jump to content

Cloudflare

Connect Cloudflareca access review source using an APIscalable token so the platform can list account members, roles, and MFA status for review.

Show as Markdown

the platform reads the members of your account.CloudflarethroughCloudflareAPIso that you can verify who has access.

  • the platform organization administrator access
  • Member in the accountCloudflareon which you want to review, with privileges to grant reading permissions at account level (Super Administrator - All Privileges One account is enough. Administrator also works)
  • Each member of the group must be examined (Account Resources set to All accounts or specific accounts), because the platform only sees the accounts for which the token is authorized
the platform field Cloudflare field Notes
Name first_name and last_name Combined in the member's display name
Email email
Role roles[].name Default to Member when the Member does not have roles
Admin roles[].name Flag as administrator when a role is Super Administrator - All privileges or Administrator
Status status A member is active when status is accepted
MFA two_factor_authentication_enabled If two-factor authentication is enabled for a member
Last login Not supported
External ID id Stable ID used to track your account through reviews
Created at Not supported
  1. In the Cloudflare dashboard, go to My Profile > API Tokens > Create Token, then choose get Started under Custom token.
  2. Name it (for example Probo Access Review), add permission Account > Account Settings > Read, and set Account Resources to Include > All accounts Reading access is sufficient, as the platform only has problems reading applications.
  3. Create the token, then copy it and store it securely.

Step 2: Connect in the platform

“Step 2: Connect in the platform”
  1. On the platform, go to Access Reviews > Sources > Add Source.
  2. Find Cloudflare, click API KeyHold it in your hand and click Connect.

When the token covers multiple accounts, the source name uses the first account returned by Cloudflare, even if the campaign includes members from all.

  • Token rejected. Confirm that it is a tokenAPI Account Settings: Read A global key will not work because it uses X-Auth-Email and X-Auth-Key instead of Authorization: Bearer.
  • No members appear. The token must be included to include the account you are reviewing (Account Resources) and its creator must be a member of that account with permission to read the account membership.

Ultima actualizare: