# pi Cloudflare MCP Extension

A pi package that bridges pi to the official Cloudflare remote MCP server (`https://mcp.cloudflare.com/mcp`). Provides broad API access: DNS, zones, email routing, account management, workers, and more.

It exposes a small, generic bridge instead of registering dozens of Cloudflare tools by default. This keeps pi's tool list compact while still allowing the model to discover and call any Cloudflare MCP tool.

## Installation

```bash
pi install npm:@khmuhtadin/pi-cloudflare-mcp
```

## Registered tools

- `cloudflare_mcp_list_tools` — list tools exposed by the Cloudflare MCP server.
- `cloudflare_mcp_call_tool` — call any Cloudflare MCP tool by `name` with JSON `arguments`.

## Slash commands

- `/cloudflare-mcp-auth-url` — start OAuth and print the Cloudflare authorization URL to the terminal.
- `/cloudflare-mcp-auth <full-redirect-url-or-code>` — finish OAuth with the full redirect URL or the `code` value from that URL.
- `/cloudflare-mcp-token-status` — show token status without exposing token values.
- `/cloudflare-mcp-reset` — clear stored OAuth credentials.
- `/cloudflare-mcp-register [tool1,tool2|*]` — optional: register selected MCP tools as native pi tools with a `cloudflare_` prefix.

## OAuth flow

1. Start or reload pi.
2. Run:

   ```text
   /cloudflare-mcp-auth-url
   ```

3. Open the printed Cloudflare authorization URL in your browser.
4. After approval, the browser redirects to `http://localhost:9877/callback?...`. A local server is not required; copy the full redirect URL from the address bar.
5. Run:

   ```text
   /cloudflare-mcp-auth <full-redirect-url>
   ```

   You can also paste only the `code` query parameter value, but do not include `code=`, `&state=...`, or whitespace.

6. Test by asking pi to use `cloudflare_mcp_list_tools`.

Credentials are stored at:

```text
~/.pi/agent/extensions/cloudflare-mcp/auth-store.json
```

## Configuration

Optional environment variables:

- `CLOUDFLARE_MCP_URL` — defaults to `https://mcp.cloudflare.com/mcp`.
- `CLOUDFLARE_MCP_REDIRECT_URL` — defaults to `http://localhost:9877/callback`.
- `CLOUDFLARE_MCP_STORE_PATH` — defaults to `~/.pi/agent/extensions/cloudflare-mcp/auth-store.json`.
- `CLOUDFLARE_MCP_TIMEOUT_MS` — defaults to `10000`.
- `CLOUDFLARE_MCP_SCOPE` — defaults to `read write`.

## Development

```bash
npm install
npm run typecheck
npm pack --dry-run
```

## License

MIT
