published on Tuesday, Aug 25, 2026 by Pulumi
published on Tuesday, Aug 25, 2026 by Pulumi
Accepted Permissions
MCP Portals ReadMCP Portals Write
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as cloudflare from "@pulumi/cloudflare";
const exampleZeroTrustAccessAiControlsMcpServer = new cloudflare.ZeroTrustAccessAiControlsMcpServer("example_zero_trust_access_ai_controls_mcp_server", {
accountId: "a86a8f5c339544d7bdc89926de14fb8c",
zeroTrustAccessAiControlsMcpServerId: "my-mcp-server",
authType: "unauthenticated",
hostname: "https://example.com/mcp",
name: "My MCP Server",
authCredentials: "sk-my-bearer-token",
clientSecret: "client_secret",
description: "This is one remote MCP server",
isSharedOauthCallbackEnabled: true,
secureWebGateway: false,
updatedPrompts: [{
name: "name",
alias: "my-custom-alias",
description: "description",
enabled: true,
}],
updatedTools: [{
name: "name",
alias: "my-custom-alias",
description: "description",
enabled: true,
}],
});
import pulumi
import pulumi_cloudflare as cloudflare
example_zero_trust_access_ai_controls_mcp_server = cloudflare.ZeroTrustAccessAiControlsMcpServer("example_zero_trust_access_ai_controls_mcp_server",
account_id="a86a8f5c339544d7bdc89926de14fb8c",
zero_trust_access_ai_controls_mcp_server_id="my-mcp-server",
auth_type="unauthenticated",
hostname="https://example.com/mcp",
name="My MCP Server",
auth_credentials="sk-my-bearer-token",
client_secret="client_secret",
description="This is one remote MCP server",
is_shared_oauth_callback_enabled=True,
secure_web_gateway=False,
updated_prompts=[{
"name": "name",
"alias": "my-custom-alias",
"description": "description",
"enabled": True,
}],
updated_tools=[{
"name": "name",
"alias": "my-custom-alias",
"description": "description",
"enabled": True,
}])
package main
import (
"github.com/pulumi/pulumi-cloudflare/sdk/v6/go/cloudflare"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
_, err := cloudflare.NewZeroTrustAccessAiControlsMcpServer(ctx, "example_zero_trust_access_ai_controls_mcp_server", &cloudflare.ZeroTrustAccessAiControlsMcpServerArgs{
AccountId: pulumi.String("a86a8f5c339544d7bdc89926de14fb8c"),
ZeroTrustAccessAiControlsMcpServerId: pulumi.String("my-mcp-server"),
AuthType: pulumi.String("unauthenticated"),
Hostname: pulumi.String("https://example.com/mcp"),
Name: pulumi.String("My MCP Server"),
AuthCredentials: pulumi.String("sk-my-bearer-token"),
ClientSecret: pulumi.String("client_secret"),
Description: pulumi.String("This is one remote MCP server"),
IsSharedOauthCallbackEnabled: pulumi.Bool(true),
SecureWebGateway: pulumi.Bool(false),
UpdatedPrompts: cloudflare.ZeroTrustAccessAiControlsMcpServerUpdatedPromptArray{
&cloudflare.ZeroTrustAccessAiControlsMcpServerUpdatedPromptArgs{
Name: pulumi.String("name"),
Alias: pulumi.String("my-custom-alias"),
Description: pulumi.String("description"),
Enabled: pulumi.Bool(true),
},
},
UpdatedTools: cloudflare.ZeroTrustAccessAiControlsMcpServerUpdatedToolArray{
&cloudflare.ZeroTrustAccessAiControlsMcpServerUpdatedToolArgs{
Name: pulumi.String("name"),
Alias: pulumi.String("my-custom-alias"),
Description: pulumi.String("description"),
Enabled: pulumi.Bool(true),
},
},
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Cloudflare = Pulumi.Cloudflare;
return await Deployment.RunAsync(() =>
{
var exampleZeroTrustAccessAiControlsMcpServer = new Cloudflare.ZeroTrustAccessAiControlsMcpServer("example_zero_trust_access_ai_controls_mcp_server", new()
{
AccountId = "a86a8f5c339544d7bdc89926de14fb8c",
ZeroTrustAccessAiControlsMcpServerId = "my-mcp-server",
AuthType = "unauthenticated",
Hostname = "https://example.com/mcp",
Name = "My MCP Server",
AuthCredentials = "sk-my-bearer-token",
ClientSecret = "client_secret",
Description = "This is one remote MCP server",
IsSharedOauthCallbackEnabled = true,
SecureWebGateway = false,
UpdatedPrompts = new[]
{
new Cloudflare.Inputs.ZeroTrustAccessAiControlsMcpServerUpdatedPromptArgs
{
Name = "name",
Alias = "my-custom-alias",
Description = "description",
Enabled = true,
},
},
UpdatedTools = new[]
{
new Cloudflare.Inputs.ZeroTrustAccessAiControlsMcpServerUpdatedToolArgs
{
Name = "name",
Alias = "my-custom-alias",
Description = "description",
Enabled = true,
},
},
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.cloudflare.ZeroTrustAccessAiControlsMcpServer;
import com.pulumi.cloudflare.ZeroTrustAccessAiControlsMcpServerArgs;
import com.pulumi.cloudflare.inputs.ZeroTrustAccessAiControlsMcpServerUpdatedPromptArgs;
import com.pulumi.cloudflare.inputs.ZeroTrustAccessAiControlsMcpServerUpdatedToolArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var exampleZeroTrustAccessAiControlsMcpServer = new ZeroTrustAccessAiControlsMcpServer("exampleZeroTrustAccessAiControlsMcpServer", ZeroTrustAccessAiControlsMcpServerArgs.builder()
.accountId("a86a8f5c339544d7bdc89926de14fb8c")
.zeroTrustAccessAiControlsMcpServerId("my-mcp-server")
