Skip to content

Cloudflare MCP connector

The Cloudflare connector lets Claude, ChatGPT, Cursor, or any MCP client look up your Cloudflare accounts, zones, members, roles, firewall rules, rule sets, WAF overrides, and audit logs through one governed Elaichi endpoint, inside each person's own access.

  • How it connects. Connects with an API key. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect Cloudflare to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Cloudflare once

  1. Open Connections, choose Add connection, and pick Cloudflare.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Paste a Cloudflare API key. One person generates a token in Cloudflare and pastes it once. Everyone else works through Share with, and never sees it.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

cloudflare
Cloudflare
Apache Airflow
Apify
Boomi
Browserbase
Caspio
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Cloudflare MCP connector for Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Cloudflare MCP connector for ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Cloudflare MCP connector for Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Cloudflare to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Cloudflare through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • Security

    Review firewall rules before a change window

    Ask which firewall rules and rule sets are active on a zone and get them read back in plain language before anyone touches production.

  • IT

    Check who still has access to Cloudflare

    List every member across your Cloudflare accounts with their roles, then spot contractors and former staff who should no longer be there.

  • Compliance

    Pull Cloudflare audit history for a review

    When an auditor asks who changed what and when, have the agent read the Cloudflare audit log for the period and summarize it.

  • Support

    Find the zone behind a customer domain

    When a customer says their site is misbehaving, look up the zone it sits in and read its details without opening the Cloudflare dashboard.

  • Engineering

    Compare rule sets across staging and production

    Fetch the rule sets attached to two zones and ask where they differ before a release goes out.

  • Operations

    Inventory every domain across accounts

    List all zones across every Cloudflare account you manage for a quarterly ownership review, in one question instead of account by account.

Try asking

  • “Which zones changed firewall rules in the last week?”
  • “List members with admin roles on our production account.”
  • “Show WAF overrides active across all Cloudflare zones.”

See all 12 Cloudflare tools below

Compare

Elaichi vs Zapier MCP vs Composio for Cloudflare

All three can connect Cloudflare to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

Elaichi compared with Zapier MCP and Composio for Cloudflare, by what to check
What to check Elaichi Zapier MCP Composio
Where the AI connects One address for the whole organization. https://api.elaichi.ai/mcp A server per member, created at sign-in. An MCP endpoint per team, or an SDK.
Control over Cloudflare tools Allow or restrict single Cloudflare tools, per role or user. App and action restrictions on the account. Role permissions, down to the action.
Record of calls One audit entry per Cloudflare call. A History tab of tool calls. A log of every tool call.
Single sign-on SAML or OIDC, plus SCIM, on Gold. SAML on Enterprise. SAML and OIDC on Enterprise.
Price $15 per user per month. 2 tasks per successful call. Billed per tool call.

Sources: Zapier MCP docs, security, usage; Composio docs, gateway, enterprise, pricing. Checked September 2026.

Longer take: Zapier MCP alternative and when you don't need an MCP gateway.

AI tools

Cloudflare tools for your AI agents

12 tools are ready to call through Elaichi's MCP endpoint the moment you connect Cloudflare, governed by the same roles, restrictions, and audit log as everything else in Elaichi.

See it in Elaichi

What connecting Cloudflare gets you

6 screens from the product, each doing one job for your Cloudflare account.

The agent

Ask about zones, get answers from Cloudflare.

Plain language questions return live zones, firewall rules and members.

  • zones
  • firewall rules
  • members
  • rule sets

Ask Elaichi to work across your apps.

Which zones changed firewall rules in the last week?

List members with admin roles on our production account.

Show WAF overrides active across all Cloudflare zones.

Also runs in Claude, ChatGPT or Cursor

MCP clients

Claude, ChatGPT and Cursor reach Cloudflare.

One org MCP endpoint over OAuth, no SDK and no shared API key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emily Carter

• Connected 4 minutes ago
Cursor
M

Megan Brooks

• Connected 2 hours ago
ChatGPT
R

Ryan Hayes

• Connected Yesterday

Tool catalog

12 Cloudflare tools ready on connect.

Accounts, zones, members, roles, firewall rules and rule sets, no custom code.

  • List all Cloudflare accounts
  • Get single Cloudflare account by ID
  • List all Cloudflare members
  • Get single Cloudflare member by ID
ElaichiTools
Tool Action Description
List all Cloudflare accounts List List all accounts you have ownership or verified access to. Use the name query parameter to filter by account name.
Get single Cloudflare account by ID Get Get information about a specific Cloudflare account that you are a member of. Always requires the id to fetch.
List all Cloudflare members List Use this endpoint to get all the team members in a Cloudflare account.
Get single Cloudflare member by ID Get Use this endpoint to get a single team member in a Cloudflare account. Always requires the id to fetch.
List all Cloudflare roles List Use this endpoint to list all the roles available in Cloudflare.

Toolboxes

Every team gets its own Cloudflare toolbox.

Curate one toolbox per team, from zone reads to WAF overrides.

