Direct answer: Finta's Aurora catalog includes Cloudflare's API MCP server at https://mcp.cloudflare.com/mcp. Cloudflare documents search and execute tools that can discover and call typed Cloudflare API operations across the resources allowed by the connected OAuth identity.
This guide is for teams using Finta as relationship intelligence around a capital, investor, customer, or company-building workflow. Cloudflare remains the source system for its records. Aurora can use only the context and actions exposed to the connected account.
How the Cloudflare connection works
| Connection detail | Current Finta guidance |
|---|---|
| Classification | Catalog MCP |
| Configured endpoint | https://mcp.cloudflare.com/mcp |
| Authentication and transport | Provider OAuth through Aurora; Streamable HTTP |
| Source of truth | Cloudflare remains authoritative for provider records, permissions, and action results. |
| Human control | Review external communication, record changes, financial actions, publishing, deletion, and other consequential work before execution. |
What you can use it for
- Search Cloudflare's typed API surface for the operation relevant to a specific account task.
- Inspect authorized zones, DNS, Workers, storage, Zero Trust, and related account resources.
- Prepare a configuration change and its exact API operation for review.
- Execute only an approved operation within the granted account and resource permissions.
These uses summarize the current provider documentation and Finta catalog purpose. The exact tool inventory varies by provider version, plan, workspace, user permissions, region, and authorization scopes.
Relationship intelligence workflows for Cloudflare
Check a fundraising campaign domain before launch
Outcome: Apply a change only after the domain owner approves the exact operation.
- Identify the exact zone and hostname used for the campaign.
- Inspect relevant DNS, certificate, redirect, and security configuration.
- Prepare a source-linked launch checklist with unknowns.
- Apply a change only after the domain owner approves the exact operation.
Human decision: Do not change DNS, redirects, security controls, or production traffic based on a general natural-language instruction.
Review an investor-facing Worker deployment
Outcome: Execute any deployment or setting change only after explicit approval.
- Locate the authorized Worker, route, and relevant observability context.
- Inspect the current configuration and recent evidence.
- Prepare a risk and rollback note for the owner.
- Execute any deployment or setting change only after explicit approval.
Human decision: A configuration read does not prove the end-to-end page, authentication, database, or download flow works.
How to connect Cloudflare to Aurora
- In Aurora, open Apps and select Cloudflare.
- Authorize https://mcp.cloudflare.com/mcp with the intended Cloudflare account identity.
- Review the requested account, zone, and resource permissions and narrow them where possible.
- Confirm that Aurora discovers Cloudflare's search and execute tools.
- Run a read-only search and account-resource lookup before any execute operation that can mutate state.
Open the official Finta apps directory to confirm the catalog entry before authorizing a provider account.
Permissions and approval boundary
Cloudflare's execute tool can reach a broad account surface. Keep OAuth permissions narrow, verify the target account and zone, and require explicit approval for DNS, Worker, storage, security, access, billing, or traffic changes. Preserve a rollback path for every production mutation.
Limitations to understand
- Cloudflare exposes a broad and evolving API surface through search and execute rather than a fixed narrow tool list.
- Available operations depend on OAuth grants, account entitlements, API coverage, and resource policies.
- A generated API operation can still be destructive or mis-targeted and needs review.
- The catalog listing does not prove each Cloudflare product operation works through Aurora.
Verification checklist
- Confirm the endpoint, OAuth identity, account, zones, and effective permissions.
- Capture the discovered search and execute tools and one read-only API discovery receipt.
- Run a safe resource lookup against a controlled zone and retain the receipt.
- Test one reversible non-production change only after explicit approval and verify the result.
- Record API coverage, unavailable resources, rollback procedure, and verification date.
Verification status: On 2026-08-22, Finta confirmed that this connector appears in the enabled production Aurora catalog and reviewed the configured endpoint, authentication type, and first-party sources listed below. This is not a claim that every provider tool or an authenticated end-to-end action has been tested for every account.