.authType("unauthenticated")
.hostname("https://example.com/mcp")
.name("My MCP Server")
.authCredentials("sk-my-bearer-token")
.clientSecret("client_secret")
.description("This is one remote MCP server")
.isSharedOauthCallbackEnabled(true)
.secureWebGateway(false)
.updatedPrompts(ZeroTrustAccessAiControlsMcpServerUpdatedPromptArgs.builder()
.name("name")
.alias("my-custom-alias")
.description("description")
.enabled(true)
.build())
.updatedTools(ZeroTrustAccessAiControlsMcpServerUpdatedToolArgs.builder()
.name("name")
.alias("my-custom-alias")
.description("description")
.enabled(true)
.build())
.build());
}
}
resources:
exampleZeroTrustAccessAiControlsMcpServer:
type: cloudflare:ZeroTrustAccessAiControlsMcpServer
name: example_zero_trust_access_ai_controls_mcp_server
properties:
accountId: a86a8f5c339544d7bdc89926de14fb8c
zeroTrustAccessAiControlsMcpServerId: my-mcp-server
authType: unauthenticated
hostname: https://example.com/mcp
name: My MCP Server
authCredentials: sk-my-bearer-token
clientSecret: client_secret
description: This is one remote MCP server
isSharedOauthCallbackEnabled: true
secureWebGateway: false
updatedPrompts:
- name: name
alias: my-custom-alias
description: description
enabled: true
updatedTools:
- name: name
alias: my-custom-alias
description: description
enabled: true
pulumi {
required_providers {
cloudflare = {
source = "pulumi/cloudflare"
}
}
}
resource "cloudflare_zerotrustaccessaicontrolsmcpserver" "example_zero_trust_access_ai_controls_mcp_server" {
account_id = "a86a8f5c339544d7bdc89926de14fb8c"
zero_trust_access_ai_controls_mcp_server_id = "my-mcp-server"
auth_type = "unauthenticated"
hostname = "https://example.com/mcp"
name = "My MCP Server"
auth_credentials = "sk-my-bearer-token"
client_secret = "client_secret"
description = "This is one remote MCP server"
is_shared_oauth_callback_enabled = true
secure_web_gateway = false
updated_prompts {
name = "name"
alias = "my-custom-alias"
description = "description"
enabled = true
}
updated_tools {
name = "name"
alias = "my-custom-alias"
description = "description"
enabled = true
}
}
Create ZeroTrustAccessAiControlsMcpServer Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new ZeroTrustAccessAiControlsMcpServer(name: string, args: ZeroTrustAccessAiControlsMcpServerArgs, opts?: CustomResourceOptions);@overload
def ZeroTrustAccessAiControlsMcpServer(resource_name: str,
args: ZeroTrustAccessAiControlsMcpServerArgs,
opts: Optional[ResourceOptions] = None)
@overload
def ZeroTrustAccessAiControlsMcpServer(resource_name: str,
opts: Optional[ResourceOptions] = None,
account_id: Optional[str] = None,
auth_type: Optional[str] = None,
hostname: Optional[str] = None,
name: Optional[str] = None,
zero_trust_access_ai_controls_mcp_server_id: Optional[str] = None,
auth_credentials: Optional[str] = None,
client_secret: Optional[str] = None,
description: Optional[str] = None,
is_shared_oauth_callback_enabled: Optional[bool] = None,
secure_web_gateway: Optional[bool] = None,
updated_prompts: Optional[Sequence[ZeroTrustAccessAiControlsMcpServerUpdatedPromptArgs]] = None,
updated_tools: Optional[Sequence[ZeroTrustAccessAiControlsMcpServerUpdatedToolArgs]] = None)func NewZeroTrustAccessAiControlsMcpServer(ctx *Context, name string, args ZeroTrustAccessAiControlsMcpServerArgs, opts ...ResourceOption) (*ZeroTrustAccessAiControlsMcpServer, error)public ZeroTrustAccessAiControlsMcpServer(string name, ZeroTrustAccessAiControlsMcpServerArgs args, CustomResourceOptions? opts = null)
public ZeroTrustAccessAiControlsMcpServer(String name, ZeroTrustAccessAiControlsMcpServerArgs args)
public ZeroTrustAccessAiControlsMcpServer(String name, ZeroTrustAccessAiControlsMcpServerArgs args, CustomResourceOptions options)
type: cloudflare:ZeroTrustAccessAiControlsMcpServer
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "cloudflare_zero_trust_access_ai_controls_mcp_server" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args ZeroTrustAccessAiControlsMcpServerArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args ZeroTrustAccessAiControlsMcpServerArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args ZeroTrustAccessAiControlsMcpServerArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args ZeroTrustAccessAiControlsMcpServerArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args ZeroTrustAccessAiControlsMcpServerArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var zeroTrustAccessAiControlsMcpServerResource = new Cloudflare.ZeroTrustAccessAiControlsMcpServer("zeroTrustAccessAiControlsMcpServerResource", new()
{
AccountId = "string",
AuthType = "string",
Hostname = "string",
Name = "string",
ZeroTrustAccessAiControlsMcpServerId = "string",
AuthCredentials = "string",
ClientSecret = "string",
Description = "string",
IsSharedOauthCallbackEnabled = false,
SecureWebGateway = false,
UpdatedPrompts = new[]
{
new Cloudflare.Inputs.ZeroTrustAccessAiControlsMcpServerUpdatedPromptArgs
{
Name = "string",
Alias = "string",
Description = "string",
Enabled = false,
},
},
UpdatedTools = new[]
{
new Cloudflare.Inputs.ZeroTrustAccessAiControlsMcpServerUpdatedToolArgs
{
Name = "string",
Alias = "string",
Description = "string",
Enabled = false,
},
},
});
example, err := cloudflare.NewZeroTrustAccessAiControlsMcpServer(ctx, "zeroTrustAccessAiControlsMcpServerResource", &cloudflare.ZeroTrustAccessAiControlsMcpServerArgs{
AccountId: pulumi.String("string"),
AuthType: pulumi.String("string"),
Hostname: pulumi.String("string"),
Name: pulumi.String("string"),
ZeroTrustAccessAiControlsMcpServerId: pulumi.String("string"),
AuthCredentials: pulumi.String("string"),
ClientSecret: pulumi.String("string"),
Description: pulumi.String("string"),
IsSharedOauthCallbackEnabled: pulumi.Bool(false),
SecureWebGateway: pulumi.Bool(false),
UpdatedPrompts: cloudflare.ZeroTrustAccessAiControlsMcpServerUpdatedPromptArray{
&cloudflare.ZeroTrustAccessAiControlsMcpServerUpdatedPromptArgs{
Name: pulumi.String("string"),
Alias: pulumi.String("string"),
Description: pulumi.String("string"),
Enabled: pulumi.Bool(false),
},
},
UpdatedTools: cloudflare.ZeroTrustAccessAiControlsMcpServerUpdatedToolArray{
&cloudflare.ZeroTrustAccessAiControlsMcpServerUpdatedToolArgs{
Name: pulumi.String("string"),
Alias: pulumi.String("string"),
Description: pulumi.String("string"),
Enabled: pulumi.Bool(false),
},
},
})
resource "cloudflare_zero_trust_access_ai_controls_mcp_server" "zeroTrustAccessAiControlsMcpServerResource" {
lifecycle {
create_before_destroy = true
}
account_id = "string"
auth_type = "string"
hostname = "string"
name = "string"
zero_trust_access_ai_controls_mcp_server_id = "string"
auth_credentials = "string"
client_secret = "string"
description = "string"
is_shared_oauth_callback_enabled = false
secure_web_gateway = false
updated_prompts {
name = "string"
alias = "string"
description = "string"
enabled = false
}
updated_tools {
name = "string"
alias = "string"
description = "string"
enabled = false
}
}
var zeroTrustAccessAiControlsMcpServerResource = new ZeroTrustAccessAiControlsMcpServer("zeroTrustAccessAiControlsMcpServerResource", ZeroTrustAccessAiControlsMcpServerArgs.builder()
.accountId("string")
.authType("string")
.hostname("string")
.name("string")
.zeroTrustAccessAiControlsMcpServerId("string")
.authCredentials("string")
.clientSecret("string")
.description("string")
.isSharedOauthCallbackEnabled(false)
.secureWebGateway(false)
.updatedPrompts(ZeroTrustAccessAiControlsMcpServerUpdatedPromptArgs.builder()
.name("string")
.alias("string")
.description("string")
.enabled(false)
.build())
.updatedTools(ZeroTrustAccessAiControlsMcpServerUpdatedToolArgs.builder()
.name("string")
.alias("string")
.description("string")
.enabled(false)
.build())
.build());
zero_trust_access_ai_controls_mcp_server_resource = cloudflare.ZeroTrustAccessAiControlsMcpServer("zeroTrustAccessAiControlsMcpServerResource",
account_id="string",
auth_type="string",
hostname="string",
name="string",
zero_trust_access_ai_controls_mcp_server_id="string",
auth_credentials="string",
client_secret="string",
description="string",
is_shared_oauth_callback_enabled=False,
secure_web_gateway=False,
updated_prompts=[{
"name": "string",
"alias": "string",
"description": "string",
"enabled": False,
}],
updated_tools=[{
"name": "string",
"alias": "string",
"description": "string",
"enabled": False,
}])
const zeroTrustAccessAiControlsMcpServerResource = new cloudflare.ZeroTrustAccessAiControlsMcpServer("zeroTrustAccessAiControlsMcpServerResource", {
accountId: "string",
authType: "string",
hostname: "string",
name: "string",
zeroTrustAccessAiControlsMcpServerId: "string",
authCredentials: "string",
clientSecret: "string",
description: "string",
isSharedOauthCallbackEnabled: false,
secureWebGateway: false,
updatedPrompts: [{
name: "string",
alias: "string",
description: "string",
enabled: false,
}],
updatedTools: [{
name: "string",
alias: "string",
description: "string",
enabled: false,
}],
});
type: cloudflare:ZeroTrustAccessAiControlsMcpServer
properties:
accountId: string
authCredentials: string
authType: string
clientSecret: string
description: string
hostname: string
isSharedOauthCallbackEnabled: false
name: string
secureWebGateway: false
updatedPrompts:
- alias: string
description: string
enabled: false
name: string
updatedTools:
- alias: string
description: string
enabled: false
name: string
zeroTrustAccessAiControlsMcpServerId: string
ZeroTrustAccessAiControlsMcpServer Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The ZeroTrustAccessAiControlsMcpServer resource accepts the following input properties:
- Account
Id string - Auth
Type string - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- Hostname string
- URL of the upstream MCP endpoint.
- Name string
- Display name for the MCP server.
- Zero
Trust stringAccess Ai Controls Mcp Server Id - Unique identifier for the MCP server.
- Auth
Credentials string - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - Client
Secret string - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- Description string
- Optional description of the MCP server.
- bool
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- Secure
Web boolGateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- Updated
Prompts List<ZeroTrust Access Ai Controls Mcp Server Updated Prompt> - Server-wide prompt capability overrides.
- Updated
Tools List<ZeroTrust Access Ai Controls Mcp Server Updated Tool> - Server-wide tool capability overrides.
- Account
Id string - Auth
Type string - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- Hostname string
- URL of the upstream MCP endpoint.
- Name string
- Display name for the MCP server.
- Zero
Trust stringAccess Ai Controls Mcp Server Id - Unique identifier for the MCP server.
- Auth
Credentials string - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - Client
Secret string - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- Description string
- Optional description of the MCP server.
- bool
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- Secure
Web boolGateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- Updated
Prompts []ZeroTrust Access Ai Controls Mcp Server Updated Prompt Args - Server-wide prompt capability overrides.
- Updated
Tools []ZeroTrust Access Ai Controls Mcp Server Updated Tool Args - Server-wide tool capability overrides.
- account_
id string - auth_
type string - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- hostname string
- URL of the upstream MCP endpoint.
- name string
- Display name for the MCP server.
- zero_
trust_ stringaccess_ ai_ controls_ mcp_ server_ id - Unique identifier for the MCP server.
- auth_
credentials string - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - client_
secret string - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- description string
- Optional description of the MCP server.
- bool
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- secure_
web_ boolgateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- updated_
prompts list(object) - Server-wide prompt capability overrides.
- updated_
tools list(object) - Server-wide tool capability overrides.
- account
Id String - auth
Type String - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- hostname String
- URL of the upstream MCP endpoint.
- name String
- Display name for the MCP server.
- zero
Trust StringAccess Ai Controls Mcp Server Id - Unique identifier for the MCP server.
- auth
Credentials String - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - client
Secret String - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- description String
- Optional description of the MCP server.
- Boolean
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- secure
Web BooleanGateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- updated
Prompts List<ZeroTrust Access Ai Controls Mcp Server Updated Prompt> - Server-wide prompt capability overrides.
- updated
Tools List<ZeroTrust Access Ai Controls Mcp Server Updated Tool> - Server-wide tool capability overrides.
- account
Id string - auth
Type string - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- hostname string
- URL of the upstream MCP endpoint.
- name string
- Display name for the MCP server.
- zero
Trust stringAccess Ai Controls Mcp Server Id - Unique identifier for the MCP server.
- auth
Credentials string - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - client
Secret string - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- description string
- Optional description of the MCP server.
- boolean
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- secure
Web booleanGateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- updated
Prompts ZeroTrust Access Ai Controls Mcp Server Updated Prompt[] - Server-wide prompt capability overrides.
- updated
Tools ZeroTrust Access Ai Controls Mcp Server Updated Tool[] - Server-wide tool capability overrides.
- account_
id str - auth_
type str - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- hostname str
- URL of the upstream MCP endpoint.
- name str
- Display name for the MCP server.
- zero_
trust_ straccess_ ai_ controls_ mcp_ server_ id - Unique identifier for the MCP server.
- auth_
credentials str - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - client_
secret str - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- description str
- Optional description of the MCP server.
- bool
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- secure_
web_ boolgateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- updated_
prompts Sequence[ZeroTrust Access Ai Controls Mcp Server Updated Prompt Args] - Server-wide prompt capability overrides.
- updated_
tools Sequence[ZeroTrust Access Ai Controls Mcp Server Updated Tool Args] - Server-wide tool capability overrides.
- account
Id String - auth
Type String - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- hostname String
- URL of the upstream MCP endpoint.
- name String
- Display name for the MCP server.
- zero
Trust StringAccess Ai Controls Mcp Server Id - Unique identifier for the MCP server.
- auth
Credentials String - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - client
Secret String - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- description String
- Optional description of the MCP server.
- Boolean
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- secure
Web BooleanGateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- updated
Prompts List<Property Map> - Server-wide prompt capability overrides.
- updated
Tools List<Property Map> - Server-wide tool capability overrides.
Outputs
All input properties are implicitly available as output properties. Additionally, the ZeroTrustAccessAiControlsMcpServer resource produces the following output properties:
- Auth
Config ZeroSummary Trust Access Ai Controls Mcp Server Auth Config Summary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- Authentication
Status string - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- Created
At string - Created
By string - Error string
- Error
Details ZeroTrust Access Ai Controls Mcp Server Error Details - Id string
- The provider-assigned unique ID for this managed resource.
- Last
Successful stringSync - Last
Synced string - Modified
At string - Modified
By string - Prompts
List<Immutable
Dictionary<string, string>> - Status string
- Tools
List<Immutable
Dictionary<string, string>>
- Auth
Config ZeroSummary Trust Access Ai Controls Mcp Server Auth Config Summary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- Authentication
Status string - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- Created
At string - Created
By string - Error string
- Error
Details ZeroTrust Access Ai Controls Mcp Server Error Details - Id string
- The provider-assigned unique ID for this managed resource.
