Cloudflare
Connect Cloudflareca access review source using an APIscalable token so the platform can list account members, roles, and MFA status for review.
the platform reads the members of your account.CloudflarethroughCloudflareAPIso that you can verify who has access.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- Member in the accountCloudflareon which you want to review, with privileges to grant reading permissions at account level (Super Administrator - All Privileges One account is enough. Administrator also works)
- Each member of the group must be examined (Account Resources set to All accounts or specific accounts), because the platform only sees the accounts for which the token is authorized
Collected Fields
Section entitled “Collected Fields”| the platform field | Cloudflare field | Notes |
|---|---|---|
| Name | first_name and last_name |
Combined in the member's display name |
email |
||
| Role | roles[].name |
Default to Member when the Member does not have roles |
| Admin | roles[].name |
Flag as administrator when a role is Super Administrator - All privileges or Administrator |
| Status | status |
A member is active when status is accepted |
| MFA | two_factor_authentication_enabled |
If two-factor authentication is enabled for a member |
| Last login | Not supported | |
| External ID | id |
Stable ID used to track your account through reviews |
| Created at | Not supported |
Step 1: Create an API Token
Section entitled “Step 1: Create anAPIToken”- In the Cloudflare dashboard, go to My Profile > API Tokens > Create Token, then choose get Started under Custom token.
- Name it (for example
Probo Access Review), add permission Account > Account Settings > Read, and set Account Resources to Include > All accounts Reading access is sufficient, as the platform only has problems reading applications. - Create the token, then copy it and store it securely.
Step 2: Connect in the platform
“Step 2: Connect in the platform”- On the platform, go to Access Reviews > Sources > Add Source.
- Find Cloudflare, click API KeyHold it in your hand and click Connect.
When the token covers multiple accounts, the source name uses the first account returned by Cloudflare, even if the campaign includes members from all.
Troubleshooting
Section “Troubleshooting”- Token rejected. Confirm that it is a tokenAPI Account Settings: Read A global key will not work because it uses
X-Auth-EmailandX-Auth-Keyinstead ofAuthorization: Bearer. - No members appear. The token must be included to include the account you are reviewing (Account Resources) and its creator must be a member of that account with permission to read the account membership.