In short
Use AI agents with Cloudflare in two stages. First, read-only: let the agent answer questions about traffic, DNS, settings and deployments with a read-only token, and apply its recommended changes yourself. Then, with an approval queue, let it propose changes that you review and approve before they’re applied. Never hand an agent an edit token directly, keep every change reversible where you can, and log what changed and why.
Know the blast radius
- DNS records: a wrong target or a deleted record can take a site or email offline.
- SSL and HSTS: the wrong SSL mode breaks a site; a long HSTS max-age makes browsers insist on HTTPS for that whole period.
- Firewall and rate limits: too broad, and real customers are blocked.
- Cache purges: harmless but disruptive at peak times.
- Pages deploys and rollbacks: fast to apply, but a bad build ships to everyone.
Read-only gets you most of the value
Most Cloudflare questions are answered by reading: which site had errors this week, what the SSL mode is, which DNS records are missing, why the last deploy failed. A read-only token can’t break anything, so start there. Ask the agent for a recommended change with its reasons, and make the change yourself until you have an approval step.
A change routine that works
- Propose: the agent writes the exact change, before and after, and why.
- Review: a person checks it against what the agent read.
- Approve: a deliberate action, not a reply in chat.
- Verify: the agent reads the result back and confirms the site still answers.
- Log: keep the proposal, the decision and the result.
Tokens: scoped and out of the agent’s reach
Give agents read-only tokens. If changes are made by software, keep the edit token in a broker on your machine that only acts on approved proposals, never in the agent’s configuration or prompt.
Checklist
Cloudflare and AI agents
- Agents use a read-only token.
- No edit token sits in an agent’s config, environment or chat.
- Every change is proposed, reviewed and approved before it’s applied.
- You check the site after DNS, SSL and firewall changes.
- Changes are logged with the reason.
Where MoltenRock Connect is today
MoltenRock Connect gives agents Cloudflare reads today, with the token kept on your Mac. The Human Queue for Cloudflare, where agents propose changes you approve with Touch ID, is coming soon; we don’t give dates.
Questions
Is it safe to give Claude a Cloudflare edit token?
We advise against it. An edit token in an agent’s reach can change any record or setting it covers. Use a read-only token and an approval step instead.
What’s risky about HSTS?
With a long max-age, browsers that saw it will only use HTTPS for that period, so a broken certificate setup can’t be worked around by switching back to HTTP.
How do we undo a bad change?
Keep the previous value in the change log. DNS and most settings can be set back; deploys can be rolled back to a previous deployment.
When will approvals for Cloudflare arrive in MoltenRock?
Soon. There’s no date; moltenrock.com’s Cloudflare pages have a form for one email the day it lands.
More guides
- Private, safe AI for companies: a practical guide
- A simple shadow-AI policy for small businesses
- AI and client confidentiality: a practical guide for law and accounting firms
- Human in the loop, explained: when an AI agent should ask first
- AI agents and money: a refunds and disputes playbook
- Secrets hygiene for AI agents: OpenClaw, Hermes and your API keys
- AI email triage without send access
- Solutions →