Walrus Tusk AI Code Systems
← Back Console Unlock
Cloudflare Ops MCP · v0.4.2

Questions
answered

What the MCP does, what it refuses to do, and how the approval gate works.

01 of 10 open

Frequently
asked

One answer open at a time. Opening a question closes the last one.

No. Cloudflare Ops MCP is made by AMH - Artificial Mind Hive, operated by Service Pricer LLC. It is independent, third-party, open-source software, not affiliated with, endorsed by, sponsored by, or made by Cloudflare, Inc. "Cloudflare" and "Wrangler" are referenced only to describe compatibility with Cloudflare's platform and official developer tooling.

No. Every mutating function is dry-run by default and only writes when { apply: true } is passed; the CLI is dry-run unless you add --apply. A dry-run returns the planned change plus a before/after diff and writes nothing.

Never as a side effect. Deleting a DNS record requires an explicit deleteDnsRecord(..., { confirm: true }) call (CLI: --force). An apply never deletes anything.

The Cloudflare API token is read only from process.env.CLOUDFLARE_API_TOKEN. It is never logged, never written to the audit log, and never included in thrown error messages — any token-looking substring is redacted defensively. Use a least-privilege scoped token, not the Global API Key.

Public users authorize Cloudflare directly and receive an opaque cfops_ connector key. OAuth access and refresh tokens stay server-side in KV; the connector key is stored only as a SHA-256 hash and is bound to one OAuth grant. Either side can revoke the connection.

The deploy gate checks the public target for an explicit 2xx status, rejects redirects, and optionally requires an expected release marker before reporting success.

No. The self-catching loopback exercises the configured sending/routing path and records delivery evidence; it does not claim to prove placement in a provider's inbox tab.

Five ways: the cfops CLI with a scoped token, the zero-dependency library, the hosted OAuth MCP, a self-hosted MCP Worker deployed with Wrangler, or the private Agent Harness behind the MCP Worker's AGENT_HARNESS service binding.

Yes. Every apply appends one JSON line to an audit log (default ./cloudflare-ops-mcp-audit.log) with { ts, action, domain, record, before, after } — never the token. The harness keeps a tamper-evident chain in one Durable Object per user.

setupBimi checks the domain's DMARC policy. If p is missing or none, it refuses to write in apply mode, because BIMI is not honored below enforcement, unless you pass { force: true }. In dry-run it warns.