Prerequisites
- A Cloudflare account that contains the zones you want to sync.
- A Cloudflare API token with read access to zones and DNS records — the
Zone:ReadandDNS:Readpermissions. - Access to create tokens in the Cloudflare dashboard (My Profile → API Tokens → Create Token).
Use a scoped API token rather than a global API key. A token can be limited to specific zones and permissions, and revoked without affecting other tooling.
Connect Cloudflare
1
Open the Applications tab
In the console sidebar, open Integrations and select the Applications tab.
2
Open Cloudflare
Select the Cloudflare card.
3
Enter a name and API token
Enter an Integration name, then paste your Cloudflare API Token.
4
Set a sync schedule (optional)
Turn on Sync schedule and build a cron schedule, or leave it off to sync manually. See Schedule asset syncs.
5
Connect
Select Connect. OASM validates the token against Cloudflare before saving the integration.
What Cloudflare sync finds
The sync reads every zone the token can see, then each zone’s DNS records.- The zone apex — for example,
example.com— becomes a domain target. - Every other hostname in the zone becomes an asset under that target.
- The sync reads
A,AAAA,CNAME,MX,NS,SOA, andTXTrecords. Other record types are ignored. - Wildcard records such as
*.example.comare counted but not added, because a wildcard is not a single scan target. The same applies to placeholder addresses.
Hostnames come back from Cloudflare in punycode form and are stored as-is. DNS records discovered by scanning can extend an asset that a later sync also touches; the sync only adds or updates records, it does not remove records found by scanners.
Test and sync
- Test Integration reads the zones with a dry run and confirms the token works. It writes nothing.
- Sync now queues a real sync. The detail sheet shows the last run time.
- A scheduled sync uses the same code path as Sync now.
Troubleshooting
A zone is missing from the sync
A zone is missing from the sync
The token can only read zones in its scope. Edit the token’s zone resources in Cloudflare to include the missing zone, then run Sync now.
A hostname is missing
A hostname is missing
Wildcard records are not materialized as targets or assets. If a hostname is not a wildcard, confirm it has a DNS record of a supported type.
A sync stops early on a large account
A sync stops early on a large account
The sync bounds how many zones and records it reads per run to protect the queue. Run Sync now again to continue, or narrow the token’s zone scope.
Related
Targets
Review the zones Cloudflare sync adds as targets
Assets
See the hostnames discovered under each zone
Integrations overview
Learn how connections, secrets, and schedules work
