CloudflareBLOCK
MCP server for the Cloudflare API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A token-efficient MCP server for the entire Cloudflare API. 2500 endpoints in 1k tokens, powered by Code Mode.
Token Comparison
Get Started
MCP URL: https://mcp.cloudflare.com/mcp
Option 1: OAuth (Recommended)
Just connect to the MCP server URL - you'll be redirected to Cloudflare to authorize and select permissions.
Example JSON Configuration
{
"mcpServers": {
"cloudflare-api": {
"type": "http",
"url": "https://mcp.cloudflare.com/mcp"
}
}
}Option 2: API Token
For CI/CD, automation, or if you prefer managing tokens yourself.
Create a Cloudflare API token with the permissions you need. Both user tokens and account tokens are supported. For account tokens, include the Account Resources : Read permission so the server can auto-detect your account ID.
Note: API tokens with Client IP Address Filtering enabled are not currently supported.
Add to Agent
c69372cfd36fOBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add cloudflare-mcp -- npx -y [email protected]
{
"mcpServers": {
"cloudflare-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (4)
3 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
docs | read | |
execute | write | |
get_user | read | GET /user\n\nGet current user |
search | read |
Trust audit
BLOCKgrade D · trust 65/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (19)
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
exec(query: string): Promise<D1ExecResult>;
const token = 'cfut_invalid-cache-token'
streamable-http
.env_example
.oxfmtrc.json
} from '../../src/auth/account-access'
import { AUTH_PROPS_VERSION, LEGACY_ACCOUNTS_PAGE_SIZE, type AuthProps } from '../../src/auth/types'} from '../../src/auth/api-token-mode'
import { AUTH_PROPS_VERSION } from '../../src/auth/types'vi.mock('../../src/utils/fetch-retry', async (importOriginal) => {'http://127.0.0.1:3210/callback',
'http://127.255.255.255:3210/callback',
const binary = atob(value)
const legacy = LegacyOAuthState.safeParse(JSON.parse(atob(state)))
decodedAsJson = JSON.parse(atob(cfState))
atob(data: string): string;
declare function atob(data: string): string;
hono, zod, @cloudflare/vitest-pool-workers, @types/node, msw, oxfmt, oxlint, tsx
Gates applied: no_behavioural_pass.
c69372cfd36ffull audit observations/trust-audit/mcp-server/cloudflare__cloudflare-10.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | c69372cfd36f | BLOCK | D | 65 | first audit |
Questions
What is the Cloudflare MCP server?
MCP server for the Cloudflare API
What tools does Cloudflare expose?
4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Cloudflare safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (65/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Cloudflare need?
No credential environment variables were found in its source, so it appears to need none.
How does Cloudflare run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as cloudflare-mcp at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (c69372cfd36f), read on 2026-09-28. The repository is watched and re-audited when it changes.