Skip to content
Graphify
First-party publisher Registry listed

Cloudflare API MCP Server

Explore and call the Cloudflare API through a compact, hosted MCP endpoint with OAuth or scoped API tokens.

Overview

What Cloudflare API MCP Server does

Cloudflare's hosted API MCP server covers the broad Cloudflare API without placing thousands of endpoint schemas into every conversation. Its default Code Mode exposes a small search-and-execute workflow: the agent queries a typed API description, then runs JavaScript against Cloudflare's API client inside an isolated worker. Teams that do not want agent-authored code can disable Code Mode and expose conventional endpoint tools instead. Cloudflare also operates narrower MCP endpoints for documentation, observability, browser rendering, DNS analytics, audit logs, and other product areas.

Best for

  • Cross-product Cloudflare administration from an agent workflow
  • Finding the right API operation without loading a very large schema
  • Hosted remote access with Cloudflare OAuth and granular permissions

Not ideal for

  • Organizations that prohibit agent-generated code execution even in an isolated service
  • Unauthenticated access to private Cloudflare account data

Capabilities

What an agent can do

  1. 01

    Search a typed representation of the Cloudflare OpenAPI specification

  2. 02

    Execute selected Cloudflare API requests from an isolated Dynamic Worker

  3. 03

    Query GraphQL Analytics through the same execution workflow

  4. 04

    Switch to native per-endpoint tools with the codemode=false query parameter

  5. 05

    Use separate product-specific remote servers when a narrower tool surface is preferred

Representative tools and operations

searchexecutedocs

Installation

Connect Cloudflare API MCP Server

Use the publisher’s current instructions as the source of truth. The examples below were checked on .

Remote MCP clientsConnect to the Code Mode endpoint
Command
https://mcp.cloudflare.com/mcp
Configuration
{
  "mcpServers": {
    "cloudflare": {
      "url": "https://mcp.cloudflare.com/mcp"
    }
  }
}
Remote MCP clientsExpose conventional endpoint tools instead of Code Mode
Command
https://mcp.cloudflare.com/mcp?codemode=false
Configuration
Use this endpoint when policy favors individual API tools over the search-and-execute code workflow.

Trust and access

Authentication and security notes

Authentication: Interactive Cloudflare OAuth is the recommended path. Automation can send a scoped user or account API token as a Bearer token.

Review before connecting

  • Grant only the Cloudflare API token scopes needed for the intended tasks and prefer read-only permissions where possible.
  • Review mutating execute calls because the server can change account configuration when the granted token allows it.
  • Code Mode runs generated JavaScript in an isolated worker, but organizations should still evaluate that execution model against their policies.

Known limitations

  • Useful operations are bounded by the permissions granted during OAuth or on the API token.
  • Some Cloudflare products and MCP endpoints may require paid plan features.
  • Large multi-step investigations can still produce substantial context even though the initial tool schema is compact.

Evidence

Sources used for this guide

Facts were checked against primary publisher material. Descriptions and guidance are original Graphify summaries.

FAQ

Questions about Cloudflare API MCP Server

Why does Cloudflare's API server expose only a few tools by default?

Code Mode keeps the initial schema small. The agent first searches the API description, then executes only the operations needed for the task.

Can I avoid Code Mode?

Yes. Add ?codemode=false to the endpoint to register individual API tools, accepting a much larger tool surface in return.

Editorial review · MCP server

What this page is based on

Server capabilities and operational notes are tied to the recorded source set and review date.

Review basis
MCP server record and linked primary evidence
Last checked
Jul 11, 2026
Evidence links
3 recorded in the page data

Source snapshot is 91 days old; verify upstream details before relying on pricing, availability, or security claims.