- Last
Successful stringSync - Last
Synced string - Modified
At string - Modified
By string - Prompts []map[string]string
- Status string
- Tools []map[string]string
- auth_
config_ objectsummary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- authentication_
status string - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- created_
at string - created_
by string - error string
- error_
details object - id string
- The provider-assigned unique ID for this managed resource.
- last_
successful_ stringsync - last_
synced string - modified_
at string - modified_
by string - prompts list(map(string))
- status string
- tools list(map(string))
- auth
Config ZeroSummary Trust Access Ai Controls Mcp Server Auth Config Summary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- authentication
Status String - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- created
At String - created
By String - error String
- error
Details ZeroTrust Access Ai Controls Mcp Server Error Details - id String
- The provider-assigned unique ID for this managed resource.
- last
Successful StringSync - last
Synced String - modified
At String - modified
By String - prompts List<Map<String,String>>
- status String
- tools List<Map<String,String>>
- auth
Config ZeroSummary Trust Access Ai Controls Mcp Server Auth Config Summary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- authentication
Status string - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- created
At string - created
By string - error string
- error
Details ZeroTrust Access Ai Controls Mcp Server Error Details - id string
- The provider-assigned unique ID for this managed resource.
- last
Successful stringSync - last
Synced string - modified
At string - modified
By string - prompts {[key: string]: string}[]
- status string
- tools {[key: string]: string}[]
- auth_
config_ Zerosummary Trust Access Ai Controls Mcp Server Auth Config Summary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- authentication_
status str - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- created_
at str - created_
by str - error str
- error_
details ZeroTrust Access Ai Controls Mcp Server Error Details - id str
- The provider-assigned unique ID for this managed resource.
- last_
successful_ strsync - last_
synced str - modified_
at str - modified_
by str - prompts Sequence[Mapping[str, str]]
- status str
- tools Sequence[Mapping[str, str]]
- auth
Config Property MapSummary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- authentication
Status String - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- created
At String - created
By String - error String
- error
Details Property Map - id String
- The provider-assigned unique ID for this managed resource.
- last
Successful StringSync - last
Synced String - modified
At String - modified
By String - prompts List<Map<String>>
- status String
- tools List<Map<String>>
Look up Existing ZeroTrustAccessAiControlsMcpServer Resource
Get an existing ZeroTrustAccessAiControlsMcpServer resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: ZeroTrustAccessAiControlsMcpServerState, opts?: CustomResourceOptions): ZeroTrustAccessAiControlsMcpServer@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
account_id: Optional[str] = None,
auth_config_summary: Optional[ZeroTrustAccessAiControlsMcpServerAuthConfigSummaryArgs] = None,
auth_credentials: Optional[str] = None,
auth_type: Optional[str] = None,
authentication_status: Optional[str] = None,
client_secret: Optional[str] = None,
created_at: Optional[str] = None,
created_by: Optional[str] = None,
description: Optional[str] = None,
error: Optional[str] = None,
error_details: Optional[ZeroTrustAccessAiControlsMcpServerErrorDetailsArgs] = None,
hostname: Optional[str] = None,
is_shared_oauth_callback_enabled: Optional[bool] = None,
last_successful_sync: Optional[str] = None,
last_synced: Optional[str] = None,
modified_at: Optional[str] = None,
modified_by: Optional[str] = None,
name: Optional[str] = None,
prompts: Optional[Sequence[Mapping[str, str]]] = None,
secure_web_gateway: Optional[bool] = None,
status: Optional[str] = None,
tools: Optional[Sequence[Mapping[str, str]]] = None,
updated_prompts: Optional[Sequence[ZeroTrustAccessAiControlsMcpServerUpdatedPromptArgs]] = None,
updated_tools: Optional[Sequence[ZeroTrustAccessAiControlsMcpServerUpdatedToolArgs]] = None,
zero_trust_access_ai_controls_mcp_server_id: Optional[str] = None) -> ZeroTrustAccessAiControlsMcpServerfunc GetZeroTrustAccessAiControlsMcpServer(ctx *Context, name string, id IDInput, state *ZeroTrustAccessAiControlsMcpServerState, opts ...ResourceOption) (*ZeroTrustAccessAiControlsMcpServer, error)public static ZeroTrustAccessAiControlsMcpServer Get(string name, Input<string> id, ZeroTrustAccessAiControlsMcpServerState? state, CustomResourceOptions? opts = null)public static ZeroTrustAccessAiControlsMcpServer get(String name, Output<String> id, ZeroTrustAccessAiControlsMcpServerState state, CustomResourceOptions options)resources: _: type: cloudflare:ZeroTrustAccessAiControlsMcpServer get: id: ${id}import {
to = cloudflare_zero_trust_access_ai_controls_mcp_server.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Account
Id string - Auth
Config ZeroSummary Trust Access Ai Controls Mcp Server Auth Config Summary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- Auth
Credentials string - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - Auth
Type string - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- Authentication
Status string - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- Client
Secret string - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- Created
At string - Created
By string - Description string
- Optional description of the MCP server.
- Error string
- Error
Details ZeroTrust Access Ai Controls Mcp Server Error Details - Hostname string
- URL of the upstream MCP endpoint.
- bool
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- Last
Successful stringSync - Last
Synced string - Modified
At string - Modified
By string - Name string
- Display name for the MCP server.
- Prompts
List<Immutable
Dictionary<string, string>> - Secure
Web boolGateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- Status string
- Tools
List<Immutable
Dictionary<string, string>> - Updated
Prompts List<ZeroTrust Access Ai Controls Mcp Server Updated Prompt> - Server-wide prompt capability overrides.
