In-depth architectural comparison of the Cloud Tools and Cloudflare MCP Pro MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.
At a Glance & Executive Verdict
Cloud Tools
Cloud Platforms · Local stdio
Quality: 61/100 (Good) | Auth: other
Cloudflare MCP Pro
Cloud Platforms · Local stdio
Quality: 60/100 (Good) | Auth: API Key required
Verdict Summary: Choose Cloud Tools if you need specialized Cloud Platforms tools running via a local process. Choose Cloudflare MCP Pro if your workspace requires Cloud Platforms integration with local subprocess execution. Both servers can be configured concurrently in your client's mcpServers manifest.
Which MCP Server Should You Choose?
Choose Cloud Tools when:
You need dedicated capabilities in the Cloud Platforms domain.
You prefer local stdio subprocess transport architecture.
Your security boundary fits: other (Free / Open Source).
You have access to required keys: AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_PROFILE, GOOGLE_APPLICATION_CREDENTIALS, CLOUDFLARE_API_TOKEN, CLOUDFLARE_ACCOUNT_ID, OVH_APPLICATION_KEY, OVH_CONSUMER_KEY.
Multi-cloud cost, inventory and waste analysis over MCP: AWS, GCP, Cloudflare and OVH.
The most complete Cloudflare MCP — 69 tools over the REST API v4 (DNS, Zones, Workers, KV, R2, D1, Pages, WAF, SSL, Email Routing, Logpush, Workers AI) in a single local stdio server, with a server-side human-approval gate on every mutation. npx -y cloudflare-mcp-pro.
This period against the same day window of the previous month, so a partial month does not read as a fall. AWS and GCP only. GCP needs credentials.gcp.billing_table.
get_commitments
Commitments you are paying for, and whether you are consuming them, over the last 30 days. AWS: Savings Plans utilisation, coverage of eligible spend, and the saving a further commitment would give. GCP: committed use discounts with their expiry. Not implemented for Cloudflare or OVH, which sell no commitments.
get_costs
Cloud spend. AWS: by service over a date range, from Cost Explorer; pass group_by="data_transfer" for transfer cost by usage type. GCP: by service from the BigQuery billing export, which credentials.gcp.billing_table must name — without it you get budget amounts, not spend. Cloudflare: subscriptions and zone plan costs. OVH: the 6 most recent invoices.
get_cross_cloud_summary
One cost and waste report over every cloud you pass credentials for, with a grand total. Omit a cloud's credentials to skip it.
Ready-to-Paste Client Configurations
Paste either (or both) of these JSON server blocks into your client config file (e.g. claude_desktop_config.json or ~/.cursor/mcp.json).
Cloud Tools is categorized under Cloud Platforms and uses a local stdio subprocess. In contrast, Cloudflare MCP Pro belongs to Cloud Platforms using local stdio subprocess. Select Cloud Tools when you need capabilities focused on cloud platforms and Cloudflare MCP Pro when you require tools for cloud platforms.
What exists. GCP: GCE instances, disks, addresses, snapshots, forwarding rules, GKE clusters with node pools, Cloud SQL, Cloud Functions, Cloud Run, GCS buckets, Cloud NAT, Cloud IDS, Artifact Registry, VPN gateways, subnets, PSC endpoints and Cloud Logging ingestion, with a per-project summary. Cloudflare: zones with plan and price, DNS records split proxied against dns-only, certificates with hosts and expiry, and Workers with invocation counts. OVH: instances and active services with renewal dates and monthly cost. Not implemented for AWS.
get_recommendations
The cloud provider's own optimisation suggestions. GCP: the Recommender API across every zone and region — idle VMs, machine type rightsizing, idle disks and addresses, idle and oversized Cloud SQL. Not implemented for the others; AWS Compute Optimizer is read as part of get_waste instead.
get_waste
What is wasted, with the monthly cost of each finding and the utilisation evidence behind it. AWS: idle and oversized EC2 and RDS measured from CloudWatch CPU series, stopped instances, orphaned volumes and snapshots, unused AMIs and Elastic IPs, idle load balancers and NAT gateways, DynamoDB and ElastiCache, and log groups with no retention. GCP: idle and oversized instances, orphaned disks, unattached addresses, snapshots over 90 days, idle Cloud SQL, GKE clusters with no nodes, Cloud Functions and Cloud Run with no invocations, buckets with no lifecycle rule. Not implemented for Cloudflare or OVH.
Cloudflare MCP Pro Tools (69)
verify_token
Validate the configured Cloudflare API token and show its status/permissions.
list_accounts
List Cloudflare accounts accessible by the token.
list_zones
List zones (domains), optionally filtered by name or status.
get_zone
Get details of a single zone by ID.
create_zone
Add a new domain (zone) to an account. Requires confirm:true (human-approval gate); without it returns a preview only.
delete_zone
Delete a zone by ID. Requires confirm:true (human-approval gate); without it returns a preview only.
purge_cache
Purge a zone's cache — everything, or by files/tags/hosts/prefixes. Requires confirm:true (human-approval gate); without it returns a preview only.
get_zone_analytics
Get HTTP traffic analytics for a zone over a time range (via GraphQL).
get_zone_setting
Get a single zone setting (e.g. ssl, always_use_https, min_tls_version).
update_zone_setting
Update a single zone setting (e.g. set ssl=full, always_use_https=on). Requires confirm:true (human-approval gate); without it returns a preview only.
list_dns_records
List DNS records of a zone, optionally filtered by type/name.
create_dns_record
Create a DNS record (A, AAAA, CNAME, TXT, MX, etc). Requires confirm:true (human-approval gate); without it returns a preview only.