インストール不要。2分以内に動きます。
cloud.anythingmcp.com で無料トライアルを開始し、Cloudflare をワンクリックで追加して、AI クライアント(Claude、ChatGPT、Copilot、Cursor)を生成された MCP エンドポイントに向けるだけ。Docker も git clone も、開発経験も不要です。
AnythingMCP は Claude のコネクタディレクトリに掲載されています。ワンクリックで Claude に追加 (新しいタブで開きます)し、サインインして Claude が使える MCP サーバーを選んでください。
概要
AI に Cloudflare のゾーンを管理させます。DNS レコードの確認と変更、キャッシュのパージ、ゾーン設定とリダイレクト、トランスフォーム、キャッシュの各ルールの読み取り、トラフィック分析の確認、Workers と R2 バケットの一覧表示ができます。API トークンは、触れてよい範囲だけに絞れます。
こう聞いてみよう
Cloudflare のサンプルプロンプト
プロンプトをクリックでコピー。Claude / ChatGPT / Cursor / Gemini / Copilot / OpenClaw に貼り付けて、このコネクターで実行できます。
Claude は AI のため誤ることがあります。回答をご確認ください。
💡 インストール不要? cloud.anythingmcp.com を直接利用してください。 サインインし、Connectors → Cloudflare をクリック、認証情報を貼り付け、MCP API キーを発行すれば完了です。Docker も
git cloneもローカルサーバーも不要。
Cloudflare + Claude
AI に Cloudflare のゾーンを管理させます。DNS レコードの確認と変更、キャッシュのパージ、ゾーン設定とリダイレクト、トランスフォーム、キャッシュの各ルールの読み取り、トラフィック分析の確認、Workers と R2 バケットの一覧表示ができます。API トークンは、触れてよい範囲だけに絞れます。
前提条件
完全なセットアップ手順はコネクタ自体に組み込まれています (ストアでコネクタを選択すると表示)。必要な環境変数:
CLOUDFLARE_API_TOKEN
ステップ 1 — 認証情報を取得
- Cloudflare ダッシュボードで My Profile → API Tokens(https://dash.cloudflare.com/profile/api-tokens)を開き、**Create Token** をクリックしてから、いちばん下の Create Custom Token をクリックします。Read all resources テンプレートから始めて、下記の 2 つの書き込み権限を追加する方法もあります。
- トークンに名前を付け(例: 「AnythingMCP」)、次の権限を追加します。
- Zone → Zone → Read、DNS → Edit(読み取り専用にする場合は Read)、Cache Purge → Purge
- Zone → Zone Settings、Page Rules、Analytics、Workers Routes → Read
- ルール用: Zone → Single Redirect、Transform Rules、Cache Rules、Origin Rules、Config Rules、Zone WAF → Read(ルールの種類ごとに個別の権限が必要です)
- Account → Account Settings、Workers Scripts、Workers R2 Storage、Account Analytics → Read
- Zone Resources で Include → All zones from an account を選びます。AI が触れるドメインを一部に絞るなら Specific zone を選びます。Account Resources では自分のアカウントを含めます。必要に応じて Client IP Address Filtering で制限をかけ、TTL を設定します。
- Continue to summary → Create Token をクリックし、トークンをコピーして(Cloudflare が表示するのは一度だけです)、Bearer という語を付けずに
CLOUDFLARE_API_TOKENに貼り付けて、コネクターをインストールします。Global API Key は使わないでください。 - まず
cloudflare_list_zonesを実行します。トークンから見えるゾーン(ドメイン)が、ステータスとプランとともに表示されます。
アカウント所有のトークン: Manage Account → Account API Tokens で作成したトークンも使えますが、Page Rules だけは例外です。このトークンでは cloudflare_list_page_rules が Page Rules を読み取れません。
読み取り専用の設定: DNS には Read だけを付与し、Cache Purge は外して、cloudflare_create_dns_record、cloudflare_update_dns_record、cloudflare_purge_cache をオフにします。ゾーン設定、ルール、分析、Workers、R2 は、このコネクターではもともと読み取り専用です。
インストール時はオフ: cloudflare_delete_dns_record と cloudflare_purge_everything。レコードを削除すると、それに依存していたもの(Web サイト、メールの配信、ドメイン認証)が数秒で動かなくなります。先に cloudflare_export_dns_records でゾーンをエクスポートしてください。キャッシュをすべてパージすると、すべての訪問者の次のリクエストがオリジンに届き、アクセスの多いサイトでは過負荷になることがあります。たいていは cloudflare_purge_cache で特定の URL を指定すれば十分です。
DNS の変更: 変更は数秒で反映されるため、誤ったレコードひとつで Web サイトやメールがすぐに止まることがあります。AI は何かを変更する前にまずレコードを読み取り、変更前と変更後の値を示します。CNAME は他のどのレコードとも名前を共有できず、まったく同じレコードは Cloudflare に拒否されます。
キャッシュのパージ: cloudflare_purge_cache は 1 回の呼び出しで最大 100 件の URL、キャッシュタグ、ホスト名、プレフィックスを削除でき、どのプランでも使えます。Free プランでは、タグ、ホスト、プレフィックスによるパージは 1 分あたり 5 回までです。
