Cloudflare Api Key for AI agents

Cloudflare's API key access covers the same DNS, firewall, and zone management as its OAuth integration, for setups that authenticate with a key instead. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Security and identityAPI keyMCP + RESTcloudflare.com
AUDIT LOG · CLOUDFLARE API KEYPOLICY: acme-support
09:41:07 · claude · u_8f2read
cloudflare_api_key.list_zones
List Cloudflare Zones✓ allowed · 212ms
09:41:08 · claude · u_8f2read
cloudflare_api_key.get_ruleset
Get Ruleset✓ allowed · 164ms
09:41:09 · claude · u_8f2write
cloudflare_api_key.create_ruleset
Create Ruleset✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
cloudflare_api_key.delete_zone
Delete a zone✕ blocked · policy: deny
EVERY CLOUDFLARE API KEY CALL, ON THE RECORD
01 · USE CASES

What agents do in Cloudflare Api Key.

01

Check a zone's details

Check a zone's details and status before making a change to its configuration.

02

Create a firewall rule

Create a rule in a ruleset to block or challenge traffic matching a pattern.

03

Confirm before deleting a zone

Confirm before deleting a zone, since it removes DNS and security settings permanently.

02 · ACTIONS

25 Cloudflare Api Key actions, graded by risk.

Every Cloudflare Api Key action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

8

Look things up. Allowed by default.

  • cloudflare_api_key.list_zones
    List Cloudflare Zones
  • cloudflare_api_key.get_ruleset
    Get Ruleset
  • cloudflare_api_key.get_zone_details
    Get Zone Details
  • cloudflare_api_key.list_dns_records
    List DNS Records
  • cloudflare_api_key.get_lockdown_rule
    Get Lockdown Rule
  • cloudflare_api_key.get_regional_tiered_cache
    Get Regional Tiered Cache
  • cloudflare_api_key.get_cloudflare_ip_addresses
    Get Cloudflare IP Addresses
  • cloudflare_api_key.get_entrypoint_ruleset_version
    Get Entrypoint Ruleset Version

write

12

Create and change things. Allow, or ask the user first.

  • cloudflare_api_key.update_zone
    Update Cloudflare Zone
  • cloudflare_api_key.create_ruleset
    Create Ruleset
  • cloudflare_api_key.update_ruleset
    Update Ruleset
  • cloudflare_api_key.create_dns_record
    Create DNS Record
  • cloudflare_api_key.create_lockdown_rule
    Create Zone Lockdown Rule
  • cloudflare_api_key.update_dnssec_status
    Update DNSSEC Status
  • cloudflare_api_key.update_lockdown_rule
    Update Lockdown Rule
  • cloudflare_api_key.create_rule_in_ruleset
    Create Rule in Ruleset
  • cloudflare_api_key.update_rule_in_ruleset
    Update Rule in Ruleset
  • cloudflare_api_key.upload_file_to_s3
    Upload File to S3
  • cloudflare_api_key.overwrite_dns_record
    Overwrite DNS Record
  • cloudflare_api_key.rerun_zone_activation_check
    Rerun Zone Activation Check

destructive

5

Delete, cancel or archive. Ask first, or deny outright.

  • cloudflare_api_key.delete_zone
    Delete a zone
  • cloudflare_api_key.delete_dnssec
    Delete DNSSEC
  • cloudflare_api_key.delete_ruleset
    Delete Ruleset
  • cloudflare_api_key.delete_dns_record
    Delete DNS Record
  • cloudflare_api_key.delete_rule_from_ruleset
    Delete Rule from Ruleset
03 · HOW IT WORKS

Cloudflare Api Key in three steps.

  1. 01Your users connect Cloudflare Api KeyThey add their Cloudflare Api Key api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Ruleset” can wait for the user, and “delete a zone” can be denied outright.
  3. 03Any agent can actYour agent calls Cloudflare Api Key through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('cloudflare_api_key', {
  read: 'allow',
  write: 'ask',        // create_ruleset
  destructive: 'deny',  // delete_zone
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Cloudflare Api Key connects.

Users add their Cloudflare Api Key api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Cloudflare Api Key connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Cloudflare Api Key from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Cloudflare Api Key and Arc0, answered.

Q01

Can I use Cloudflare Api Key with Claude, ChatGPT or Cursor?

Yes. Connect Cloudflare Api Key to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Cloudflare Api Key actions you allow.

Q02

How do users connect Cloudflare Api Key?

Users add their Cloudflare Api Key api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Cloudflare Api Key actions can my agent take?

25 in total: 8 read, 12 write and 5 destructive, such as “create Ruleset”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Cloudflare Api Key?

Yes. Actions like “delete a zone” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Cloudflare Api Key too?

Yes. The same Cloudflare Api Key connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Cloudflare Api Key into your agent.

Your users connect Cloudflare Api Key once, under your brand. Your agent gets 25 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan