Skip to main content
Let your agents manage Cloudflare zones and DNS records, purge the cache, read zone settings and rulesets, and work with Workers, KV and Pages.

Connection

  • Authentication: API key (API token).
Sign in at dash.cloudflare.com → My Profile → API Tokens → Create Token. Start from the “Edit zone DNS” template or a custom token with the permissions you want your agents to have: Zone:Read, DNS:Edit, Cache Purge:Purge, Account Settings:Read, Workers Scripts:Read, Workers KV Storage:Edit, Cloudflare Pages:Read. Scope it to the zones/accounts concerned, create it and copy the token (shown once). Do not use the Global API Key.See Cloudflare’s documentation.

Read actions (14)

Write actions (4)

Permissions

Every action above must be explicitly granted to an agent before it can be used. See Permissions for the grant model and Security for how credentials are protected.
Last reviewed against the provider API: September 2026.