Skip to main content
Tembo and Cloudflare logos

Features

  • Access to the full Cloudflare API through Cloudflare’s official MCP server (https://mcp.cloudflare.com/mcp)
  • Coverage across Workers, DNS, R2, D1, KV, Zero Trust, and other Cloudflare products
  • Permissions you choose on Cloudflare’s authorization screen, so agents only get the access you grant

Prerequisites

You need access to your Tembo organization and a Cloudflare account with access to the accounts and zones you want Tembo to work with.

Installation

1

Open Integrations

In the Tembo app, go to Settings → Integrations.
2

Install Cloudflare

Scroll to the Developer Tools group and click Install next to Cloudflare.
3

Sign in to Cloudflare and choose permissions

Sign in with the Cloudflare account you want to connect. On the Authorize Tembo screen, review the base scopes. Open Advanced to edit them, then click Continue.
You can narrow the scopes further later in Cloudflare’s authorization flow. Grant only the access your agents need.
4

Confirm install

After authorizing, you’ll be redirected back to the Tembo Integrations page and Cloudflare will switch from uninstalled to installed.

Usage

Once installed, Tembo agents automatically have access to the Cloudflare MCP server during sessions. No further configuration is needed in Tembo. Start a new session and ask Tembo to list the Workers in your account, or to show the DNS records for a zone. Confirm that the returned data belongs to the account you intended to connect before asking Tembo to make changes.

Advanced

Cloudflare’s MCP server exposes two tools, search() and execute(). Agents search a typed representation of the Cloudflare API, then run code against it in a sandbox on Cloudflare. This gives agents access to the whole Cloudflare API without loading every endpoint as a separate tool. See Cloudflare’s MCP server documentation.
Tembo requests Cloudflare’s default base scopes (user:read and account:read). On the authorization screen you can switch to a different scope template or edit the scopes under Advanced. To change permissions later, uninstall Cloudflare in Settings → Integrations and install it again.
If the connection remains pending, return to Settings → Integrations and finish authorization. If tools do not appear, confirm the connection was saved and start a new session. If a request fails with a permissions error, reinstall Cloudflare and grant the scopes the task needs. See MCP troubleshooting for authentication and connectivity checks.