Paperclip’s Cloudflare MCP connector gives your AI agents tools to find API operations and execute resource changes. Each tool can be Allowed, Ask first or Off.
The credential’s Cloudflare account, zone and permission scopes determine reach. Paperclip has no zone picker.
What agents can do with Cloudflare
- Find the API operation before using it
search·execute - Inspect resources through the API
search·execute - Apply a reviewed configuration change
search·execute
How to connect Cloudflare
- In Paperclip, open Connectors and select Cloudflare.
- On the Access step, choose the identity and which agents may use the connection.
- Select Sign in with Cloudflare for browser sign-in or Use an API key and enter a scoped Cloudflare API token.
Cloudflare tools for agents2
Write 2
executeExecute JavaScript code that can read, create, update, or delete resources through the Cloudflare API.
Full description
Execute JavaScript code that can read, create, update, or delete resources through the Cloudflare API. First use the 'search' tool to find the right endpoints, then write code using the cloudflare.request() function. Available in your code: interface CloudflareRequestOptions { method: "GET" | "POST" | "PUT" | "PATCH" | "DELETE"; path: string; query?: Record<string, string | number | boolean | undefined>; body?: unknown; contentType?: string; // Custom Content-Type header (defaults to application/json if body is present) rawBody?: boolean; // If true, sends body as-is without JSON.stringify } interface CloudflareResponse<T = unknown> { success: boolean; status: number; result: T; errors: Array<{ code: number; message: string }>; messages: Array<{ code: number; message: string }>; result_info?: { page: number; per_page: number; total_pages: number; count: number; total_count: number; }; } declare const cloudflare: { request<T = unknown>(options: CloudflareRequestOptions): Promise<CloudflareResponse<T>>; }; declare const accountId: string; // accountId is the account_id tool argument when passed; otherwise the session's account when it is authorized for exactly one. Reading it when neither applies throws an error. When the session has access to multiple accounts, pass account_id. Call GET /accounts to discover available accounts. Paginate as needed, or filter by exact name with GET /accounts?name=<exact account name>. Your code must be an async arrow function that returns the result. Example: Worker with bindings (requires multipart/form-data): async () => { const code = `addEventListener('fetch', e => e.respondWith(MY_KV.get('key').then(v => new Response(v || 'none'))));`; const metadata = { body_part: "script", bindings: [{ type: "kv_namespace", name: "MY_KV", namespace_id: "your-kv-id" }] }; const b = `--F${Date.now()}`; const body = [`--${b}`, 'Content-Disposition: form-data; name="metadata"', 'Content-Type: application/json', '', JSON.stringify(metadata), `--${b}`, 'Content-Disposition: form-data; name="script"', 'Content-Type: application/javascript', '', code, `--${b}--`].join("\r\n"); return cloudflare.request({ method: "PUT", path: `/accounts/${accountId}/workers/scripts/my-worker`, body, contentType: `multipart/form-data; boundary=${b}`, rawBody: true }); }
search
Tool availability and permissions
This list describes the reviewed tools. Your selected method, provider access and action permissions determine what agents can use.
These lists use a conservative permission policy. Read requires a provider read-only hint or a reviewed Paperclip read rule. Evidence that an action changes data or submits information elsewhere puts it in Write. Write also includes actions we cannot verify as read-only. Read describes the reviewed evidence; it does not guarantee that an action has no side effects. A connected account can group actions differently.
This list includes Code Mode search and execute. Individual API operations are not separate tools. Search has no description because its wording depends on the account’s available products.
Connection policies
Discovered actions follow the connection’s policies. Review their permissions and set actions to Ask first or Off as needed. Set execute to Ask first because this single tool can change or delete resources.
Cloudflare connector FAQ
Can I require approval for actions?
Set an action to Ask first to require human approval of each call or Off to prevent calls. Allowed actions run without approval. Read and Write grouping is separate from these settings.
What can agents reach in Cloudflare?
The credential’s Cloudflare account, zone and permission scopes determine reach. Paperclip has no zone picker.
What do I need before connecting?
Use a Cloudflare account with access to the intended resources or an API token with only the required permissions.