The bridge from K2 agents through Wrangler to your master AI - safe, approval-gated Cloudflare ops.
MCPpedia last refreshed this data
io.github.pain2hustle/cloudflare-ops-mcp is an MCP server that the bridge from K2 agents through Wrangler to your master AI - safe, approval-gated Cloudflare ops. Its tool list has not been published yet over http, requires no API key, and scores 87/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"cloudflareOps": {
"url": "https://cfops.nothingunseen.com/mcp",
"headers": {
"Authorization": "Bearer cfops_YOUR_CONNECTOR_KEY"
}
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
An approval-gated Cloudflare operations suite with an optional private Agent Harness: bounded delegation, deterministic verification, OAuth-isolated MCP tools, and verified deploy checks without handing agents raw account credentials.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y 'cloudflare-ops-mcp' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
No known CVEs.
Checked cloudflare-ops-mcp against OSV.dev.
Click any tool to inspect its schema.
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in cloud
MCP Server for GCP environment for interacting with various Observability APIs.
Evidence-grounded agent memory with mandatory provenance, on local SQLite or Cloudflare D1
MCP Server for kubernetes management commands
Upload, organize, search, and transform images, videos, and files with AI-powered tools.
MCP Security Weekly
Get CVE alerts and security updates for io.github.pain2hustle/cloudflare-ops-mcp and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
-/\-\ M H // WT
WT WALRUS TUSK
🦣 Walrus Tusk home · FAQ · Docs
An approval-gated Cloudflare operations suite with an optional private Agent Harness: bounded delegation, deterministic verification, OAuth-isolated MCP tools, and verified deploy checks without handing agents raw account credentials.
Latest update - v0.5.3: the owner-supplied WT Connected OAuth setup UI is now the only success-page renderer. Every release runs it in Chromium under the production security policy and verifies the WT/AMH identity, all four copy controls, phone layout, images, and legacy-link removal. See the latest release.
Cloudflare Ops MCP scans Cloudflare configuration, computes a diff of desired vs current DNS / Email Routing / BIMI / DMARC / SPF / Pages / cache / Turnstile setup, and applies fixes only after explicit approval. It is built for people who want an AI agent to help with Cloudflare safely: scan first, show the plan, then write only when the owner approves.
Version 0.5.3 works five ways:
cfops locally with a scoped Cloudflare token.cfops_ connector key. The owner's API token is never shared.agent/ Worker behind the MCP Worker's AGENT_HARNESS service binding for bounded jobs, health watches, schedules, audit, and the authenticated operator console at console.artificialmindhive.com/console.For repository-connected deployments, see GIT-INTEGRATION.md. The recommended route uses Cloudflare Workers Builds' GitHub App authorization; the MCP does not store a GitHub token.
Machine discovery is available at [robots.txt](https://mcp.artificialmindhive.com/robots.tx