Cloudflare MCP server for AI agents and assistants

Securely connect your AI agents and chatbots (Claude, ChatGPT, Cursor, etc) with Cloudflare MCP or direct API to manage DNS records, automate firewall rules, monitor analytics, and control access settings through natural language.

Cloudflare logoCloudflare
Api Key

Cloudflare is a global network that secures and accelerates web traffic. It helps protect your sites and APIs from attacks while ensuring reliable performance.

20 Tools

Try Cloudflare now

Type what you want done — sign in and watch it run live in the Tool Router playground.

TOOL ROUTER PLAYGROUND
Cloudflare
Try asking
TOOLS

Supported Tools

Every Cloudflare action and event your agent gets out of the box.

Create DNS record

Tool to create a new DNS record within a specific zone.

Create WAF List

Create a new empty custom list for use in WAF rules and filters.

Create Zone

Creates a new DNS zone (domain) in Cloudflare.

Delete DNS Record

Tool to delete a DNS record within a specific zone.

Delete WAF List

Tool to delete a WAF list.

Delete Zone

Tool to delete a zone.

Get Bot Management Settings

Tool to retrieve a zone's Bot Management configuration (Bot Fight Mode / Super Bot Fight Mode / Enterprise Bot Management).

List WAF Lists

Tool to fetch all WAF lists (no items) for an account.

List Account Members

Lists all members of a Cloudflare account with their roles, permissions, and status.

List Accounts

List all Cloudflare accounts you have ownership or verified access to.

List DNS records

Tool to list and search DNS records in a Cloudflare zone.

List Firewall Rules

Tool to list firewall rules for a specific DNS zone.

List Monitors

Tool to list all load-balancer monitors in a Cloudflare account.

List Pools

Tool to list all load balancer pools in a Cloudflare account.

List Tunnels

List Cloudflare Tunnel (cloudflared) tunnels in an account to discover tunnel IDs, names, and statuses.

List Zones

Lists, searches, sorts, and filters zones in the authenticated account.

Update DNS record

Tool to update an existing DNS record within a specific zone.

Update WAF List

Tool to update the description of a WAF list (cannot update items).

Update Tunnel Configuration

Tool to update a remotely-managed Cloudflare Tunnel's configuration (ingress rules and routing).

Update Zone

Tool to update properties of an existing zone; changes apply immediately to the live zone.

SETUP GUIDE

Connect Cloudflare MCP Tool with your Agent

1

Install Composio

typescript
npm install @composio/core ai @ai-sdk/mcp @ai-sdk/openai
Install the Composio SDK and your agent framework
2

Create a session with MCP enabled

typescript
import { Composio } from "@composio/core";

const composio = new Composio();
const { mcp } = await composio.create("your-user-id", {
  toolkits: ["cloudflare"],
  mcp: true,
});
Create a session scoped to Cloudflare and read its MCP URL and headers
3

Connect your agent to the MCP server

typescript
import { createMCPClient } from "@ai-sdk/mcp";
import { openai } from "@ai-sdk/openai";
import { generateText, stepCountIs } from "ai";

const client = await createMCPClient({
  transport: { type: "http", url: mcp.url, headers: mcp.headers },
});

const { text } = await generateText({
  model: openai("gpt-5.6-sol"),
  tools: await client.tools(),
  prompt: "List all firewall rules for zone abc123",
  stopWhen: stepCountIs(10),
});

console.log(text);
await client.close();
Pass the session's MCP URL and headers to your agent and run a Cloudflare request
SETUP GUIDE

Connect Cloudflare API Tool with your Agent

1

Install Composio

typescript
npm install @composio/core @composio/openai openai
Install the Composio SDK, the OpenAI provider, and the OpenAI SDK
2

Create a Composio session

typescript
import OpenAI from "openai";
import { Composio } from "@composio/core";
import { OpenAIResponsesProvider } from "@composio/openai";

const composio = new Composio({ provider: new OpenAIResponsesProvider() });
const client = new OpenAI();

const session = await composio.create("your-user-id", { toolkits: ["cloudflare"] });
const tools = await session.tools();
Initialize Composio with the OpenAI Responses provider and create a session scoped to Cloudflare
3

Run Cloudflare tools with your agent

typescript
let response = await client.responses.create({
  model: "gpt-5.6-sol",
  tools,
  input: [{ role: "user", content: "List all firewall rules for zone abc123" }],
});

while (response.output.some((o) => o.type === "function_call")) {
  const outputs = await composio.provider.handleToolCalls(session, response.output);
  response = await client.responses.create({
    model: "gpt-5.6-sol",
    tools,
    previous_response_id: response.id,
    input: outputs,
  });
}

console.log(response.output_text);
Send a request, execute the Cloudflare tool calls through the session, and print the final answer

Why Use Composio?