分析: cloudflare_get_zone_traffic は、日ごとのリクエスト数、データ転送量、キャッシュから配信されたトラフィック、脅威、ページビュー、ユニーク訪問者数を、ステータスコード別と国別の内訳とともに返します。それ以外(アクセスの多いパス、ファイアウォールのイベント、Worker の呼び出しなど)には、AI が cloudflare_graphql_analytics を使います。どこまでさかのぼれるかはプランによって異なり、Free プランでは直近の数週間です。
Workers と R2: cloudflare_get_worker_settings は Worker のバインディングを表示しますが、シークレットの値は決して表示しません。cloudflare_list_r2_buckets が応答するには、アカウントで R2 を有効にしておく必要があります(Storage & databases → R2、無料枠で十分です)。有効でない場合は 403「NotEntitled」で失敗します。
制限: Cloudflare の API はトークンごとに 5 分あたり 1,200 リクエストまでで、ダッシュボードでの操作も数に含まれます。超えると Cloudflare は 429 を返し、5 分間すべての呼び出しをブロックします。しばらく待ってからやり直してください。分析クエリには別に、5 分あたり約 300 件の制限があります。
よくあるエラー: コード 6003 の 400 は、たいてい API トークンではなく Global API Key を貼り付けたことを示します。401 は、トークンが間違っているか、期限切れか、無効化されているか、別のクライアント IP アドレスに制限されていることを示します。My Profile → API Tokens で確認してください。403(コード 10000 または 9109)は、その呼び出しやゾーンに必要な権限がトークンにないことを示します。トークンを編集して、Zone Read や DNS Read などの権限を追加してください。404 は、存在しないゾーン、レコード、ルールセットです。cloudflare_get_phase_rules の場合は、そのゾーンにその種類のルールがないという意味にすぎません。「An identical record already exists」や「A CNAME record with that host already exists」には、競合しているレコードが示されます。
このコネクターは、ルールセット、Page Rules、ゾーン設定の編集は行わず、SSL/TLS 証明書、Workers のデプロイや削除、KV、D1、R2 のオブジェクト、Zero Trust、レジストラ、請求は扱いません。
ステップ 2 — アダプターをインストール
curl -fsSL https://raw.githubusercontent.com/HelpCode-ai/anythingmcp/main/docker-compose.quickstart.yml -o docker-compose.yml
printf 'JWT_SECRET=%s\nENCRYPTION_KEY=%s\n' "$(openssl rand -hex 32)" "$(openssl rand -hex 32)" > .env
docker compose up -d
ステップ 3 — Claude にコネクタを追加
サーバーURL: AnythingMCP で MCP Servers を開き、このコネクタがあるサーバーを選んで URL(
https://cloud.anythingmcp.com/mcp/…)をコピーします。このガイドでYOUR_SERVER_IDと表示されている箇所に使ってください。
推奨ルート:設定ファイルを触らずに claude.ai web で動作します。
- Claude で Customize → Connectors を開きます。
- + をクリックし、Add custom connector を選びます。
- 名前(例:
Cloudflare)とリモート MCP サーバー URLhttps://cloud.anythingmcp.com/mcp/YOUR_SERVER_IDを入力し、Add をクリックします。 - Connect をクリックし、AnythingMCP にサインイン(OAuth)してアクセスを許可します。
下記のすべてのツールがチャットに表示されます。プロンプトを入力し始めてください。
利用可能なツール
| Tool | What it does |
|---|---|
cloudflare_list_zones | List the zones (domains) the token can see: id, name, status (active, pending, initializing, moved), plan, name_servers, paused and account… |
cloudflare_get_zone | Get one zone: name, status, plan, name servers (the ones Cloudflare assigned and the original ones), account, created and activated dates… |
cloudflare_list_accounts | List the Cloudflare accounts the token has access to: id, name, type and settings |
cloudflare_list_zone_settings | Read all settings of a zone, each as id, value and editable: SSL mode (ssl), always_use_https, min_tls_version, cache_level… |
cloudflare_get_zone_setting | Read one zone setting by its id, e.g. ssl, always_use_https, min_tls_version, security_level, cache_level, development_mode: value… |
cloudflare_list_dns_records | List a zone's DNS records with filters: id, type, name, content, proxied, ttl (1 = automatic), priority, comment, tags and modified_on |
cloudflare_get_dns_record | Get one DNS record by id: type, name, content, proxied, ttl, priority, data (SRV, CAA ...), comment, tags, created_on and modified_on |
cloudflare_export_dns_records | Export all DNS records of a zone as a BIND zone file (plain text), handy for a backup before changes or to review everything at once |
cloudflare_create_dns_record | Create a DNS record in a zone |
cloudflare_update_dns_record | Change fields of an existing DNS record (only the fields given), e.g. point it at a new IP, switch proxying on or off, change the TTL or… |
cloudflare_delete_dns_record | Delete a DNS record |
cloudflare_purge_cache | Remove cached content from Cloudflare's edge so the next request fetches it from the origin |
cloudflare_purge_everything | Purge the zone's entire cache |
cloudflare_list_rulesets | List a zone's rulesets: id, name, kind (zone, managed, custom), phase and last_updated |
cloudflare_get_ruleset | Get one ruleset with all its rules: for each rule id, description, expression (the filter, e.g. http.host eq "example.com"), action… |
cloudflare_get_phase_rules | Get the zone's own rules for one phase (its entry point ruleset): e.g. http_request_dynamic_redirect for single redirects… |
cloudflare_list_page_rules | List a zone's legacy Page Rules: id, targets (URL patterns), actions (forwarding_url, cache_level, always_use_https ...), priority and… |
cloudflare_get_zone_traffic | Daily traffic of a zone between two dates from the GraphQL Analytics API: per day requests, bytes, cached requests and bytes, threats, page… |
cloudflare_graphql_analytics | Run a query against Cloudflare's GraphQL Analytics API (read-only) for anything cloudflare_get_zone_traffic does not cover: e.g.… |
cloudflare_list_workers | List the Workers scripts of an account: id (the script name), created_on, modified_on, usage_model, handlers (fetch, scheduled ...)… |
cloudflare_get_worker_settings | Get a Worker's settings: bindings (KV, R2, D1, Durable Objects, environment variables; secret values are never returned), compatibility… |
cloudflare_get_worker_content | Download a Worker's deployed code as text, cut at 200 KB |
cloudflare_list_worker_routes | List a zone's Worker routes: id, pattern (e.g. example.com/api/*) and the script that handles it |
cloudflare_list_worker_domains | List the custom domains attached to Workers in an account: hostname, zone, service (the Worker) and environment |
cloudflare_list_r2_buckets | List an account's R2 buckets: name, creation_date, location and jurisdiction |
cloudflare_get_r2_bucket | Get one R2 bucket: name, creation_date, location, jurisdiction and storage_class |
プロンプトの例
- 「acme.com の DNS レコードをすべて表示して、Cloudflare のプロキシを通っていないものを教えてください。」
- 「acme.com にはどんなリダイレクトルールが設定されていて、/blog はどこに転送されますか?」
- 「先週、acme.com には日ごとにどれくらいのトラフィックがあり、リクエストが多かったのはどの国からですか?」
- 「shop.acme.com の A レコードを 198.51.100.24 に向けてください。プロキシは有効のままにして、変更する前に今の値を見せてください。」
FAQ
Claude Code は Claude Desktop と同じように動作しますか? はい。両方を https://cloud.anythingmcp.com/mcp/YOUR_SERVER_ID に向けてください。
次のステップ
このガイドは役に立ちましたか?