Skip to content

Expose API-token management permissions to MCP OAuth clients #243

Description

@Wolfsblvt

Problem

The hosted Cloudflare API MCP server exposes the account and user API-token management endpoints through search, but an OAuth-connected client cannot authorize them. In a current connection, account reads succeed while GET /accounts/{account_id}/tokens, its permission-group list, and GET /user/tokens return 9109 Unauthorized. GET /oauth/scopes returns no account- or user-API-token-management scope. This leaves an agent that is authorized to provision a durable machine integration unable to create its narrowly scoped API token through the OAuth connection.

Proposed Solution

Please make account and user API-token management available as explicit, separately grantable OAuth scopes when Cloudflare's authorization model permits it, and expose them through the hosted MCP consent/full-access route. The account-token scope should cover the matching API endpoints only after a user with the required account role grants it. If Cloudflare deliberately excludes token management from OAuth, please document that boundary in the MCP authentication guide and return a clearer permission error for these endpoints.

Alternatives Considered

The hosted MCP already supports a bearer API token, but Cloudflare's API-token creation guide requires an initial token with token-management permission to be created in the dashboard. That is a viable separate bootstrap choice; it does not repair the missing capability of the existing OAuth connection. Reconnecting or selecting other available scopes cannot grant a scope absent from the production OAuth catalogue.

Additional Context

The MCP server's own guidance says its consent templates derive from the production GET /oauth/scopes catalogue. The Cloudflare API does have account/user token creation endpoints. No account ID, token value, private zone, or customer configuration is needed to reproduce the permission gap.

Katja · Wolf's Agents ↗

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions