Customer-owned
Runtime state and access controls remain inside your Cloudflare account.
Company Access canary
Deploy a read-only MCP Portal and management page into your Cloudflare account. The installer asks for a short-lived grant only after you review the exact plan.
Runtime state and access controls remain inside your Cloudflare account.
Only the tools you name are enabled; newly discovered tools stay off.
The retained result offers a bounded removal plan during the recovery window.
Step 1 of 4
Choose two unused hostnames beneath one active Cloudflare zone. The management hostname is for administrators; the portal hostname is the MCP connection.
Step 2 of 4
Use a public HTTPS MCP endpoint. This canary accepts only unauthenticated upstreams; provider credentials are never collected here.
Step 3 of 4
Creating a plan performs no writes. Authorization begins only after you approve the exact plan shown here.
Step 4 of 4
Cloudflare will show the exact short-lived permission grant. Ankka does not receive or retain your Cloudflare password or access token.
Use the primary administrator selected in step one, choose exactly one account, and verify the active zone.
Installation result
Checking the retained installation result…
Canary rollback
Removal is available only during the retained recovery window. It removes the exact receipt-owned canary resources; your Cloudflare zone and unrelated resources remain.