Cloudflare
for LuumenAI

Read zones, DNS, and WAF lists; change records as an approved step.

Connect Cloudflare and the agent can read your zones, DNS records, firewall rules, WAF lists, load balancer pools, and tunnels while you work. Ask what a record points at today, or which rules cover a zone, and get an answer straight away. Changes like creating a DNS record are previewed first and go out for approval before they touch the live zone.

The Cloudflare toolbox

20 tools: 10 read, 10 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadGet Bot Management SettingsRetrieve a zone's Bot Management configuration (Bot Fight Mode / Super Bot Fight Mode / Enterprise Bot Management).
  • ReadList WAF ListsFetch all WAF lists (no items) for an account.
  • ReadList Account MembersLists all members of a Cloudflare account with their roles, permissions, and status.
  • ReadList AccountsList all Cloudflare accounts you have ownership or verified access to.
  • ReadList DNS recordsList and search DNS records in a Cloudflare zone.
  • ReadList Firewall RulesList firewall rules for a specific DNS zone.
  • ReadList MonitorsList all load-balancer monitors in a Cloudflare account.
  • ReadList PoolsList all load balancer pools in a Cloudflare account.
  • ReadList TunnelsList Cloudflare Tunnel (cloudflared) tunnels in an account to discover tunnel IDs, names, and statuses.
  • ReadList ZonesLists, searches, sorts, and filters zones in the authenticated account.
  • WriteCreate DNS recordCreate a new DNS record within a specific zone. Approval by default
  • WriteCreate WAF ListCreate a new empty custom list for use in WAF rules and filters. Approval by default
  • WriteCreate ZoneCreates a new DNS zone (domain) in Cloudflare. Approval by default
  • WriteDelete DNS RecordDelete a DNS record within a specific zone. Approval by default
  • WriteDelete WAF ListDelete a WAF list. Approval by default
  • WriteDelete ZoneDelete a zone. Approval by default
  • WriteUpdate DNS recordUpdate an existing DNS record within a specific zone. Approval by default
  • WriteUpdate WAF ListUpdate the description of a WAF list (cannot update items). Approval by default
  • WriteUpdate Tunnel ConfigurationUpdate a remotely-managed Cloudflare Tunnel's configuration (ingress rules and routing). Approval by default
  • WriteUpdate ZoneUpdate properties of an existing zone; changes apply immediately to the live zone. Approval by default

One prompt, start to finish

What a governed Cloudflare run looks like inside Luumen.

Questions

How does LuumenAI connect to Cloudflare?

Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Cloudflare on its own?

Read actions answer immediately. Anything that writes — create dns record, create waf list, create zone, delete dns record, and more — is shown as a plan and requires approval by default, including the 3 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to Cloudflare — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Cloudflare to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.