Skip the install. Get this working in under 2 minutes.
Start a free trial on cloud.anythingmcp.com, add the Cloudflare in one click, then point your AI client (Claude, ChatGPT, Copilot or Cursor) at the generated MCP endpoint. No Docker, no git clone, zero engineering experience required.
AnythingMCP is listed in Claude's connector directory: add it to Claude in one click (opens in a new tab), then sign in and choose which MCP servers Claude may use.
Summary
Let your AI manage your Cloudflare zones: review and change DNS records, purge the cache, read zone settings, redirect, transform and cache rules, check traffic analytics, and list Workers and R2 buckets. With an API token limited to what it should touch.
Try asking
Example prompts for Cloudflare
Click any prompt to copy it. Paste into Claude, ChatGPT, Cursor, Gemini, Copilot or OpenClaw to run it against this connector.
Claude is AI and can make mistakes. Please double-check responses.
💡 No install? Use cloud.anythingmcp.com directly. Sign in, click Connectors → Cloudflare, paste your credentials, mint an MCP API key and you're done. No Docker, no
git clone, no local server.
Cloudflare + Claude
Let your AI manage your Cloudflare zones: review and change DNS records, purge the cache, read zone settings, redirect, transform and cache rules, check traffic analytics, and list Workers and R2 buckets. With an API token limited to what it should touch.
Prerequisites
See the full setup instructions baked into the connector (visible in the in-app store when you select the connector). The required environment variables for this connector are:
CLOUDFLARE_API_TOKEN
Step 1 — Get credentials
- In the Cloudflare dashboard open My Profile → API Tokens (https://dash.cloudflare.com/profile/api-tokens), click Create Token, then Create Custom Token at the bottom. You can also start from the Read all resources template and add the two write permissions below.
- Name the token (for example "AnythingMCP") and add these permissions:
- Zone → Zone → Read, DNS → Edit (Read for a read-only setup), Cache Purge → Purge
- Zone → Zone Settings, Page Rules, Analytics and Workers Routes → Read
- For rules: Zone → Single Redirect, Transform Rules, Cache Rules, Origin Rules, Config Rules and Zone WAF → Read (each kind of rule needs its own permission)
- Account → Account Settings, Workers Scripts, Workers R2 Storage and Account Analytics → Read
- Under Zone Resources choose Include → All zones from an account, or Specific zone to limit the AI to some of your domains. Under Account Resources include your account. If you like, restrict Client IP Address Filtering and set a TTL.
- Click Continue to summary → Create Token, copy the token (Cloudflare shows it only once) and paste it into
CLOUDFLARE_API_TOKENwithout the word Bearer, then install the connector. Do not use the Global API Key. - Start with
cloudflare_list_zones: it shows which zones (domains) the token can see, with their status and plan.
Account-owned tokens: a token created under Manage Account → Account API Tokens works too, except for Page Rules: with it cloudflare_list_page_rules cannot read them.
Read-only setup: give DNS only Read, leave out Cache Purge, and switch off cloudflare_create_dns_record, cloudflare_update_dns_record and cloudflare_purge_cache. Zone settings, rules, analytics, Workers and R2 are read-only in this connector anyway.
Switched off at install: cloudflare_delete_dns_record and cloudflare_purge_everything. A deleted record stops whatever relied on it (a website, mail delivery, a domain verification) within seconds, so export the zone first with cloudflare_export_dns_records. Purging everything sends every visitor's next request to your origin, which can overload a busy site; cloudflare_purge_cache with specific URLs is usually enough.
DNS changes: changes go live within seconds, so a wrong record can take a website or its email offline at once. The AI reads the record first and shows you the old and new values before it changes anything. A CNAME cannot share its name with any other record, and Cloudflare refuses an identical record.
Cache purges: cloudflare_purge_cache removes up to 100 URLs, cache tags, hostnames or prefixes per call, on every plan. Free plans allow 5 purge requests per minute by tag, host or prefix.
Analytics: cloudflare_get_zone_traffic gives daily requests, bandwidth, cached traffic, threats, page views and unique visitors, with breakdowns by status code and country. For anything else (top paths, firewall events, Worker invocations) the AI uses cloudflare_graphql_analytics. How far back you can look depends on your plan; the Free plan covers recent weeks.
Workers and R2: cloudflare_get_worker_settings shows a Worker's bindings but never secret values. R2 must be enabled on the account (Storage & databases → R2, the free tier is enough) before cloudflare_list_r2_buckets answers; otherwise it fails with 403 "NotEntitled".
Limits: Cloudflare allows 1,200 API requests per 5 minutes per token, dashboard use included. Over it Cloudflare answers 429 and blocks every call for 5 minutes: wait and try again. Analytics queries have their own limit of about 300 per 5 minutes.
Common errors: 400 with code 6003 usually means the Global API Key was pasted instead of an API token. 401 means the token is wrong, expired, disabled or limited to other client IP addresses: check it under My Profile → API Tokens. 403 (codes 10000 or 9109) means the token lacks a permission for that call or zone: edit the token and add it, for example Zone Read or DNS Read. 404 is an unknown zone, record or ruleset; from cloudflare_get_phase_rules it simply means the zone has no rules of that kind. "An identical record already exists" or "A CNAME record with that host already exists" names the record that is in the way.