- Updated
Tools List<ZeroTrust Access Ai Controls Mcp Server Updated Tool> - Server-wide tool capability overrides.
- Zero
Trust stringAccess Ai Controls Mcp Server Id - Unique identifier for the MCP server.
- Account
Id string - Auth
Config ZeroSummary Trust Access Ai Controls Mcp Server Auth Config Summary Args - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- Auth
Credentials string - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - Auth
Type string - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- Authentication
Status string - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- Client
Secret string - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- Created
At string - Created
By string - Description string
- Optional description of the MCP server.
- Error string
- Error
Details ZeroTrust Access Ai Controls Mcp Server Error Details Args - Hostname string
- URL of the upstream MCP endpoint.
- bool
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- Last
Successful stringSync - Last
Synced string - Modified
At string - Modified
By string - Name string
- Display name for the MCP server.
- Prompts []map[string]string
- Secure
Web boolGateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- Status string
- Tools []map[string]string
- Updated
Prompts []ZeroTrust Access Ai Controls Mcp Server Updated Prompt Args - Server-wide prompt capability overrides.
- Updated
Tools []ZeroTrust Access Ai Controls Mcp Server Updated Tool Args - Server-wide tool capability overrides.
- Zero
Trust stringAccess Ai Controls Mcp Server Id - Unique identifier for the MCP server.
- account_
id string - auth_
config_ objectsummary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- auth_
credentials string - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - auth_
type string - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- authentication_
status string - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- client_
secret string - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- created_
at string - created_
by string - description string
- Optional description of the MCP server.
- error string
- error_
details object - hostname string
- URL of the upstream MCP endpoint.
- bool
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- last_
successful_ stringsync - last_
synced string - modified_
at string - modified_
by string - name string
- Display name for the MCP server.
- prompts list(map(string))
- secure_
web_ boolgateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- status string
- tools list(map(string))
- updated_
prompts list(object) - Server-wide prompt capability overrides.
- updated_
tools list(object) - Server-wide tool capability overrides.
- zero_
trust_ stringaccess_ ai_ controls_ mcp_ server_ id - Unique identifier for the MCP server.
- account
Id String - auth
Config ZeroSummary Trust Access Ai Controls Mcp Server Auth Config Summary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- auth
Credentials String - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - auth
Type String - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- authentication
Status String - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- client
Secret String - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- created
At String - created
By String - description String
- Optional description of the MCP server.
- error String
- error
Details ZeroTrust Access Ai Controls Mcp Server Error Details - hostname String
- URL of the upstream MCP endpoint.
- Boolean
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- last
Successful StringSync - last
Synced String - modified
At String - modified
By String - name String
- Display name for the MCP server.
- prompts List<Map<String,String>>
- secure
Web BooleanGateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- status String
- tools List<Map<String,String>>
- updated
Prompts List<ZeroTrust Access Ai Controls Mcp Server Updated Prompt> - Server-wide prompt capability overrides.
- updated
Tools List<ZeroTrust Access Ai Controls Mcp Server Updated Tool> - Server-wide tool capability overrides.
- zero
Trust StringAccess Ai Controls Mcp Server Id - Unique identifier for the MCP server.
- account
Id string - auth
Config ZeroSummary Trust Access Ai Controls Mcp Server Auth Config Summary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- auth
Credentials string - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - auth
Type string - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- authentication
Status string - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- client
Secret string - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- created
At string - created
By string - description string
- Optional description of the MCP server.
- error string
- error
Details ZeroTrust Access Ai Controls Mcp Server Error Details - hostname string
- URL of the upstream MCP endpoint.
- boolean
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- last
Successful stringSync - last
Synced string - modified
At string - modified
By string - name string
- Display name for the MCP server.
- prompts {[key: string]: string}[]
- secure
Web booleanGateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- status string
- tools {[key: string]: string}[]
- updated
Prompts ZeroTrust Access Ai Controls Mcp Server Updated Prompt[] - Server-wide prompt capability overrides.
- updated
Tools ZeroTrust Access Ai Controls Mcp Server Updated Tool[] - Server-wide tool capability overrides.
- zero
Trust stringAccess Ai Controls Mcp Server Id - Unique identifier for the MCP server.
- account_
id str - auth_
config_ Zerosummary Trust Access Ai Controls Mcp Server Auth Config Summary Args - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- auth_
credentials str - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - auth_
type str - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- authentication_
status str - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- client_
secret str - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- created_
at str - created_
by str - description str
- Optional description of the MCP server.
- error str
- error_
details ZeroTrust Access Ai Controls Mcp Server Error Details Args - hostname str
- URL of the upstream MCP endpoint.
- bool
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- last_
successful_ strsync - last_
synced str - modified_
at str - modified_
by str - name str
- Display name for the MCP server.
- prompts Sequence[Mapping[str, str]]
- secure_
web_ boolgateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- status str
- tools Sequence[Mapping[str, str]]
- updated_
prompts Sequence[ZeroTrust Access Ai Controls Mcp Server Updated Prompt Args] - Server-wide prompt capability overrides.
- updated_
tools Sequence[ZeroTrust Access Ai Controls Mcp Server Updated Tool Args] - Server-wide tool capability overrides.
- zero_
trust_ straccess_ ai_ controls_ mcp_ server_ id - Unique identifier for the MCP server.
- account
Id String - auth
Config Property MapSummary - Safe subset of authcredentials surfaced to the dashboard. Includes authmode (dcr|manual), hasclientsecret, clientsecretversion, and the OAuth endpoints + client*id for manual servers. Never includes the secret value.
