CLOUDFLARE-MCP
Managed Cloudflare MCP rollout for account, zone, DNS, security, Workers, Pages, and edge platform workflows.
Authentication
-
Header:
Authorization -
Format:
Bearer mad_live_*** -
This service reference is generated from the active immutable Portal catalog.
Catalog Coverage
- Raw provider tools: 6
- Exposed compatibility tools: 6
- Agent-ready tools: 5
- Documented descriptors: 6
- Public reference pages: 6
- Source repository: https://github.com/MADPANDA3D/CF-MCP
- Catalog version:
2026.07.12.1 - Catalog verified:
2026-07-12T09:24:46.22504+00:00(5 days old) - Guide verified:
not manually verified(not verified) - Committed snapshot:
catalog-5ec40de147b11c40 - Docs generated:
2026-07-18T00:19:58.776Z
Read-only Tools
- Check Cloudflare Configuration — Use this to verify that the Cloudflare MCP Portal gate and provider credential routing are configured without returning credential values. Set verify_cloudflare_token=true only when a live, read-only Cloudflare token check is needed. The default performs no provider request and changes no state.
- Find Cloudflare Tools — Use this for deterministic punctuation-normalized, multi-token search across Cloudflare MCP names, aliases, titles, descriptions, and categories. Default results contain only agent-ready local navigation tools; set include_legacy=true only for advanced discovery of the mixed-risk API dispatcher.
- Get Cloudflare Endpoint Coverage — Use this to search the checked-in official Cloudflare OpenAPI inventory by feature, method, path text, or risk before considering an advanced API request. It returns a paginated local coverage page, performs no provider request, and does not imply that the mixed-risk legacy dispatcher is safe for default use.
- Get Cloudflare Tool Usage — Use this when an agent already has a Cloudflare native name, canonical name, or exact alias and needs its complete descriptor, setup, side effects, and next step. This resolves local catalog metadata only and performs no Cloudflare request.
- List Cloudflare MCP Capabilities — Use this to inspect Cloudflare MCP catalog counts, safe workflows, and the provider-owned ToolManifest. Set include_descriptors=true when the Portal or an advanced agent needs every lossless schema and annotation. This is local, read-only, and requires no Cloudflare provider credential.
Write and Destructive Tools
- Execute Advanced Cloudflare API Request — Advanced compatibility tool for executing one documented Cloudflare REST method and path with a request-scoped provider credential. This single dispatcher spans read, write, and destructive operations, so it is intentionally excluded from default agent discovery and must never be treated as one uniformly safe risk. Writes require confirm_write=true; destructive operations also require confirm_destructive=true after explicit user approval.