Triagic + Cloudflare: ticket investigations over your cloud account, read-only
Query Workers Observability logs and analytics at the edge, read-only. Connects to Cloudflare's hosted server. Triagic connects to Cloudflare from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of Cloudflare.
What you can ask
- In Cloudflare, find the log lines for the Lambda that handles webhook retries between 10:00 and 10:20
- Did the error rate in Cloudflare for the API gateway change in the last six hours?
- Which alarms in Cloudflare fired this week, and which are still in alarm?
- Show me the Cloudflare deployment that was live when ticket 4819 was filed
- What is the dead-letter queue depth in Cloudflare right now?
What the agent can do
These are the 8 tools Triagic exposes from the Cloudflare MCP server. Anything else the server lists is dropped at connect time.
- query_worker_observability
- observability_keys
- observability_values
- workers_list
- workers_get_worker
- workers_get_worker_code
- search_cloudflare_documentation
- migrate_pages_to_workers_guide
Connect in three steps
- 1
Mint a read-only credential in Cloudflare
Create a dedicated user or token that can only read. A hosted Workers Observability endpoint; an allowlist of the query, keys, values and worker read tools.
- 2
Add it in the Triagic portal
Integrations, then Add shared data source, then Cloudflare.
- API token: dash.cloudflare.com → My Profile → API Tokens, with Account → Workers Observability → Read. An account-scoped token needs Account → Account Settings → Read as well, or the server cannot look up which account it is for and setup fails. A Global API Key is not accepted. It must be an API token.
- 3
Let a desktop pick it up
Saving validates the shape of what you typed. The first desktop app to sync starts Cloudflare locally and reports running or degraded with the error text.
Field-by-field setup, TLS options and the error table: Cloudflare in the docs.
Read-only, by construction
A hosted Workers Observability endpoint; an allowlist of the query, keys, values and worker read tools.
FAQ
- Can Triagic change anything in Cloudflare?
- No. A hosted Workers Observability endpoint; an allowlist of the query, keys, values and worker read tools. Give it a read-only credential as well, so the guarantee does not rest on one layer.
- What do I need to connect Cloudflare?
- API token. The desktop app on a member's machine starts the connection; the portal never holds a live process.
- Does Cloudflare cost extra?
- No. Every connector is included in the seat price. Start a 14-day trial without a card.
Related integrations
- AWS CloudWatchRead CloudWatch logs, metrics, and alarms.
- AWS SQS / SNSInspect queues, topics, and message attributes.
- Azure MonitorQuery Log Analytics and Application Insights with KQL, and read metrics and the activity log.
- AzureAsk about any Azure service the service principal can read: compute, storage, SQL, Cosmos, AKS, App Service, Monitor and more. Runs the Azure MCP server read-only; Key Vault values are never exposed.
Try it on your own Cloudflare
No card. Install the desktop app, connect Cloudflare read-only, and triage a real ticket this afternoon.