BunnyCDN for AI agents
BunnyCDN delivers websites, files, and media through a global content delivery network, letting a team manage pull zones, storage, and DNS from one API. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in BunnyCDN.
Create a new pull zone
Set up a new pull zone to start caching and delivering an origin site through the CDN.
Add a DNS record
Add a DNS record to a zone, such as pointing a subdomain at a new pull zone.
Confirm before deleting a storage zone
Confirm before deleting a storage zone, since every file stored there is removed with it.
129 BunnyCDN actions, graded by risk.
Every BunnyCDN action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
81Look things up. Allowed by default.
- bunnycdn.get_groupGet Database Group
- bunnycdn.get_limitsGet Database Limits
- bunnycdn.get_oembedGet oEmbed
- bunnycdn.list_groupList Database Groups
- bunnycdn.list_nodesList Nodes
- bunnycdn.get_databaseGet Database
- bunnycdn.list_regionsList Regions
- bunnycdn.list_volumesList Volumes
- bunnycdn.get_languagesGet Languages
- bunnycdn.get_pull_zoneGet Pull Zone
- bunnycdn.list_api_keysList API Keys
- bunnycdn.get_statisticsGet Statistics
- bunnycdn.get_user_auditGet User Audit Log
- bunnycdn.get_shield_zoneGet Shield Zone
- bunnycdn.get_user_limitsGet User Limits
- bunnycdn.get_user_detailsGet User Details
write
32Create and change things. Allow, or ask the user first.
- bunnycdn.update_groupUpdate Database Group
- bunnycdn.add_blocked_ipAdd Blocked IP
- bunnycdn.create_databaseCreate Database
- bunnycdn.update_databaseUpdate Database
- bunnycdn.add_storage_zoneAdd Storage Zone
- bunnycdn.create_pull_zoneCreate Pull Zone
- bunnycdn.update_pull_zoneUpdate Pull Zone
- bunnycdn.create_dns_recordCreate DNS Record
- bunnycdn.create_live_live2Create Live Live 2
- bunnycdn.update_shield_zoneUpdate Shield Zone
- bunnycdn.add_allowed_refererAdd Allowed Referer
- bunnycdn.add_blocked_refererAdd Blocked Referer
- bunnycdn.update_storage_zoneUpdate Storage Zone
- bunnycdn.update_user_detailsUpdate User Details
- bunnycdn.add_update_edge_ruleAdd/Update Edge Rule
- bunnycdn.create_coinify_paymentCreate Coinify Payment
destructive
16Delete, cancel or archive. Ask first, or deny outright.
- bunnycdn.delete_groupDelete Database Group
- bunnycdn.delete_databaseDelete Database
- bunnycdn.delete_dns_zoneDelete DNS Zone
- bunnycdn.delete_edge_ruleDelete Edge Rule
- bunnycdn.delete_pull_zoneDelete Pull Zone
- bunnycdn.delete_dns_recordDelete DNS Record
- bunnycdn.remove_blocked_ipRemove Blocked IP
- bunnycdn.delete_storage_zoneDelete Storage Zone
- bunnycdn.remove_allowed_refererRemove Allowed Referer
- bunnycdn.remove_blocked_refererRemove Blocked Referer
- bunnycdn.delete_container_registryDelete Container Registry
- bunnycdn.delete_shield_zone_access_listDelete Shield Zone Access List
- bunnycdn.purge_urlPurge URL
- bunnycdn.purge_pull_zonePurge Pull Zone
- bunnycdn.reset_whats_newReset What's New
- bunnycdn.reset_pull_zone_security_keyReset Pull Zone Security Key
BunnyCDN in three steps.
- 01Your users connect BunnyCDNThey add their BunnyCDN api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Database” can wait for the user, and “delete Database Group” can be denied outright.
- 03Any agent can actYour agent calls BunnyCDN through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('bunnycdn', { read: 'allow', write: 'ask', // create_database destructive: 'deny', // delete_group }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How BunnyCDN connects.
Users add their BunnyCDN api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same BunnyCDN connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use BunnyCDN from any agent.
BunnyCDN and Arc0, answered.
Can I use BunnyCDN with Claude, ChatGPT or Cursor?
Yes. Connect BunnyCDN to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the BunnyCDN actions you allow.
How do users connect BunnyCDN?
Users add their BunnyCDN api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which BunnyCDN actions can my agent take?
129 in total: 81 read, 32 write and 16 destructive, such as “create Database”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in BunnyCDN?
Yes. Actions like “delete Database Group” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call BunnyCDN too?
Yes. The same BunnyCDN connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug BunnyCDN into your agent.
Your users connect BunnyCDN once, under your brand. Your agent gets 129 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan