Skip to content
Scalekit Docs
Talk to an Engineer Dashboard

Connect AI agents to Cloudflare

Scalekit connector
Open markdown

The Cloudflare connector lets your AI agent act in each user's Cloudflare account. Each user signs in to Cloudflare once, and Scalekit stores and refreshes their tokens, so your agent never handles credentials. It comes with 31 tools.

Tools
31
What they doRead · write · destructive
17 · 11 · 317 read11 write3 destructive
Users sign in with
OAuth app
Scalekit's or your own

Setup

  1. Install the SDK

    Terminal window
    npm install @scalekit-sdk/node dotenv
  2. Set your credentials

    Add your Scalekit credentials to your .env file. Find values in app.scalekit.com > Developers > API Credentials.

    .env
    SCALEKIT_ENVIRONMENT_URL=<your-environment-url>
    SCALEKIT_CLIENT_ID=<your-client-id>
    SCALEKIT_CLIENT_SECRET=<your-client-secret>
  3. Create the Cloudflare connection

    In AgentKit > Connections, create a Cloudflare connection. The name you give it is the connection_name your code passes. See Configure connections.

    Scalekit credentials are available for Cloudflare, so you don't need to register an OAuth app. To show your own app on the consent screen, use your own credentials instead.

    Use your own OAuth app

    Register your Scalekit environment with Cloudflare so Scalekit handles the OAuth flow and token lifecycle for your users. Create a Cloudflare OAuth client, then add its Client ID and Client Secret to your Scalekit connection.

    1. Copy the redirect URI from Scalekit

      • In the Scalekit dashboard, go to AgentKit > Connections > Create Connection. Find Cloudflare and click Create.

      • Click Use your own credentials and copy the redirect URI. It looks like https://<SCALEKIT_ENVIRONMENT_URL>/sso/v1/oauth/<CONNECTION_ID>/callback.

    2. Create an OAuth client in Cloudflare

      • Sign in to the Cloudflare dashboard and go to Manage account > OAuth clients.

      • Click Create OAuth client.

      • Fill in the Configure OAuth client form:

        • Client Name — for example, Agent Auth
        • Response Type — Code, Token
        • Grant type — Authorization Code
        • Token Authentication Method — None (PKCE)
        • Redirect (Callback) URLs — paste the redirect URI you copied from Scalekit, then press Return to add it
      • Click Next to continue to Select permission scopes.

        Cloudflare Create OAuth client form showing Client Name, Response Type, Grant type, Token Authentication Method, and Redirect URLs fields

    3. Select permission scopes

      Enable at least the scopes Scalekit requires:

      ScopeRequired
      Zone Read (zone.read)Yes
      DNS Read (dns.read)Yes
      DNS Write (dns.write)Only if your agent needs to manage DNS records
      Cache Purge (cache.purge)Only if your agent needs to purge cached content

      Click Create to finish creating the OAuth client.

    4. Copy your Client ID and Client Secret

      • Cloudflare shows the Client ID and Client Secret once the client is created.
      • Copy both values — the secret is shown only once.
    5. Add credentials in Scalekit

      • Return to the connection you created in Scalekit and enter:
        • Client ID — from your Cloudflare OAuth client
        • Client Secret — from your Cloudflare OAuth client
      • Click Save.
  4. Authorize a user and make your first call

    quickstart.mts
    import { ScalekitClient } from '@scalekit-sdk/node'
    import 'dotenv/config'
    import { createInterface } from 'node:readline/promises'
    const scalekit = new ScalekitClient(
    process.env.SCALEKIT_ENVIRONMENT_URL,
    process.env.SCALEKIT_CLIENT_ID,
    process.env.SCALEKIT_CLIENT_SECRET,
    )
    const actions = scalekit.actions
    const connector = 'cloudflare'
    const identifier = 'user_123'
    // Generate an authorization link for the user
    const { link } = await actions.getAuthorizationLink({ connectionName: connector, identifier })
    console.log('Authorize Cloudflare:', link)
    const rl = createInterface({ input: process.stdin, output: process.stdout })
    await rl.question('Press Enter after authorizing...')
    rl.close()
    // Make your first call
    const result = await actions.executeTool({
    connector,
    identifier,
    toolName: 'cloudflare_account_list',
    toolInput: {},
    })
    console.log(result)
    Terminal window
    npx tsx quickstart.mts

    Each user signs in once. See Authorize a user for the full flow and statuses.

