EvoHub Docs Sign in

Integrations

Cloudflare

Use with AI
View as MarkdownThis page as plain text, for pasting into an AI tool Open in ClaudeAsk Claude questions about this page Open in ChatGPTAsk ChatGPT questions about this page
Connect to Cursor / VS Code / ClaudeSearch and read these docs from your AI tool (MCP server)

MCP server URL

https://docs-dev.evohub.io/mcp

Claude Code

claude mcp add --transport http evohub-docs-docs https://docs-dev.evohub.io/mcp

Claude (claude.ai and Claude Desktop): Settings → Connectors → Add custom connector, and paste the URL above.

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://docs-dev.evohub.io/mcp"
      ]
    }
  }
}

Cursor — ~/.cursor/mcp.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

VS Code — .vscode/mcp.json

{
  "servers": {
    "evohub-docs-docs": {
      "type": "http",
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

EvoHub receives Cloudflare notifications through a webhook destination. Any notification policy that uses the destination opens an EvoHub alert. Alerts with a start and an end, such as DDoS attacks, resolve when Cloudflare sends the end event.

Set it up

Create the integration

In EvoHub, go to On-Call → Integrations → + Add Integration, choose Cloudflare, pick an Escalation Policy and click Create Integration. Copy the Webhook URL.

Create the destination

In the Cloudflare dashboard, go to Notifications → Destinations → Webhooks → Create. Name it, set URL to your webhook URL and leave Secret empty — the key in the URL authenticates the call.

Test and save

Save and test the webhook. Cloudflare's "Hello World" test is answered with success and opens no alert.

Use it in notifications

Go to Notifications → All Notifications → Add, pick the alert type and select the webhook destination.

What EvoHub reads

EvoHub alert Taken from
Title policy_name (or name).
Description text, Cloudflare's description of the notification.
Labels alert_type, account_id, policy_id, the alert's data fields (zone, hostname, attack type and so on), and url when the data carries a dashboard link.
Fingerprint alert_correlation_id; for health checks the health check ID; otherwise the policy and alert type.

Severity

Alert type EvoHub severity
Contains ddos, origin or health_check high
Anything else medium

Resolve and deduplication

  • alert_event: ALERT_STATE_EVENT_END resolves the alert that the matching start event opened.
  • A health check notification whose new status is Healthy resolves the open alert for that health check.
  • One-off notices, such as certificate expiry or usage notifications, have no end event and stay open until resolved in EvoHub.
  • PENDING events (Workers observability) are ignored.

Last updated