# Cloudflare connector

[Product](https://paperclip.ing/product/) / [Connectors](https://paperclip.ing/product/connectors/) / Cloudflare

Find API operations and execute resource changes.

Category: [Developer tools](/product/connectors/?category=developer)
Tools from: [Cloudflare](https://raw.githubusercontent.com/cloudflare/mcp/259b2afc5aa84ce34461848d4fc36d817d49815e/README.md)
Sign-in: Choose a supported connection method
Works as: Agent tool

Source recorded: Sep 30, 2026

## Overview

Paperclip’s Cloudflare MCP connector gives your AI agents tools to find API operations and execute resource changes. Each tool can be Allowed, Ask first or Off.

The credential’s Cloudflare account, zone and permission scopes determine reach. Paperclip has no zone picker.

## What agents can do with Cloudflare

- Find the API operation before using it (`search`, `execute`)
- Inspect resources through the API (`search`, `execute`)
- Apply a reviewed configuration change (`search`, `execute`)

## How to connect Cloudflare

1. In Paperclip, open Connectors and select Cloudflare.
2. On the Access step, choose the identity and which agents may use the connection.
3. Select Sign in with Cloudflare for browser sign-in or Use an API key and enter a scoped Cloudflare API token.

[Setup guide](https://docs.paperclip.ing/connectors/cloudflare/)

## Cloudflare tools for agents (2)



### Write (2)

<div data-tool-name="execute" data-tool-class="write">
<code>execute</code>
<p class="c4-description-summary">Execute JavaScript code that can read, create, update, or delete resources through the Cloudflare API.</p>
<details class="faq-item c4-tool-description">
<summary class="faq-header" aria-label="Full description for execute">Full description</summary>

<pre class="faq-answer c4-description-text">Execute JavaScript code that can read, create, update, or delete resources through the Cloudflare API. First use the 'search' tool to find the right endpoints, then write code using the cloudflare.request() function.

Available in your code:

interface CloudflareRequestOptions {
  method: &quot;GET&quot; | &quot;POST&quot; | &quot;PUT&quot; | &quot;PATCH&quot; | &quot;DELETE&quot;;
  path: string;
  query?: Record&lt;string, string | number | boolean | undefined&gt;;
  body?: unknown;
  contentType?: string;  // Custom Content-Type header (defaults to application/json if body is present)
  rawBody?: boolean;     // If true, sends body as-is without JSON.stringify
}

interface CloudflareResponse&lt;T = unknown&gt; {
  success: boolean;
  status: number;
  result: T;
  errors: Array&lt;{ code: number; message: string }&gt;;
  messages: Array&lt;{ code: number; message: string }&gt;;
  result_info?: {
    page: number;
    per_page: number;
    total_pages: number;
    count: number;
    total_count: number;
  };
}

declare const cloudflare: {
  request&lt;T = unknown&gt;(options: CloudflareRequestOptions): Promise&lt;CloudflareResponse&lt;T&gt;&gt;;
};

declare const accountId: string;

// accountId is the account_id tool argument when passed; otherwise the session's account when it is authorized for exactly one. Reading it when neither applies throws an error.

When the session has access to multiple accounts, pass account_id. Call GET /accounts to discover available accounts. Paginate as needed, or filter by exact name with GET /accounts?name=&lt;exact account name&gt;.

Your code must be an async arrow function that returns the result.

Example: Worker with bindings (requires multipart/form-data):
async () =&gt; {
  const code = `addEventListener('fetch', e =&gt; e.respondWith(MY_KV.get('key').then(v =&gt; new Response(v || 'none'))));`;
  const metadata = { body_part: &quot;script&quot;, bindings: [{ type: &quot;kv_namespace&quot;, name: &quot;MY_KV&quot;, namespace_id: &quot;your-kv-id&quot; }] };
  const b = `--F${Date.now()}`;
  const body = [`--${b}`, 'Content-Disposition: form-data; name=&quot;metadata&quot;', 'Content-Type: application/json', '', JSON.stringify(metadata), `--${b}`, 'Content-Disposition: form-data; name=&quot;script&quot;', 'Content-Type: application/javascript', '', code, `--${b}--`].join(&quot;\r\n&quot;);
  return cloudflare.request({ method: &quot;PUT&quot;, path: `/accounts/${accountId}/workers/scripts/my-worker`, body, contentType: `multipart/form-data; boundary=${b}`, rawBody: true });
}</pre>
</details>
</div>

<div data-tool-name="search" data-tool-class="write">
<code>search</code>
</div>

This list describes the reviewed tools. Your selected method, provider access and action permissions determine what agents can use.

These lists use a conservative permission policy. Read requires a provider read-only hint or a reviewed Paperclip read rule. Evidence that an action changes data or submits information elsewhere puts it in Write. Write also includes actions we cannot verify as read-only. Read describes the reviewed evidence; it does not guarantee that an action has no side effects. A connected account can group actions differently.

This list includes Code Mode search and execute. Individual API operations are not separate tools. Search has no description because its wording depends on the account’s available products.



### Connection policies

Discovered actions follow the connection’s policies. Review their permissions and set actions to Ask first or Off as needed. Set execute to Ask first because this single tool can change or delete resources.

## Cloudflare connector FAQ

### Can I require approval for actions?

Set an action to Ask first to require human approval of each call or Off to prevent calls. Allowed actions run without approval. Read and Write grouping is separate from these settings.

### What can agents reach in Cloudflare?

The credential’s Cloudflare account, zone and permission scopes determine reach. Paperclip has no zone picker.

### What do I need before connecting?

Use a Cloudflare account with access to the intended resources or an API token with only the required permissions.


Ways to connect

- Sign in with Cloudflare
  - Use browser sign-in for the provider-hosted server.
- Use an API key
  - Use your own restricted key when browser sign-in is not suitable.

[Cloudflare connector](https://docs.paperclip.ing/connectors/cloudflare/)

[Set action permissions](https://docs.paperclip.ing/connectors/action-permissions/)

## Related connectors

- [GitHub](https://paperclip.ing/product/connectors/github/): Read code and pull requests, comment on issues.
- [Netlify](https://paperclip.ing/product/connectors/netlify/): Inspect projects and deploys and start deployments.
- [PagerDuty](https://paperclip.ing/product/connectors/pagerduty/): Inspect incidents, check schedules and update incidents.

## Give your agents Cloudflare.

Join the Paperclip waitlist to connect Cloudflare and choose what your agents can do.

[Join the waitlist](https://paperclip.ing/waitlist/)