Tools

Pass the exact name to execute_tool
Try in PlaygroundRequest a tool
  • cloudflare_access_application_getRetrieve details of a single Zero Trust Access application by ID.Read-only

    Get Access Application

    Retrieve details of a single Zero Trust Access application by ID. Use List Access Applications to find an application ID.

    Inputs

    account_idstringrequired
    The ID of the Cloudflare account
    app_idstringrequired
    The ID of the Access application to retrieve
  • cloudflare_access_application_listList all Zero Trust Access applications configured in a Cloudflare account, with optional filtering by name or domain.Read-only

    List Access Applications

    List all Zero Trust Access applications configured in a Cloudflare account, with optional filtering by name or domain.

    Inputs

    account_idstringrequired
    The ID of the Cloudflare account
    domainstring
    Filter applications by domain
    namestring
    Filter applications by name
    pageinteger
    Page number of results to return
    per_pageinteger
    Number of results per page
  • cloudflare_account_listList all Cloudflare accounts the current authenticated user has access to, with optional filtering by account name.Read-only

    List Accounts

    List all Cloudflare accounts the current authenticated user has access to, with optional filtering by account name.

    Inputs

    directionstring
    Sort direction for resultsone of ascdesc
    namestring
    Filter accounts by name (partial match supported)
    pageinteger
    Page number of results to return
    per_pageinteger
    Number of results per page
  • cloudflare_dns_record_getRetrieve details of a single DNS record by ID.Read-only

    Get DNS Record

    Retrieve details of a single DNS record by ID. Use List DNS Records to find a record ID.

    Inputs

    dns_record_idstringrequired
    The unique identifier of the DNS record to retrieve
    zone_idstringrequired
    The unique identifier for the zone the record belongs to
  • cloudflare_dns_record_listList, search, sort, and filter DNS records for a Cloudflare zone.Read-only

    List DNS Records

    List, search, sort, and filter DNS records for a Cloudflare zone. Supports filtering by record type, name, and content.

    Inputs

    zone_idstringrequired
    The unique identifier for the zone to list DNS records from
    contentstring
    Filter DNS records by content/value
    directionstring
    Sort direction (asc or desc)one of ascdesc
    matchstring
    Whether to match all or any filter conditionsone of anyall
    namestring
    Filter DNS records by name
    orderstring
    Field to order results byone of typenamecontentttlproxied
    pageinteger
    Page number for pagination (default 1)
    per_pageinteger
    Number of results per page (default 20, max 100)
    typestring
    Filter DNS records by typeone of AAAAACAACERTCNAMEDNSKEYDSHTTPSLOCMXNAPTRNSPTRSMIMEASPFSRVSSHFPSVCBTLSATXTURI
  • cloudflare_firewall_rule_listList the firewall rules configured on a Cloudflare zone, including their filter expressions and actions.Read-only

    List Firewall Rules

    List the firewall rules configured on a Cloudflare zone, including their filter expressions and actions.

    Inputs

    zone_idstringrequired
    The unique identifier for the zone to list firewall rules from
    pageinteger
    Page number for pagination (default 1)
    per_pageinteger
    Number of results per page (default 20, max 100)
  • cloudflare_load_balancer_listList the Load Balancers configured on a Cloudflare zone.Read-only

    List Load Balancers

    List the Load Balancers configured on a Cloudflare zone.

    Inputs

    zone_idstringrequired
    The unique identifier for the zone to list load balancers from
  • cloudflare_page_rule_listList the page rules configured on a Cloudflare zone, including their URL targets, actions, and status.Read-only

    List Page Rules

    List the page rules configured on a Cloudflare zone, including their URL targets, actions, and status.

    Inputs

    zone_idstringrequired
    The unique identifier for the zone to list page rules from
    statusstring
    Filter page rules by statusone of activedisabled