Browse docs · Guides
Get started
Concepts
Guides
Security
Reference
Docs / Guides
Cloudflare
Broker Cloudflare DNS operations for AI agents, with optional per-call tokens scoped to one zone and one action.
Agents can read and change DNS records without a Cloudflare token in their reach. Optionally, the broker mints a fresh Cloudflare token for every operation, scoped to one zone and one action.
Actions
| Action | Parameters |
|---|---|
DNS_READ | optional name, type filters |
DNS_CREATE | type, name, content, optional ttl, proxied |
DNS_UPDATE | record_id or name+type, then the new values |
DNS_DELETE | record_id or name+type |
The resource is the zone name, such as example.com.
Credential
Seal a Cloudflare API token (never the Global API Key) with Zone Read and DNS Edit for the zones you use, and store it as the cloudflare credential.
Per-call scoped tokens (optional)
With a root token that can create API tokens, the broker mints a short-lived child token for each operation, limited to the zone and to DNS read or edit. Set on the broker:
CLOUDFLARE_TOKEN_MINT=1 CLOUDFLARE_ACCOUNT_ID=<account id> # account-owned root tokens CLOUDFLARE_PG_DNS_READ=<permission group id> CLOUDFLARE_PG_DNS_EDIT=<permission group id> CLOUDFLARE_PG_ZONE_READ=<permission group id> CLOUDFLARE_MINT_TTL=15m # default lifetime CLOUDFLARE_MINT_CLIENT_IP=203.0.113.4/32 # optional: lock tokens to the broker's IP
Permission group IDs come from GET /accounts/{id}/tokens/permission_groups. A token that can create tokens is powerful, so use a dedicated one and restrict it to the broker's IP.