Cloudflare MCP Setup: Use Code Mode Without Granting Account-Wide Writes
Connect Cloudflare’s official remote API server at https://mcp.cloudflare.com/mcp with OAuth, grant only the account permissions you need, and keep Code Mode’s search-and-execute surface enabled. First confirm account and zone reads. Then add narrowly scoped permission for DNS, Workers, R2, or security changes only when each write has an explicit approval path.

Connect Cloudflare’s official remote API server at https://mcp.cloudflare.com/mcp with OAuth, grant only the account permissions you need, and keep Code Mode’s search-and-execute surface enabled. First confirm account and zone reads. Then add narrowly scoped permission for DNS, Workers, R2, or security changes only when each write has an explicit approval path.
Table of contents
- Which Cloudflare MCP server should you connect?
- How do you connect with OAuth or an API token?
- What does Code Mode change?
- How do you verify account and zone reads first?
- How do you gate DNS, Workers, R2, and security writes?
- How do you fix account, permission, transport, and Code Mode failures?
- FAQ
Which Cloudflare MCP server should you connect?
Connect to Cloudflare’s official remote API MCP server at https://mcp.cloudflare.com/mcp when the task involves managing Cloudflare through its API. Use OAuth, select only the account permissions required, and keep Code Mode enabled unless your client specifically needs individual API tools.
Cloudflare’s managed MCP server documentation identifies the supported route, while the Cloudflare API MCP repository provides the implementation reference. New connections use Streamable HTTP at /mcp, so the URL above is the operational starting point.
Keep API management separate from documentation lookup. If you need reference material first, MCPtrove’s Cloudflare Docs MCP remote entry is a practical directory step; return to the official API server for authenticated account actions.
After choosing a client such as Cursor, keep the server URL, authentication method, and permission scope visible to the operator. MCP architecture separates the host application, client connection, and server that exposes tools, so each boundary should be identifiable before a change is attempted. See the MCP architecture guide for that model.
How do you connect with OAuth or an API token?
Use OAuth for an interactive connection to the official remote server. For automation, use an API token with only the permissions required by the workflow.
In your MCP client, add the exact endpoint, choose OAuth, and complete the authorization flow presented by the client. Check the requested account permissions before accepting access. OAuth is the recommended path for a person connecting interactively because it keeps authorization in the connection flow.
Use an API token when an automated process requires token-based authentication. Create the token with the smallest permission set that covers the intended operation, rather than granting broad account access. Cloudflare’s API token guidance is the source for creating and scoping tokens.
If your client supports token authentication, provide the token through its supported secret mechanism. Do not paste it into prompts, documentation, shared configuration, or logs. A token that can read account data does not need permission to change DNS, deploy Workers, modify storage, or alter security settings.
Start with the least disruptive connection: authenticate, perform reads, and confirm the returned account and zone context. MCPtrove’s Config Doctor can be the next practical step when a client configuration needs a structured check.

What does Code Mode change?
Code Mode lets the client search for the needed Cloudflare API operation and execute it through a compact tool surface. It reduces the amount of tool description context the client must carry, but it does not replace permission controls or write approvals.
Cloudflare represents more than 2,500 API endpoints through a search-and-execute surface of roughly 1,000 tokens. Instead of exposing every individual API tool at connection time, the client can locate the relevant operation and then run it.
The default Code Mode path is therefore suited to broad API coverage with a smaller context footprint. It still requires the same authentication, account selection, and permission discipline as individual tools.
Appending ?codemode=false exposes individual API tools instead. That can consume far more client context, so use it only when a client or workflow specifically needs the non-Code-Mode shape. The Cloudflare MCP overview and API MCP repository document the current behavior.
Treat Code Mode as a tool-discovery choice, not as an authorization choice. Whether the client searches for an operation or displays separate tools, the account permissions and approval path remain your responsibility.
How do you verify account and zone reads first?
Verify authenticated account and zone reads before enabling any write permission. Confirm that the returned identity and resource context match the Cloudflare account and zone you intend to manage.
Begin with a read that establishes the authenticated account context. Then perform a zone read and check the returned zone identity, name, or other available context against the target you selected. Do not infer correctness merely because a tool was found or a request completed.
Use the responses to answer three questions:
- Is the connection authenticated as the intended Cloudflare identity?
- Is the intended account visible?
- Is the intended zone visible and distinct from any other available zone?
If an account or zone is missing, stop before changing permissions. Resolve the identity, account-selection, or access issue first. The MCP security best practices support treating authorization boundaries and user confirmation as explicit parts of an MCP deployment.
Only after the read results are correct should you consider a narrowly scoped write permission. Keep the initial verification repeatable so another operator can distinguish an account mismatch from a failed change.
How do you gate DNS, Workers, R2, and security writes?
Gate DNS, Workers, R2, and security writes separately from read access. Grant only the permissions needed for the specific change, and require explicit confirmation immediately before execution.
Treat each resource family as its own decision:
- DNS changes should identify the intended zone and record scope.
- Worker changes should identify the intended account, Worker, and deployment action.
- R2 changes should identify the intended storage resource and operation.
- Security changes should identify the account or zone setting being modified.
Before a write, state the target, requested change, and permission being used. If the client cannot make those details clear, keep the connection read-only until the configuration is understandable.
After a write, perform a read-back that confirms the resulting state. A successful tool call alone is not enough; the returned resource should match the requested target and change. If the result differs, stop and investigate rather than repeating the write.
For practical security guidance, consult MCPtrove’s article on what actually matters in MCP security, then apply the MCP security specification to the client, server, authorization, and confirmation boundaries.
How do you fix account, permission, transport, and Code Mode failures?
Fix failures by separating account selection, permission scope, transport, and tool-surface issues. Identify which layer failed before changing authentication or granting additional access.
| Symptom | Likely cause | Action |
|---|---|---|
| The wrong account or zone appears | Incorrect identity or account context | Reconnect, then repeat account and zone reads |
| A read or write is denied | Missing or excessive mismatch in permissions | Inspect the required account permissions and reduce or add only what the operation needs |
| The client cannot connect | Incorrect endpoint or transport handling | Use https://mcp.cloudflare.com/mcp with Streamable HTTP support |
| Search-and-execute is unavailable | Code Mode is disabled or unsupported by the client | Check whether the connection includes ?codemode=false; remove it when Code Mode is intended |
| Individual tools overload the client | Non-Code-Mode descriptions consume too much context | Return to the default endpoint without ?codemode=false |
Do not respond to every failure by granting account-wide access. First confirm the endpoint, then verify authentication, then inspect the requested permission, and finally check whether the client expects Code Mode or individual tools.
If the configuration remains unclear, use Config Doctor to organize the client-side checks. For architecture-level questions, consult the Cloudflare MCP overview before changing the connection design.