Cloudflare

The 1Password SaaS Manager integration with Cloudflare supports both the core Cloudflare services and also Cloudflare Zero Trust (also known as Cloudflare Access).

Creating an access token

To connect you will need to create an Access token in Cloudflare with the correct permissions, which will depend on the features you want access to.

  1. Go to My Profile:

    Cloudflare profile menu

  2. Choose API Tokens and then click Create Token:

    Cloudflare API Tokens page with Create Token selected

  3. Scroll down the page until you find the Custom token section and then click Get started. This allows you to create a token with the minimal set of permissions required by SaaS Manager which is more secure:

    Cloudflare Create API Token page with Custom token Get started selected

  4. Add the permissions required, based on the table below, using Add more to add each additional permission:

    Cloudflare custom API token permissions configuration

    Users, roles and activityAccount | Account Settings | Read
    LicencesAccount | Billing | Read
    Provisioning and deprovisioningAccount | Account Settings | Edit
    Zero Trust / Access

    Account | Access: Apps and policies | Read

    Account | Access: Audit logs | Read

    Account | Zero Trust | Read

  5. Optionally add IP address restrictions for SaaS Manager IP addresses:

    Cloudflare custom API token configuration

  6. Click Continue to summary when you are ready.

    Cloudflare custom API token summary

  7. Finally click Create Token and copy it to the clipboard:

    Cloudflare dialog showing the generated API token

  8. In SaaS Manager, navigate to Integrations > Cloudflare. Click Connect. Paste the token into the API key field, then click Connect:

Note

If you don’t use Cloudflare Zero Trust (also known as Cloudflare Access) make sure that the box “Cloudflare Zero Trust Access” is unchecked. Otherwise the integration will show as “Enabled with issues” showing a warning “Unable to fetch account apps, make sure permission has been configured for your API token.”



Published: