跳过安装。2 分钟内即可运行。
在 cloud.anythingmcp.com 开始免费试用,一键添加 Cloudflare,然后将你的 AI 客户端(Claude、ChatGPT、Copilot 或 Cursor)指向生成的 MCP 端点。无需 Docker,无需 git clone,无需任何工程经验。
摘要
让你的 AI 管理你的 Cloudflare 区域:查看和修改 DNS 记录,清除缓存,读取区域设置以及重定向、转换和缓存规则,查看流量分析,列出 Workers 和 R2 存储桶。所用的 API 令牌只限于它该接触的范围。
试试这样问
Cloudflare 的示例提示
点击任意提示即可复制,然后粘贴到 Claude、ChatGPT、Cursor、Gemini、Copilot 或 OpenClaw 中,在该连接器上运行。
Claude 是 AI,可能会出错。请核对回答。
💡 无需安装? 直接使用 cloud.anythingmcp.com。 登录、点击 Connectors → Cloudflare、粘贴凭证、生成 MCP API key,即可完成。无 Docker、无
git clone、无本地服务器。
Cloudflare + Gemini
让你的 AI 管理你的 Cloudflare 区域:查看和修改 DNS 记录,清除缓存,读取区域设置以及重定向、转换和缓存规则,查看流量分析,列出 Workers 和 R2 存储桶。所用的 API 令牌只限于它该接触的范围。
前提条件
完整的设置说明已内置在连接器中 (在 store 中选择连接器时可见)。所需环境变量:
CLOUDFLARE_API_TOKEN
步骤 1 — 获取凭证
- 在 Cloudflare 控制台中打开 My Profile → API Tokens(https://dash.cloudflare.com/profile/api-tokens),点击 Create Token,然后点击页面最下方的 Create Custom Token。你也可以从 Read all resources 模板开始,再加上下面的两个写入权限。
- 为令牌命名(例如 "AnythingMCP"),并添加以下权限:
- Zone → Zone → Read,DNS → Edit(只读设置时用 Read),Cache Purge → Purge
- Zone → Zone Settings、Page Rules、Analytics 和 Workers Routes → Read
- 规则相关:Zone → Single Redirect、Transform Rules、Cache Rules、Origin Rules、Config Rules 和 Zone WAF → Read(每种规则都需要单独的权限)
- Account → Account Settings、Workers Scripts、Workers R2 Storage 和 Account Analytics → Read
- 在 Zone Resources 中选择 Include → All zones from an account;如果只想让 AI 访问部分域名,选择 Specific zone。在 Account Resources 中包含你的账户。你还可以按需设置 Client IP Address Filtering 和 TTL。
- 点击 Continue to summary → Create Token,复制令牌(Cloudflare 只显示一次),把它填入
CLOUDFLARE_API_TOKEN,不要带 Bearer 字样,然后安装连接器。不要使用 Global API Key。 - 先运行
cloudflare_list_zones:它会显示该令牌能看到哪些区域(域名),以及它们的状态和套餐。
账户拥有的令牌:在 Manage Account → Account API Tokens 中创建的令牌也可以使用,但 Page Rules 除外:用这种令牌时,cloudflare_list_page_rules 无法读取 Page Rules。
只读设置:DNS 只授予 Read,不要添加 Cache Purge,并停用 cloudflare_create_dns_record、cloudflare_update_dns_record 和 cloudflare_purge_cache。区域设置、规则、分析、Workers 和 R2 在本连接器中本来就是只读的。
安装时默认关闭:cloudflare_delete_dns_record 和 cloudflare_purge_everything。删除一条记录后,依赖它的内容(网站、邮件投递、域名验证)会在几秒内失效,所以请先用 cloudflare_export_dns_records 导出区域。清除全部缓存会让每个访客的下一个请求都打到你的源站,访问量大的网站可能因此过载;通常用 cloudflare_purge_cache 指定具体 URL 就够了。
DNS 更改:更改会在几秒内生效,一条错误的记录可能让网站或邮件立即中断。AI 在做任何更改之前会先读取记录,并向你展示旧值和新值。CNAME 不能与任何其他记录同名,完全相同的记录也会被 Cloudflare 拒绝。
清除缓存:cloudflare_purge_cache 每次调用最多可清除 100 个 URL、缓存标签、主机名或前缀,所有套餐都可使用。Free 套餐按标签、主机或前缀清除时,每分钟最多 5 次请求。
分析:cloudflare_get_zone_traffic 按天返回请求数、数据量、缓存命中的流量、威胁、页面浏览量和独立访客数,并按状态码和国家细分。其他需求(访问最多的路径、防火墙事件、Worker 调用)由 AI 使用 cloudflare_graphql_analytics 查询。能回溯多远取决于你的套餐;Free 套餐覆盖最近几周。
Workers 和 R2:cloudflare_get_worker_settings 会显示 Worker 的绑定,但绝不会显示密钥的值。账户必须先启用 R2(Storage & databases → R2,免费额度即可),cloudflare_list_r2_buckets 才会返回结果;否则会以 403 "NotEntitled" 失败。
