+++ title = "Cloudflare" description = "Cloudflare DNS provider plugin" weight = 1 +++ The `mlf-dns-cloudflare` plugin reconciles `_lexicon.*` TXT records using [Cloudflare's DNS API](https://developers.cloudflare.com/api/resources/dns/). ## Install ```bash cargo install --path dns-plugins/mlf-dns-cloudflare ``` (Or download the prebuilt binary from GitHub releases once those exist.) Make sure `mlf-dns-cloudflare` is on your `$PATH` so `mlf-plugin-host` can spawn it. ## Credentials Options schema: | Field | Type | Required | Notes | |---|---|---|---| | `api_token` | secret | yes | Cloudflare API token. Create one at . | ### Token scopes The token needs `Zone.DNS:Edit` on the zone(s) you'll publish lexicons under. `Zone:Read` is implied — the plugin walks `/zones?name=...` to resolve which hosted zone covers a given `_lexicon.` name. Use the **"Edit zone DNS"** template and set the "Zone Resources" filter to the specific zone you're publishing under (or "All zones" if you're happy with that). ## Log in ```bash mlf login dns cloudflare ``` Prompts for the API token (masked), verifies it by calling `/user/tokens/verify`, and stores it in the credentials file. Non-interactive (CI): ```bash mlf login dns cloudflare --api-token $CF_TOKEN --project ``` ## Use in mlf.toml ```toml [publish] dns = "cloudflare" ``` ## Quirks - **Multiple TXT records at the same name.** Cloudflare allows it; we normalise to "exactly one" on upsert. If you had stray TXT records at `_lexicon.` from a prior hand-edit, the first `mlf publish` will replace them all. - **API token vs. Global API Key.** The plugin only accepts the newer scoped API tokens. Global API Keys won't work. - **No `--force` on the Cloudflare side.** If your TXT currently points at a different DID, the refusal to overwrite comes from `mlf publish` itself (the DNS mismatch gate), not from Cloudflare.