- auth
Credentials String - Static credential for the upstream MCP server. For authType "bearer", either a raw token string (e.g. "sk-abc123"), which is wrapped server-side as
Authorization: Bearer <token>, or a JSON-encoded object of the form{"headers":{"Header-Name":"value",...}}for custom or multiple static headers (e.g. Cloudflare Access service tokens:{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}). - auth
Type String - Authentication method used to connect to the upstream MCP server. Available values: "oauth", "bearer", "unauthenticated".
- authentication
Status String - Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow. Available values: "notRequired", "required", "connected", "stale", "manual".
- client
Secret String - Pre-registered OAuth clientsecret. Write-only - accepted on create/update when authcredentials.authmode is 'manual'. Stored AES-GCM-encrypted in serveroauth_secrets; never returned by read endpoints.
- created
At String - created
By String - description String
- Optional description of the MCP server.
- error String
- error
Details Property Map - hostname String
- URL of the upstream MCP endpoint.
- Boolean
- When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirectUri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.
- last
Successful StringSync - last
Synced String - modified
At String - modified
By String - name String
- Display name for the MCP server.
- prompts List<Map<String>>
- secure
Web BooleanGateway - Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.
- status String
- tools List<Map<String>>
- updated
Prompts List<Property Map> - Server-wide prompt capability overrides.
- updated
Tools List<Property Map> - Server-wide tool capability overrides.
- zero
Trust StringAccess Ai Controls Mcp Server Id - Unique identifier for the MCP server.
Supporting Types
ZeroTrustAccessAiControlsMcpServerAuthConfigSummary, ZeroTrustAccessAiControlsMcpServerAuthConfigSummaryArgs
- Auth
Mode string - Available values: "dcr", "manual".
- Client
Secret doubleVersion - Config
Zero
Trust Access Ai Controls Mcp Server Auth Config Summary Config - Has
Client boolSecret - Registration
Info ZeroTrust Access Ai Controls Mcp Server Auth Config Summary Registration Info
- Auth
Mode string - Available values: "dcr", "manual".
- Client
Secret float64Version - Config
Zero
Trust Access Ai Controls Mcp Server Auth Config Summary Config - Has
Client boolSecret - Registration
Info ZeroTrust Access Ai Controls Mcp Server Auth Config Summary Registration Info
- auth_
mode string - Available values: "dcr", "manual".
- client_
secret_ numberversion - config object
- has_
client_ boolsecret - registration_
info object
- auth
Mode String - Available values: "dcr", "manual".
- client
Secret DoubleVersion - config
Zero
Trust Access Ai Controls Mcp Server Auth Config Summary Config - has
Client BooleanSecret - registration
Info ZeroTrust Access Ai Controls Mcp Server Auth Config Summary Registration Info
- auth
Mode string - Available values: "dcr", "manual".
- client
Secret numberVersion - config
Zero
Trust Access Ai Controls Mcp Server Auth Config Summary Config - has
Client booleanSecret - registration
Info ZeroTrust Access Ai Controls Mcp Server Auth Config Summary Registration Info
- auth_
mode str - Available values: "dcr", "manual".
- client_
secret_ floatversion - config
Zero
Trust Access Ai Controls Mcp Server Auth Config Summary Config - has_
client_ boolsecret - registration_
info ZeroTrust Access Ai Controls Mcp Server Auth Config Summary Registration Info
- auth
Mode String - Available values: "dcr", "manual".
- client
Secret NumberVersion - config Property Map
- has
Client BooleanSecret - registration
Info Property Map
ZeroTrustAccessAiControlsMcpServerAuthConfigSummaryConfig, ZeroTrustAccessAiControlsMcpServerAuthConfigSummaryConfigArgs
- string
- Issuer string
- Resource string
- Revocation
Endpoint string - Token
Endpoint string
- string
- Issuer string
- Resource string
- Revocation
Endpoint string - Token
Endpoint string
- string
- issuer string
- resource string
- revocation_
endpoint string - token_
endpoint string
- String
- issuer String
- resource String
- revocation
Endpoint String - token
Endpoint String
- string
- issuer string
- resource string
- revocation
Endpoint string - token
Endpoint string
- str
- issuer str
- resource str
- revocation_
endpoint str - token_
endpoint str
- String
- issuer String
- resource String
- revocation
Endpoint String - token
Endpoint String
ZeroTrustAccessAiControlsMcpServerAuthConfigSummaryRegistrationInfo, ZeroTrustAccessAiControlsMcpServerAuthConfigSummaryRegistrationInfoArgs
- Client
Id string - Redirect
Uris List<string> - Scope string
- Token
Endpoint stringAuth Method
- Client
Id string - Redirect
Uris []string - Scope string
- Token
Endpoint stringAuth Method
- client_
id string - redirect_
uris list(string) - scope string
- token_
endpoint_ stringauth_ method
- client
Id String - redirect
Uris List<String> - scope String
- token
Endpoint StringAuth Method
- client
Id string - redirect
Uris string[] - scope string
- token
Endpoint stringAuth Method
- client_
id str - redirect_
uris Sequence[str] - scope str
- token_
endpoint_ strauth_ method
- client
Id String - redirect
Uris List<String> - scope String
- token
Endpoint StringAuth Method
ZeroTrustAccessAiControlsMcpServerErrorDetails, ZeroTrustAccessAiControlsMcpServerErrorDetailsArgs
- Cause string
- Underlying error message
- Is
Upstream bool - True = MCP server returned an error. False = couldn't reach the server
- Mcp
Code double - MCP protocol error code
- Retryable bool
- Whether the error is transient and worth retrying
- Status
Code double - HTTP status code from the server
- Cause string
- Underlying error message
- Is
Upstream bool - True = MCP server returned an error. False = couldn't reach the server
- Mcp
Code float64 - MCP protocol error code
- Retryable bool
- Whether the error is transient and worth retrying
- Status