限制:Cloudflare 允许每个令牌每 5 分钟 1,200 个 API 请求,控制台中的操作也计算在内。超过后 Cloudflare 返回 429,并在 5 分钟内阻止所有调用:稍等后再试。分析查询另有每 5 分钟约 300 次的限制。
常见错误:带代码 6003 的 400 通常表示填入的是 Global API Key 而不是 API 令牌。401 表示令牌错误、已过期、已停用或被限制在其他客户端 IP 地址:请在 My Profile → API Tokens 中检查。403(代码 10000 或 9109)表示令牌缺少该调用或该区域所需的权限:编辑令牌并添加该权限,例如 Zone Read 或 DNS Read。404 表示区域、记录或规则集不存在;对于 cloudflare_get_phase_rules,它只是表示该区域没有这类规则。"An identical record already exists" 或 "A CNAME record with that host already exists" 会指出造成冲突的记录。
连接器不编辑规则集、Page Rules 或区域设置,也不处理 SSL/TLS 证书、Workers 的部署或删除、KV、D1 或 R2 对象、Zero Trust、域名注册或账单。
步骤 2 — 安装 adapter
curl -fsSL https://raw.githubusercontent.com/HelpCode-ai/anythingmcp/main/docker-compose.quickstart.yml -o docker-compose.yml
printf 'JWT_SECRET=%s\nENCRYPTION_KEY=%s\n' "$(openssl rand -hex 32)" "$(openssl rand -hex 32)" > .env
docker compose up -d
步骤 3 — 在 Gemini 中添加连接器
你的服务器 URL: 在 AnythingMCP 中打开 MCP Servers → 此连接器所在的服务器,复制它的 URL(
https://cloud.anythingmcp.com/mcp/…)。本指南中出现YOUR_SERVER_ID的地方都用它替换。
Gemini CLI 从 ~/.gemini/settings.json(Windows 上为 %USERPROFILE%\.gemini\settings.json)读取 MCP 服务器。添加:
{
"mcpServers": {
"anythingmcp": {
"httpUrl": "https://cloud.anythingmcp.com/mcp/YOUR_SERVER_ID",
"headers": { "X-API-Key": "YOUR_MCP_API_KEY" }
}
}
}
- 在 AnythingMCP 的 MCP Servers → 你的服务器 → API keys 中创建 MCP API 密钥,并用它替换
YOUR_MCP_API_KEY。 - 保存文件并重启
gemini。 - 在 Gemini CLI 中运行
/mcp(或在终端运行gemini mcp list),anythingmcp应显示为已连接。 - 开始输入提示,Gemini CLI 现在可以调用
Cloudflare的工具。
可用工具
| Tool | What it does |
|---|---|
cloudflare_list_zones | List the zones (domains) the token can see: id, name, status (active, pending, initializing, moved), plan, name_servers, paused and account… |
cloudflare_get_zone | Get one zone: name, status, plan, name servers (the ones Cloudflare assigned and the original ones), account, created and activated dates… |
cloudflare_list_accounts | List the Cloudflare accounts the token has access to: id, name, type and settings |
cloudflare_list_zone_settings | Read all settings of a zone, each as id, value and editable: SSL mode (ssl), always_use_https, min_tls_version, cache_level… |
cloudflare_get_zone_setting | Read one zone setting by its id, e.g. ssl, always_use_https, min_tls_version, security_level, cache_level, development_mode: value… |
cloudflare_list_dns_records | List a zone's DNS records with filters: id, type, name, content, proxied, ttl (1 = automatic), priority, comment, tags and modified_on |
cloudflare_get_dns_record | Get one DNS record by id: type, name, content, proxied, ttl, priority, data (SRV, CAA ...), comment, tags, created_on and modified_on |
cloudflare_export_dns_records | Export all DNS records of a zone as a BIND zone file (plain text), handy for a backup before changes or to review everything at once |
