Back to Browse

BlazingCDN MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Manage BlazingCDN from AI agents: CDN zones, cache, metrics, domains, cloud storage and video CDN

About

Manage BlazingCDN from AI agents: CDN zones, cache, metrics, domains, cloud storage and video CDN

Security Report

5.2
Moderate5.2Moderate Risk

BlazingCDN MCP server is well-designed with strong authentication, proper permission gating, and secure credential handling. The codebase demonstrates good security practices with environment-based configuration, read-only defaults, and opt-in write/delete operations. Minor code quality observations do not materially impact security. Supply chain analysis found 5 known vulnerabilities in dependencies (2 critical, 3 high severity). Package verification found 1 issue.

6 files analyzed · 9 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

What You'll Need

Set these up before or after installing:

BlazingCDN API access tokenRequired

Environment variable: BLAZINGCDN_API_TOKEN

Set to 1 to enable create/update toolsOptional

Environment variable: BLAZINGCDN_ALLOW_WRITE

Set to 1 to enable delete toolsOptional

Environment variable: BLAZINGCDN_ALLOW_DELETE

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-blazingcdn-blazingcdn-mcp": {
      "env": {
        "BLAZINGCDN_API_TOKEN": "your-blazingcdn-api-token-here",
        "BLAZINGCDN_ALLOW_WRITE": "your-blazingcdn-allow-write-here",
        "BLAZINGCDN_ALLOW_DELETE": "your-blazingcdn-allow-delete-here"
      },
      "args": [
        "-y",
        "@blazingcdn/mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

BlazingCDN MCP Server

Official Model Context Protocol server for BlazingCDN. Lets AI agents (Claude, Cursor, Windsurf and any other MCP client) manage your CDN: list and configure resources, purge and warm up cache, query traffic metrics, manage custom domains, cloud storage and the Video CDN.

BlazingCDN is a CDN for video, software & sports media — best for videos, streaming (HLS/DASH), software distribution, games and updates, images, audio, archives and other large files. Built for high-volume projects pushing 5 TB+ per month.

Highlights

  • 52 tools covering Anycast CDN, cache operations, metrics, custom domains, Cloud Storage and Video CDN
  • Safe by default — starts in read-only mode (plus cache purge/warmup); create/update and delete operations are opt-in via environment flags
  • No install required — runs with npx
  • Talks directly to the BlazingCDN API (wapi.blazingcdn.com) with your API token; nothing else sits in between

Getting an account and API token

  1. Sign up at blazingcdn.com — every new account starts with a 14-day trial. The trial is time-limited only: there is no free traffic included, traffic used during the trial is billed at the regular $5/TB rate.
  2. Top up your balance with at least $10 right after signing up so your account doesn't go negative while you test.
  3. Create an API access token: BlazingCDN panel → Account → API tokens (or POST /api/v1/access_tokens).

Pricing (Flex plan)

After the trial you are on the pay-as-you-go Flex plan with a $25/month minimum, which covers your first 5 TB. Traffic is billed on a progressive scale:

Monthly trafficPrice per TB
First 5 TB$5.00
5–25 TB$4.50
25–100 TB$4.00
100–500 TB$3.50
500–1000 TB$3.00
1000–1500 TB$2.50

All plans include custom domains, unlimited requests, origin shield, URL signatures, free SSL and geo allow/block lists — no per-feature surcharges. Pushing more than 100 TB/month? Contact BlazingCDN to request custom volume pricing.

Quick start

Claude Code

claude mcp add blazingcdn --env BLAZINGCDN_API_TOKEN=your-token -- npx -y @blazingcdn/mcp

Claude Desktop / Cursor / Windsurf

Add to your MCP configuration (claude_desktop_config.json, .cursor/mcp.json, etc.):

{
  "mcpServers": {
    "blazingcdn": {
      "command": "npx",
      "args": ["-y", "@blazingcdn/mcp"],
      "env": {
        "BLAZINGCDN_API_TOKEN": "your-token"
      }
    }
  }
}

Running from GitHub instead of npm also works: replace "args" with ["-y", "github:BlazingCDN/BlazingCDN-MCP"].