AI Native Cloudflare Integration

  • Supports both Cloudflare MCP and direct API based integrations
  • Structured, LLM-friendly schemas for reliable tool execution
  • Rich coverage for reading, writing, and querying your Cloudflare zones, DNS, and security settings

Managed Auth

  • Built-in API key handling and secure credential storage
  • Central place to manage, scope, and revoke Cloudflare access
  • Per user and per environment credentials instead of hard-coded keys

Agent Optimized Design

  • Tools are tuned using real error and success rates to improve reliability over time
  • Comprehensive execution logs so you always know what ran, when, and on whose behalf

Enterprise Grade Security

  • Fine-grained RBAC so you control which agents and users can access Cloudflare
  • Scoped, least privilege access to Cloudflare resources
  • Full audit trail of agent actions to support review and compliance

Rolling this out across your team?

Give your team centralized access control across every framework with Composio’s MCP Gateway.

EXPLORE MCP GATEWAY
FAQ

Frequently asked questions

Yes, Cloudflare requires you to configure your own API key credentials. Once set up, Composio handles secure credential storage and API request handling for you.

Yes! Composio's Tool Router enables agents to use multiple toolkits. Learn more.

Yes. Composio is SOC 2 Type II compliant and is built to keep your Cloudflare connection and credentials secure. OAuth tokens and API keys are encrypted, and sensitive customer data is protected at rest and in transit.

Composio also undergoes independent security testing and continuously monitors its systems for security threats. You can review the latest reports and policies in the Composio Trust Center.

Composio maintains and updates all toolkit integrations automatically, so your agents always work with the latest API versions.

Create the key in your Cloudflare account settings, then paste it once on Composio's connection page. Composio stores it encrypted and uses it only for the Cloudflare actions your agent runs. Nobody else in your workspace can read it, and you can revoke it inside Cloudflare at any time.

When you connect a Cloudflare account through Composio, every action runs under that account, so anything the agent creates, sends, or changes shows up in Cloudflare as done by you. Keep an approval step in your prompt for actions with side effects, such as sending or deleting, and have the agent draft first.

Whatever the credentials you connect allow inside Cloudflare. If Cloudflare lets you scope a key to specific permissions, create a scoped one so the agent can only do what you intend. You can revoke the key inside Cloudflare at any time.

Yes. Composio supports multiple connected accounts for the same app, and that works in Claude, ChatGPT, or any other assistant you connect through Composio. Give each Cloudflare connection a name such as work or personal, and the assistant uses the one you mention in the request. Each account keeps its own credentials and nothing is merged.

The connection stops working the moment Cloudflare rejects the old key. Create a new key in Cloudflare and reconnect the account from the Composio dashboard or by asking your agent to reconnect Cloudflare. Nothing else changes.

Composio's free Hobby plan includes 100,000 tool calls per month with no credit card, which covers most personal Cloudflare use. Paid plans add higher limits and team features. Your Cloudflare plan and its API limits still apply as usual.

Built-in connectors usually give one AI access to a limited set of apps. Many people use Composio because it lets their AI connect to more apps than it normally supports, or connect to multiple accounts for the same app (e.g. connect Claude to multiple Cloudflare accounts).

With Composio, you connect Cloudflare once and then use it across different AI assistants without setting it up separately in each one. Connect your apps to Composio once, then connect Composio to whichever AI you use, whether that's Claude, ChatGPT, Hermes, or your own custom assistant.

Start with Cloudflare.It takes 30 seconds.

Managed auth, hosted MCP servers, and every Cloudflare tool your agent needs.Free to start.

Start building