cloudflare_create_dns_record | Create a DNS record in a zone |
cloudflare_update_dns_record | Change fields of an existing DNS record (only the fields given), e.g. point it at a new IP, switch proxying on or off, change the TTL or… |
cloudflare_delete_dns_record | Delete a DNS record |
cloudflare_purge_cache | Remove cached content from Cloudflare's edge so the next request fetches it from the origin |
cloudflare_purge_everything | Purge the zone's entire cache |
cloudflare_list_rulesets | List a zone's rulesets: id, name, kind (zone, managed, custom), phase and last_updated |
cloudflare_get_ruleset | Get one ruleset with all its rules: for each rule id, description, expression (the filter, e.g. http.host eq "example.com"), action… |
cloudflare_get_phase_rules | Get the zone's own rules for one phase (its entry point ruleset): e.g. http_request_dynamic_redirect for single redirects… |
cloudflare_list_page_rules | List a zone's legacy Page Rules: id, targets (URL patterns), actions (forwarding_url, cache_level, always_use_https ...), priority and… |
cloudflare_get_zone_traffic | Daily traffic of a zone between two dates from the GraphQL Analytics API: per day requests, bytes, cached requests and bytes, threats, page… |
cloudflare_graphql_analytics | Run a query against Cloudflare's GraphQL Analytics API (read-only) for anything cloudflare_get_zone_traffic does not cover: e.g.… |
cloudflare_list_workers | List the Workers scripts of an account: id (the script name), created_on, modified_on, usage_model, handlers (fetch, scheduled ...)… |
cloudflare_get_worker_settings | Get a Worker's settings: bindings (KV, R2, D1, Durable Objects, environment variables; secret values are never returned), compatibility… |
cloudflare_get_worker_content | Download a Worker's deployed code as text, cut at 200 KB |
cloudflare_list_worker_routes | List a zone's Worker routes: id, pattern (e.g. example.com/api/*) and the script that handles it |
cloudflare_list_worker_domains | List the custom domains attached to Workers in an account: hostname, zone, service (the Worker) and environment |
cloudflare_list_r2_buckets | List an account's R2 buckets: name, creation_date, location and jurisdiction |
cloudflare_get_r2_bucket | Get one R2 bucket: name, creation_date, location, jurisdiction and storage_class |
示例提示
- “列出 acme.com 的所有 DNS 记录,并告诉我哪些没有通过 Cloudflare 代理。”
- “acme.com 上设置了哪些重定向规则?/blog 最终会跳转到哪里?”
- “acme.com 上周每天有多少流量?哪些国家的请求最多?”
- “把 shop.acme.com 的 A 记录指向 198.51.100.24,保持代理开启,修改前先给我看旧值。”
FAQ
Gemini CLI 从哪里读取 MCP 服务器? 用户级配置位于 ~/.gemini/settings.json,项目级配置位于项目内的 .gemini/settings.json。gemini mcp list 会列出每个服务器及其连接状态。
下一步
这份指南对你有帮助吗?