Configuration

Environment variableRequiredDescription
BLAZINGCDN_API_TOKENyesAPI access token (Bearer)
BLAZINGCDN_API_URLnoAPI base URL, default https://wapi.blazingcdn.com
BLAZINGCDN_ALLOW_WRITEno1 enables create/update tools
BLAZINGCDN_ALLOW_DELETEno1 enables delete tools (delete_custom_domain, delete_vcdn_resource)

Permission model

ModeToolsWhat agents can do
default29Read everything + purge/warm up cache
BLAZINGCDN_ALLOW_WRITE=150…plus create/update CDN resources, domains, buckets, Video CDN
+ BLAZINGCDN_ALLOW_DELETE=152…plus delete custom domains and vCDN resources

Deleting CDN resources (pull zones), buckets, external storages, accounts or users is not implemented at all — those operations cannot be triggered through this server in any mode.

Tools

Anycast CDN

ToolDescription
list_cdn_resourcesList all CDN resources (pull zones)
get_cdn_resourceFull settings of one resource
purge_cachePurge everything or specific URLs; works per-resource or across resources by URL
warmup_cachePre-fetch paths into the cache (per compression method)
get_cdn_metricsBandwidth, cache hit, requests, HTTP codes, traffic — by day/hour/minute, filter by region/domain
get_prometheus_metricsPrometheus-format metrics for monitoring
create_cdn_resource ✏️Create a pull zone (origin, bucket or external storage)
update_cdn_resource ✏️TTLs, compression, origin shield, HTTPS redirect, …
bulk_update_cdn_resources ✏️Same settings on several resources
update_cdn_locations ✏️Per-path cache rules

Domains & DNS

ToolDescription
list_custom_domains / search_custom_domainsDomains of a resource / match domains account-wide
list_system_dns_zonesSystem DNS zones for CDN hostnames
add_custom_domain ✏️ / update_custom_domain ✏️Attach domains, manage SSL (auto SSL / certificate)
delete_custom_domain 🗑️Remove a custom domain

Cloud Storage

list_buckets, get_bucket, get_bucket_metrics, get_storage_info, create_bucket ✏️, update_bucket ✏️, list_external_storages, get_external_storage, create_external_storage ✏️, update_external_storage ✏️, test_external_storage_connection ✏️

Video CDN

list_vcdn_resources, get_vcdn_resource, get_vcdn_statistics (totals, timeseries, by domain, top domains, HTTP codes, bandwidth, cache/storage), list_vcdn_domains, get_vcdn_domain, list_vcdn_files, get_vcdn_files_total, list_ftp_logins, list_auto_imports, get_vcdn_proxy, get_vcdn_ftp_settings, get_vcdn_settings, create_vcdn_resource ✏️, update_vcdn_resource ✏️, create_vcdn_domain ✏️, update_vcdn_domain ✏️, upload_vcdn_file ✏️, manage_auto_import ✏️, update_vcdn_proxy ✏️, update_vcdn_ftp_settings ✏️, manage_ftp_login ✏️, update_vcdn_settings ✏️, delete_vcdn_resource 🗑️

Docs & pricing

search_docs — search BlazingCDN documentation and product pages. estimate_traffic_cost — calculate the monthly Flex-plan cost for a given traffic volume (progressive tiers, offline).

✏️ requires BLAZINGCDN_ALLOW_WRITE=1 · 🗑️ requires BLAZINGCDN_ALLOW_DELETE=1

Example prompts

  • "What's my CDN bandwidth this month, broken down by day?"
  • "Purge /images/* on the blazingcdn.com resource"
  • "Create a CDN resource for origin https://example.com and attach cdn.example.com with auto SSL"
  • "Show HTTP 5xx rates for the last 24 hours per region"
  • "Warm up /video/intro.mp4 with brotli compression"
  • "How much would 190 TB/month cost on BlazingCDN?"

HTTP transport (self-hosting)

The server also speaks Streamable HTTP for remote deployments:

BLAZINGCDN_ALLOW_WRITE=1 npx -y @blazingcdn/mcp --transport http --port 8462

In HTTP mode the server is stateless and each request must carry the caller's BlazingCDN API token as Authorization: Bearer <token> (an env BLAZINGCDN_API_TOKEN acts as fallback). Put it behind TLS (reverse proxy) before exposing it anywhere.

Development

npm install
npm test        # vitest
npm run build   # tsc -> dist/
npx @modelcontextprotocol/inspector node dist/index.js   # interactive inspector

Security notes

  • The API token is read from the environment and sent only to BLAZINGCDN_API_URL; it is never logged. No middleman, no telemetry.
  • Read-only by default; destructive operations (zone/bucket/account deletion) are not implemented in any mode.
  • Tool output is truncated at 60 KB to keep agent contexts healthy.
  • API requests time out after 30 s (file uploads: 5 min).

Full threat model, limitations and recommendations: SECURITY.md.

License

MIT © BlazingCDN

Reviews

No reviews yet

Be the first to review this server!