Code float64 - HTTP status code from the server
- cause string
- Underlying error message
- is_
upstream bool - True = MCP server returned an error. False = couldn't reach the server
- mcp_
code number - MCP protocol error code
- retryable bool
- Whether the error is transient and worth retrying
- status_
code number - HTTP status code from the server
- cause String
- Underlying error message
- is
Upstream Boolean - True = MCP server returned an error. False = couldn't reach the server
- mcp
Code Double - MCP protocol error code
- retryable Boolean
- Whether the error is transient and worth retrying
- status
Code Double - HTTP status code from the server
- cause string
- Underlying error message
- is
Upstream boolean - True = MCP server returned an error. False = couldn't reach the server
- mcp
Code number - MCP protocol error code
- retryable boolean
- Whether the error is transient and worth retrying
- status
Code number - HTTP status code from the server
- cause str
- Underlying error message
- is_
upstream bool - True = MCP server returned an error. False = couldn't reach the server
- mcp_
code float - MCP protocol error code
- retryable bool
- Whether the error is transient and worth retrying
- status_
code float - HTTP status code from the server
- cause String
- Underlying error message
- is
Upstream Boolean - True = MCP server returned an error. False = couldn't reach the server
- mcp
Code Number - MCP protocol error code
- retryable Boolean
- Whether the error is transient and worth retrying
- status
Code Number - HTTP status code from the server
ZeroTrustAccessAiControlsMcpServerUpdatedPrompt, ZeroTrustAccessAiControlsMcpServerUpdatedPromptArgs
- Name string
- Name of the tool or prompt capability to override.
- Alias string
- Custom name exposed for the capability.
- Description string
- Custom description exposed for the capability.
- Enabled bool
- Whether the capability is available through the MCP server.
- Name string
- Name of the tool or prompt capability to override.
- Alias string
- Custom name exposed for the capability.
- Description string
- Custom description exposed for the capability.
- Enabled bool
- Whether the capability is available through the MCP server.
- name string
- Name of the tool or prompt capability to override.
- alias string
- Custom name exposed for the capability.
- description string
- Custom description exposed for the capability.
- enabled bool
- Whether the capability is available through the MCP server.
- name String
- Name of the tool or prompt capability to override.
- alias String
- Custom name exposed for the capability.
- description String
- Custom description exposed for the capability.
- enabled Boolean
- Whether the capability is available through the MCP server.
- name string
- Name of the tool or prompt capability to override.
- alias string
- Custom name exposed for the capability.
- description string
- Custom description exposed for the capability.
- enabled boolean
- Whether the capability is available through the MCP server.
- name str
- Name of the tool or prompt capability to override.
- alias str
- Custom name exposed for the capability.
- description str
- Custom description exposed for the capability.
- enabled bool
- Whether the capability is available through the MCP server.
- name String
- Name of the tool or prompt capability to override.
- alias String
- Custom name exposed for the capability.
- description String
- Custom description exposed for the capability.
- enabled Boolean
- Whether the capability is available through the MCP server.
ZeroTrustAccessAiControlsMcpServerUpdatedTool, ZeroTrustAccessAiControlsMcpServerUpdatedToolArgs
- Name string
- Name of the tool or prompt capability to override.
- Alias string
- Custom name exposed for the capability.
- Description string
- Custom description exposed for the capability.
- Enabled bool
- Whether the capability is available through the MCP server.
- Name string
- Name of the tool or prompt capability to override.
- Alias string
- Custom name exposed for the capability.
- Description string
- Custom description exposed for the capability.
- Enabled bool
- Whether the capability is available through the MCP server.
- name string
- Name of the tool or prompt capability to override.
- alias string
- Custom name exposed for the capability.
- description string
- Custom description exposed for the capability.
- enabled bool
- Whether the capability is available through the MCP server.
- name String
- Name of the tool or prompt capability to override.
- alias String
- Custom name exposed for the capability.
- description String
- Custom description exposed for the capability.
- enabled Boolean
- Whether the capability is available through the MCP server.
- name string
- Name of the tool or prompt capability to override.
- alias string
- Custom name exposed for the capability.
- description string
- Custom description exposed for the capability.
- enabled boolean
- Whether the capability is available through the MCP server.
- name str
- Name of the tool or prompt capability to override.
- alias str
- Custom name exposed for the capability.
- description str
- Custom description exposed for the capability.
- enabled bool
- Whether the capability is available through the MCP server.
- name String
- Name of the tool or prompt capability to override.
- alias String
- Custom name exposed for the capability.
- description String
- Custom description exposed for the capability.
- enabled Boolean
- Whether the capability is available through the MCP server.
Import
$ pulumi import cloudflare:index/zeroTrustAccessAiControlsMcpServer:ZeroTrustAccessAiControlsMcpServer example '<account_id>/<id>'
To learn more about importing existing cloud resources, see Importing resources.
Package Details
- Repository
- Cloudflare pulumi/pulumi-cloudflare
- License
- Apache-2.0
- Notes
- This Pulumi package is based on the
cloudflareTerraform Provider.
published on Tuesday, Aug 25, 2026 by Pulumi