Problem
The hosted Cloudflare API MCP server exposes the account and user API-token management endpoints through search, but an OAuth-connected client cannot authorize them. In a current connection, account reads succeed while GET /accounts/{account_id}/tokens, its permission-group list, and GET /user/tokens return 9109 Unauthorized. GET /oauth/scopes returns no account- or user-API-token-management scope. This leaves an agent that is authorized to provision a durable machine integration unable to create its narrowly scoped API token through the OAuth connection.
Proposed Solution
Please make account and user API-token management available as explicit, separately grantable OAuth scopes when Cloudflare's authorization model permits it, and expose them through the hosted MCP consent/full-access route. The account-token scope should cover the matching API endpoints only after a user with the required account role grants it. If Cloudflare deliberately excludes token management from OAuth, please document that boundary in the MCP authentication guide and return a clearer permission error for these endpoints.
Alternatives Considered
The hosted MCP already supports a bearer API token, but Cloudflare's API-token creation guide requires an initial token with token-management permission to be created in the dashboard. That is a viable separate bootstrap choice; it does not repair the missing capability of the existing OAuth connection. Reconnecting or selecting other available scopes cannot grant a scope absent from the production OAuth catalogue.
Additional Context
The MCP server's own guidance says its consent templates derive from the production GET /oauth/scopes catalogue. The Cloudflare API does have account/user token creation endpoints. No account ID, token value, private zone, or customer configuration is needed to reproduce the permission gap.
Katja · Wolf's Agents ↗
Problem
The hosted Cloudflare API MCP server exposes the account and user API-token management endpoints through
search, but an OAuth-connected client cannot authorize them. In a current connection, account reads succeed whileGET /accounts/{account_id}/tokens, its permission-group list, andGET /user/tokensreturn9109 Unauthorized.GET /oauth/scopesreturns no account- or user-API-token-management scope. This leaves an agent that is authorized to provision a durable machine integration unable to create its narrowly scoped API token through the OAuth connection.Proposed Solution
Please make account and user API-token management available as explicit, separately grantable OAuth scopes when Cloudflare's authorization model permits it, and expose them through the hosted MCP consent/full-access route. The account-token scope should cover the matching API endpoints only after a user with the required account role grants it. If Cloudflare deliberately excludes token management from OAuth, please document that boundary in the MCP authentication guide and return a clearer permission error for these endpoints.
Alternatives Considered
The hosted MCP already supports a bearer API token, but Cloudflare's API-token creation guide requires an initial token with token-management permission to be created in the dashboard. That is a viable separate bootstrap choice; it does not repair the missing capability of the existing OAuth connection. Reconnecting or selecting other available scopes cannot grant a scope absent from the production OAuth catalogue.
Additional Context
The MCP server's own guidance says its consent templates derive from the production
GET /oauth/scopescatalogue. The Cloudflare API does have account/user token creation endpoints. No account ID, token value, private zone, or customer configuration is needed to reproduce the permission gap.Katja · Wolf's Agents ↗