MoltenRock Connect · Cloudflare

Your agent reads Cloudflare today. Changes are next.

MoltenRock Connect already gives your AI agent over eighty kinds of Cloudflare reads (your sites, DNS records, analytics and more) from your Mac, with the API token kept out of its reach. Next: the Human Queue for Cloudflare, where your agent proposes a change and nothing is applied until you approve it.

Free download · works with Claude Code, Claude Desktop, Cursor, Codex and OpenClaw

Activity · Cloudflarelocal only
  • Claude Codesites · 4 zonesread
  • Claude CodeDNS records · example.comread
  • Cursoranalytics · last 7 daysread
  • Codexproposes: add a DNS recordcoming soon

Illustration, example data. Reads are live today; proposals arrive with the Human Queue for Cloudflare.

Available today

Read access, without handing over the token.

  • Over eighty reads
    Sites, DNS records, analytics and more, through one local connection your agent already knows.
  • The token stays put
    In your Mac’s Keychain or MoltenRock’s Secure-Enclave vault. Your agent never receives it.
  • Every request logged
    One line per call in Connect’s audit log, on your Mac. A kill switch refuses everything at once.
  • Your agent, your choice
    Claude Code, Claude Desktop and Cursor over MCP; Codex, OpenClaw and others over a local socket.

Coming soon · the Human Queue for Cloudflare

Your agent proposes the change. You approve it.

Every change on its own card, showing what the setting is now and what it will be, read fresh from Cloudflare. Approve with Touch ID and Connect applies it; if something changed since the card was read, nothing is sent. What we’re building for:

  • Security & site settings
    SSL and HTTPS settings, HSTS, bot protection, security headers, DNSSEC, cache purges.
  • DNS
    Add, change or remove DNS records.
  • Firewall & rules
    IP rules, firewall and rate-limit rules, redirects, header and cache rules.
  • Email Routing
    Forwarding addresses and routes, and what happens to everything else.
  • Pages sites
    Create a site from a GitHub repository, set its build, variables and domains, deploy, roll back.
  • Workers
    Versions, routes, domains, secrets and schedules.
  • Storage
    Workers KV, R2 buckets and D1 databases.
  • Access
    Put a login in front of a staging or admin address.
  • And more
    Turnstile bot checks, notifications, Web Analytics, Tunnel routes.

Planned; the details may change before release. The Human Queue is live for Stripe today. See how it works →

Be first

Hear the day it lands.

One email when the Human Queue for Cloudflare is ready, and the odd note as it adds platforms.

Human Queue news only, when it adds a platform. Unsubscribe anytime. Privacy

Questions

Cloudflare and your agent

Can my agent change anything in Cloudflare today?

No. Today MoltenRock Connect gives your agent Cloudflare reads only. Changes arrive with the Human Queue for Cloudflare: your agent will propose, and nothing will be applied until you approve it with Touch ID.

When is the Human Queue for Cloudflare coming?

Soon. We don’t give dates; leave your email on this page and we’ll tell you the day it lands. It is already live for Stripe.

Which Cloudflare token should I use?

For reads, a read-only API token. The Cloudflare card in Connect says which permissions it expects and where to create the token. The token stays in your Mac’s Keychain or MoltenRock’s vault and is never shown to your agent.

Does anything go through a MoltenRock server?

No. Connect calls Cloudflare’s API directly from your Mac, and your agent talks to Connect on your Mac. Every request is logged locally.

What does it cost?

MoltenRock Connect is free to download and covers a couple of platforms for free; Cloudflare can be one of them. MoltenRock Connect’s one-time unlock or MoltenRock Pro opens every platform, and approving Human Queue proposals needs MoltenRock Pro.

Start with reads today. Approvals are next.

Free to download. Keep your Cloudflare token out of your agent’s config.