  • Platform
  • Security
  • SRE
  • Engineering
ElaichiToolboxes
Name Source template Tools Created

Platform toolbox

Cloudflare · zones and accounts

Cloudflare starter 18 Mar 4, 2026

Security toolbox

Cloudflare · firewall rules and WAF overrides

— 9 Mar 2, 2026

SRE toolbox

Cloudflare · rule sets and zone settings

— 24 Feb 27, 2026

Engineering toolbox

Cloudflare · zone reads and configuration

Cloudflare starter 6 Feb 19, 2026

IT toolbox

Cloudflare · members and roles

— 31 Jan 30, 2026

Compliance toolbox

Cloudflare · audit logs and access reviews

— 12 Jan 22, 2026

Shared connections

Teammates use Cloudflare without touching the token.

See who connected each account and which teams and members share it.

  • Production
  • Staging
  • Security
  • Marketing sites
ElaichiConnections
Connection Scope Status Access
CL

Cloudflare (Production)

Connected by Emily Carter

Personal • Active 1 team · 6 members
CL

Cloudflare (Staging)

Connected by Jake Morgan

Organization • Active 3 teams · 24 members
CL

Cloudflare (Security)

Connected by Megan Brooks

Organization • Active 2 teams · 11 members
CL

Cloudflare (Marketing sites)

Connected by Tyler Reed

Personal • Needs re-auth 1 team · 3 members
CL

Cloudflare (Customer edge)

Connected by Ryan Hayes

Personal • Active Not shared
CL

Cloudflare (Internal tools)

Connected by Ashley Parker

Personal • Active 2 teams · 9 members

Audit log

Every Cloudflare call has a name on it.

When, who, what happened, type and resource, appended and never edited.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emily Carter

emily.carter@northwind.io

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

Jake Morgan

jake.morgan@northwind.io

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

M

Megan Brooks

megan.brooks@northwind.io

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

T

Tyler Reed

tyler.reed@northwind.io

Cloudflare Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

R

Ryan Hayes

ryan.hayes@northwind.io

Cloudflare Zones Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

A

Ashley Parker

ashley.parker@northwind.io

Cloudflare Zones List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule fires, a Cloudflare digest ships.

Fetch zones and firewall rules, group them, draft, approve, post back.

Cloudflare digest

Run 418 · started 2 minutes ago · on behalf of Emily Carter

  1. ✓

    Schedule

    Every weekday at 8:00 AM

    0.2s
  2. ✓

    Fetch zones

    Cloudflare

    1.4s
  3. ✓

    Group by owner

    Transform

    0.1s
  4. ✓

    Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Cloudflare

    Queued

Collections and dashboards

Cloudflare zone health, counted on a schedule.

Four metrics, 14 days of records created, split by team, no model involved.

Cloudflare health

Refreshed 4 minutes ago · every 15 minutes · from the zones collection

Live

Zones

1,284 ↓ 12%

Firewall rules

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Zones created

Last 14 days

By team

Share of activity

Production 34%

Staging 27%

Security 21%

Marketing sites 18%

FAQ

Frequently asked questions

How do I connect Cloudflare to Claude?

Connect Cloudflare in Elaichi first, then open Claude, go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Cloudflare connects with an API key, so the sign-in step is pasting a key from your Cloudflare account into Elaichi. There is no OAuth application to register and no client ID or secret to generate.

Does Cloudflare work with ChatGPT and Cursor as well as Claude?

Yes. Once Cloudflare is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. You connect Cloudflare once and every client you use sees it.

What can an AI agent actually do with my Cloudflare data?

With the Cloudflare connector, an agent can list your accounts, zones, members and their roles, firewall rules, rule sets, WAF overrides, and audit logs, and look up any one of them by ID. That means you can ask in plain language which firewall rules protect a domain, who has access to an account, or what changed last week, and get an answer from live Cloudflare records. This connector reads Cloudflare; it does not change settings.

Does connecting Cloudflare give the AI access to every account and zone?

No. Everything the agent sees in Cloudflare follows the access of the person who signed in with their key, so it can only read the accounts and zones that person can already read in Cloudflare. Elaichi can narrow that further with restrictions per action, and it can never widen it beyond what Cloudflare itself allows.

Can my team share one Cloudflare connection?

Yes. One person connects Cloudflare in Elaichi and shares the connection with a team, and nobody else ever handles the Cloudflare API key. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person behind every lookup of a zone or firewall rule.

Can I stop an agent from deleting or changing things in Cloudflare?

The Cloudflare connector in Elaichi only lists and looks up records such as zones, firewall rules, and members, so there is nothing here that deletes or changes a Cloudflare setting. On top of that, Elaichi restrictions work per action, so you can turn off any individual capability for a team. A blocked action is never advertised to Claude, ChatGPT, or Cursor, so no prompt can reach it.

What happens to a Cloudflare connection when someone leaves?

Offboarding a person in Elaichi ends their access to Cloudflare through Elaichi at once, across every client they used. A shared Cloudflare connection keeps working for everyone else on the team. If you want to remove Cloudflare entirely, disconnecting it once in Elaichi removes it from Claude, ChatGPT, Cursor, and every other client at the same time.

Does the Cloudflare MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Cloudflare is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

Is Elaichi an alternative to Zapier MCP for Cloudflare?

Yes. Both let Claude, ChatGPT or Cursor use Cloudflare. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Cloudflare call.

How is Elaichi different from Composio for Cloudflare?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Cloudflare: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

Put Cloudflare in front of your team

14 days on Gold, no credit card. Connect it once and pick what each team can call.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.