At a glance
- Availability: Experimental (how to enable).
- Authentication: API key.
- Connection: The key comes from
CLOUDFLARE_API_TOKEN. - Provider documentation: Authentication reference.
Credentials
Set these per environment. See Connect an integration.Setup
- Sign in to Cloudflare: Go to https://dash.cloudflare.com and sign in. A free account with at least one zone added is sufficient for testing.
- Create an API token: Open My Profile > API Tokens (https://dash.cloudflare.com/profile/api-tokens) and create a token. The ‘Edit zone DNS’ template covers the DNS tools; add Zone:Read and Account:Read permissions for listing.
- Set the environment variable: Add the token to your .env as CLOUDFLARE_API_TOKEN=… (use a scoped API token, not the legacy Global API Key).
- Verify access: Run the Verify Token tool, then List Zones.
Provider notes
- Cloudflare authenticates with ‘Authorization: Bearer <token>’
- Account-scoped endpoints need an account ID - use List Accounts to find yours
- Tokens can be scoped per zone; if List Zones returns nothing, widen the token’s zone resources
Tools
Verify the connection
Call a read tool such ascloudflare__verify_token with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.