Docs / Guides

Cloudflare

Broker Cloudflare DNS operations for AI agents, with optional per-call tokens scoped to one zone and one action.

Agents can read and change DNS records without a Cloudflare token in their reach. Optionally, the broker mints a fresh Cloudflare token for every operation, scoped to one zone and one action.

Actions

ActionParameters
DNS_READoptional name, type filters
DNS_CREATEtype, name, content, optional ttl, proxied
DNS_UPDATErecord_id or name+type, then the new values
DNS_DELETErecord_id or name+type

The resource is the zone name, such as example.com.

Credential

Seal a Cloudflare API token (never the Global API Key) with Zone Read and DNS Edit for the zones you use, and store it as the cloudflare credential.

Per-call scoped tokens (optional)

With a root token that can create API tokens, the broker mints a short-lived child token for each operation, limited to the zone and to DNS read or edit. Set on the broker:

CLOUDFLARE_TOKEN_MINT=1
CLOUDFLARE_ACCOUNT_ID=<account id>        # account-owned root tokens
CLOUDFLARE_PG_DNS_READ=<permission group id>
CLOUDFLARE_PG_DNS_EDIT=<permission group id>
CLOUDFLARE_PG_ZONE_READ=<permission group id>
CLOUDFLARE_MINT_TTL=15m                    # default lifetime
CLOUDFLARE_MINT_CLIENT_IP=203.0.113.4/32   # optional: lock tokens to the broker's IP

Permission group IDs come from GET /accounts/{id}/tokens/permission_groups. A token that can create tokens is powerful, so use a dedicated one and restrict it to the broker's IP.