Cloudflare MCP server
Last verified: 2026-09
Workers, KV, R2, and DNS via Cloudflare.
Community Cloud & infra Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code
What it does
Cloudflare's MCP repo is now a set of remote servers (docs, bindings, observability, Workers), not one npx that does everything. Pick the hosted server that matches the job and OAuth into your account.
It sits in Cloud & infra: Most of these are admin APIs.
Good for
- Pick one remote Cloudflare MCP from their table (docs vs Workers) and OAuth that.
- Ask a docs question before connecting the account that owns production DNS.
- Read KV/R2/D1 only with a scoped token, not Global API Key.
- Skip it if the host is Vercel or Netlify.
Tools
- Workers / KV / R2 / D1 / docs (per server) — Each remote Cloudflare MCP exposes its own tools. See the repo's 'which server' table.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"cloudflare": {
"command": "npx",
"args": [
"-y",
"@cloudflare/mcp-server-cloudflare"
],
"env": {
"CLOUDFLARE_API_TOKEN": "optional if using OAuth remote"
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y @cloudflare/mcp-server-cloudflare
Secrets it wants: CLOUDFLARE_API_TOKEN
How to get started
- Open the repo table, pick one remote URL (docs vs Workers).
- Connect OAuth in the host. Ask a read-only question first.
- Do not connect the account that owns production DNS on the first try.
Access risk
Workers and DNS tokens can take a site down. Prefer a scoped API token over global.
When to skip it
Skip it for Vercel/Netlify if that is the host, or for a local wrangler-only workflow.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| Cloudflare | No | Yes | Workers, KV, R2, and DNS via Cloudflare. |
| Vercel | No | Yes | Projects and deployments on Vercel. |
| Netlify | No | Yes | Sites and deploys on Netlify. |
| AWS | No | Yes | Call AWS APIs with the default credential chain. |
More in Cloud & infra
FAQ
Why didn't npx @cloudflare/mcp-server-cloudflare do everything?
The repo is now a set of remote servers, not one stdio that is all of Cloudflare. Open the 'which server' table.
Global API key?
No. Scoped API token or OAuth. Workers and DNS tokens can take a site down.
Cloudflare or Vercel?
Match the host. Two deploy tokens in one chat is how the wrong project ships.
Official?
Yes — cloudflare/mcp-server-cloudflare.