Cloudflare
Org-level connection
Cloudflare is connected once at the org level by an admin. The credential is shared across all groups that have been granted access — individual team members don't need to connect their own accounts.
Getting your API key
Create a scoped API Token in Cloudflare → My Profile → API Tokens → Create Token. For the target zone(s), grant EDIT scopes so agents can both diagnose and remediate: Zone → Zone Settings: Edit, Zone → DNS: Edit, Zone → Bot Management: Edit (if your plan includes Bot Management), Zone → WAF/Config (Rulesets): Edit, Zone → Cache Purge: Purge, plus Zone → Zone: Read and Zone → Analytics: Read. Then paste the token below. Optionally add your Account ID and a Zone ID to save agents from looking them up.
Ready to connect?
Sign in to On Belay and open the Integrations page to add Cloudflare.
Permissions (scopes)
These are the data scopes On Belay can be granted for Cloudflare. Your org admin controls which scopes are enabled per group.
| Scope | Description | Access |
|---|---|---|
zone:read | List zones, read zone details and settings | Read only |
zone:write | Edit zone settings (SSL, redirects, canonicalization) | Read / Write |
dns:read | Read DNS records (proxied vs DNS-only) | Read only |
dns:write | Create/update/delete DNS records (toggle proxied) | Read / Write |
bot_management:read | Read bot & AI-crawler classification config | Read only |
bot_management:write | Update bot & AI-crawler config (block AI scrapers, managed robots.txt) | Read / Write |
waf:read | Read WAF/bot/redirect rulesets | Read only |
waf:write | Create/update/delete WAF/bot/redirect rules | Read / Write |
analytics:read | Read analytics, AI-crawler metrics, and security events (GraphQL) | Read only |
cache:purge | Purge cached content | Read / Write |
Troubleshooting
"Invalid API key" or "Unauthorized" error
Connected but Claude can't access data
The key expires or stops working
Still stuck? We're happy to help.
Contact support →