruleset. Minor deviations like analytics_query and batch_dns_records slightly break the pattern, but the set remains predictable overall.
With 29 tools, the server is heavy for a single MCP surface. While Cloudflare is a broad platform, the count exceeds the typical well-scoped range of 3-15 and includes several specialized or overlapping operations that could be consolidated.
DNS records and zone rulesets have strong CRUD coverage, but other apparent domains are incomplete: Page Rules only support get/list, Workers only list, and zones lack create/delete operations. These gaps are notable but not fatal for common DNS and ruleset workflows.