The connector does not edit rulesets, Page Rules or zone settings, and does not handle SSL/TLS certificates, deploying or deleting Workers, KV, D1 or R2 objects, Zero Trust, the registrar or billing.
Step 2 — Install the adapter
curl -fsSL https://raw.githubusercontent.com/HelpCode-ai/anythingmcp/main/docker-compose.quickstart.yml -o docker-compose.yml
printf 'JWT_SECRET=%s\nENCRYPTION_KEY=%s\n' "$(openssl rand -hex 32)" "$(openssl rand -hex 32)" > .env
docker compose up -d
Step 3 — Add the connector in Claude
Your server URL: in AnythingMCP, open MCP Servers → the server this connector is on, and copy its URL (
https://cloud.anythingmcp.com/mcp/…). Use it wherever this guide showsYOUR_SERVER_ID.
Recommended path: works on claude.ai web without editing any config file.
- In Claude, open Customize → Connectors.
- Click +, then Add custom connector.
- Enter a name, e.g.
Cloudflare, and the remote MCP server URLhttps://cloud.anythingmcp.com/mcp/YOUR_SERVER_ID, then click Add. - Click Connect and sign in to AnythingMCP (OAuth) to allow access.
All tools below appear in your chat: start typing prompts.
Available tools
| Tool | What it does |
|---|---|
cloudflare_list_zones | List the zones (domains) the token can see: id, name, status (active, pending, initializing, moved), plan, name_servers, paused and account… |
cloudflare_get_zone | Get one zone: name, status, plan, name servers (the ones Cloudflare assigned and the original ones), account, created and activated dates… |
cloudflare_list_accounts | List the Cloudflare accounts the token has access to: id, name, type and settings |
cloudflare_list_zone_settings | Read all settings of a zone, each as id, value and editable: SSL mode (ssl), always_use_https, min_tls_version, cache_level… |
cloudflare_get_zone_setting | Read one zone setting by its id, e.g. ssl, always_use_https, min_tls_version, security_level, cache_level, development_mode: value… |
cloudflare_list_dns_records | List a zone's DNS records with filters: id, type, name, content, proxied, ttl (1 = automatic), priority, comment, tags and modified_on |
cloudflare_get_dns_record | Get one DNS record by id: type, name, content, proxied, ttl, priority, data (SRV, CAA ...), comment, tags, created_on and modified_on |
cloudflare_export_dns_records | Export all DNS records of a zone as a BIND zone file (plain text), handy for a backup before changes or to review everything at once |
cloudflare_create_dns_record | Create a DNS record in a zone |
cloudflare_update_dns_record | Change fields of an existing DNS record (only the fields given), e.g. point it at a new IP, switch proxying on or off, change the TTL or… |
cloudflare_delete_dns_record | Delete a DNS record |
cloudflare_purge_cache | Remove cached content from Cloudflare's edge so the next request fetches it from the origin |
cloudflare_purge_everything | Purge the zone's entire cache |
cloudflare_list_rulesets | List a zone's rulesets: id, name, kind (zone, managed, custom), phase and last_updated |
cloudflare_get_ruleset | Get one ruleset with all its rules: for each rule id, description, expression (the filter, e.g. http.host eq "example.com"), action… |
cloudflare_get_phase_rules | Get the zone's own rules for one phase (its entry point ruleset): e.g. http_request_dynamic_redirect for single redirects… |
cloudflare_list_page_rules | List a zone's legacy Page Rules: id, targets (URL patterns), actions (forwarding_url, cache_level, always_use_https ...), priority and… |
cloudflare_get_zone_traffic | Daily traffic of a zone between two dates from the GraphQL Analytics API: per day requests, bytes, cached requests and bytes, threats, page… |
cloudflare_graphql_analytics | Run a query against Cloudflare's GraphQL Analytics API (read-only) for anything cloudflare_get_zone_traffic does not cover: e.g.… |
cloudflare_list_workers | List the Workers scripts of an account: id (the script name), created_on, modified_on, usage_model, handlers (fetch, scheduled ...)… |
cloudflare_get_worker_settings | Get a Worker's settings: bindings (KV, R2, D1, Durable Objects, environment variables; secret values are never returned), compatibility… |
cloudflare_get_worker_content | Download a Worker's deployed code as text, cut at 200 KB |
cloudflare_list_worker_routes | List a zone's Worker routes: id, pattern (e.g. example.com/api/*) and the script that handles it |
cloudflare_list_worker_domains | List the custom domains attached to Workers in an account: hostname, zone, service (the Worker) and environment |
cloudflare_list_r2_buckets | List an account's R2 buckets: name, creation_date, location and jurisdiction |
cloudflare_get_r2_bucket | Get one R2 bucket: name, creation_date, location, jurisdiction and storage_class |
Example prompts
- "Show me all DNS records of acme.com and tell me which ones are not proxied through Cloudflare."
- "Which redirect rules are set up on acme.com, and where does /blog end up?"
- "How much traffic did acme.com get each day last week, and which countries sent the most requests?"
- "Point the A record for shop.acme.com to 198.51.100.24, keep it proxied, and show me the old value before you change it."
FAQ
Does it work with Claude Code as well as Claude Desktop? Yes, point both at https://cloud.anythingmcp.com/mcp/YOUR_SERVER_ID.
Next steps
Was this guide helpful?