Your Cloudflare
stays yours.
Copy this connector key now. It is not your Cloudflare API token. The server stores only its SHA-256 hash and binds it to this one OAuth connection.
cfops_ztU2Inzs_C86Auw6XnwbQlmAkCZQtISLApNqHgD-2o4
Claude / Cursor
mcpServers
{
"mcpServers": {
"cloudflareOps": {
"url": "https://cfops.nothingunseen.com/mcp",
"headers": {
"Authorization": "Bearer cfops_ztU2Inzs_C86Auw6XnwbQlmAkCZQtISLApNqHgD-2o4"
}
}
}
}
Codex CLI
env var
codex mcp add cloudflare-ops \
--url https://cfops.nothingunseen.com/mcp \
--bearer-token-env-var CFOPS_CONNECTOR_KEY
# then in your own environment:
export CFOPS_CONNECTOR_KEY=cfops_ztU2Inzs_C86Auw6XnwbQlmAkCZQtISLApNqHgD-2o4
This key is shown once. Keep it private like a password. You can disconnect it later or revoke the app in Cloudflare.
1 · Paste it
Drop the configuration into your MCP client and restart it. The client calls initialize and tools/list on its own.
2 · Ask plainly
"Scan example.com and explain the DNS and email-auth problems. Do not write anything."
3 · Approve writes
Mutating tools return a dry-run diff unless the caller sends apply: true. Read the diff, then approve.