The bridge from K2 agents through Wrangler to your master AI - safe, approval-gated Cloudflare ops.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag — we're steadily working through the catalog.
💡 Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
-/\-\ M H // WT
WT WALRUS TUSK
🦣 Walrus Tusk home · FAQ · Docs
An approval-gated Cloudflare operations suite with an optional private Agent Harness: bounded delegation, deterministic verification, OAuth-isolated MCP tools, and verified deploy checks without handing agents raw account credentials.
Latest update - v0.5.3: the owner-supplied WT Connected OAuth setup UI is now the only success-page renderer. Every release runs it in Chromium under the production security policy and verifies the WT/AMH identity, all four copy controls, phone layout, images, and legacy-link removal. See the latest release.
Cloudflare Ops MCP scans Cloudflare configuration, computes a diff of desired vs current DNS / Email Routing / BIMI / DMARC / SPF / Pages / cache / Turnstile setup, and applies fixes only after explicit approval. It is built for people who want an AI agent to help with Cloudflare safely: scan first, show the plan, then write only when the owner approves.
Version 0.5.3 works five ways:
cfops locally with a scoped Cloudflare token.cfops_ connector key. The owner's API token is never shared.agent/ Worker behind the MCP Worker's AGENT_HARNESS service binding for bounded jobs, health watches, schedules, audit, and the authenticated operator console at console.artificialmindhive.com/console.For repository-connected deployments, see GIT-INTEGRATION.md. The recommended route uses Cloudflare Workers Builds' GitHub App authorization; the MCP does not store a GitHub token.
Machine discovery is available at robots.txt, sitemap.xml, llms.txt, and walrus-tusk.md. These describe the public landing and documentation; authenticated MCP and OAuth callback routes remain excluded from crawling.
Cloudflare Ops MCP is especially useful for Cloudflare operators who need repeatable DNS hygiene across many zones: SPF cleanup, DMARC enforcement, BIMI records, MX checks, DKIM discovery, Cloudflare Email Routing, TXT verification records, safe DNS upserts, and audit logs for every approved write.
Unofficial Cloudflare tool. Cloudflare Ops MCP is made by AMH - Artificial Mind Hive, operated by Service Pricer LLC. It is independent, third-party, open-source software. It is not affiliated with, endorsed by, sponsored by, or made by Cloudflare, Inc. "Cloudflare" and "Wrangler" are referenced only to describe compatibility with Cloudflare's platform and official developer tooling. You are responsible for every DNS, Email Routing, DMARC, BIMI, SPF, or Worker change you approve and apply.
No owner's API key in Git or in your client. Public users authorize Cloudflare directly. OAuth access and refresh tokens stay server-side in KV; the connector key is stored only as a SHA-256 hash and is bound to one OAuth grant.
Cloudflare Ops MCP is focused on the Cloudflare tasks that regularly break launches, email trust, bot checks, cache freshness, brand display, and AI-agent workflows:
This is not meant to replace every Cloudflare feature. It is the narrow, safe lane for common Cloudflare ops an operator or AI agent should be allowed to do.
The examples below are intentionally direct. They are not toy examples. They show the exact dry-run -> review -> apply pattern users should follow when fixing real domains.
Use this when an old registrar, parking page, Vercel app, HugeDomains page, or stale A/AAAA records are blocking a Cloudflare Pages custom domain.
Dry-run first:
Apply only after reviewing the delete/create plan:
What it changes:
--wildcard.Options:
--no-www only cuts over the apex domain.--wildcard also removes conflicting *.example.com A/AAAA/CNAME records.Wrangler is Cloudflare's official developer CLI. Cloudflare Ops MCP can run without Wrangler as a local CLI/library, but Wrangler is the right path when you want a remote MCP server because it deploys the Worker, stores secrets, tails logs, and manages Cloudflare bindings from the same toolchain Cloudflare documents.
Use Wrangler when you want:
|
Agent-safe Cloudflare writes Cloudflare Ops MCP keeps the write path narrow: scan the target, show the diff, wait for explicit approval, then apply only the requested DNS, DMARC, BIMI, SPF, Email Routing, Pages, cache, or Turnstile change. |
|
Per-user OAuth isolation Public users connect their own Cloudflare account and receive an opaque |
|
Email trust diagnostics The scanner reports SPF, DKIM discovery, DMARC policy, BIMI readiness, MX records, and Cloudflare Email Routing status so an agent or operator can see what is missing before touching production DNS. |
|
Other highlights
|
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/amh-cloudflare-ops-mcp-by-wt)<a href="https://allmcps.com/mcp/amh-cloudflare-ops-mcp-by-wt"><img src="https://allmcps.com/api/badge/amh-cloudflare-ops-mcp-by-wt?style=directory" alt="AMH Cloudflare Ops MCP by WT on AllMCPs" /></a>