Skip to main content
The Cloudflare integration reads the zones and DNS records in your Cloudflare account and adds them to your workspace. Each zone becomes a scan target, and the hostnames inside it become assets under that target.

Prerequisites

  • A Cloudflare account that contains the zones you want to sync.
  • A Cloudflare API token with read access to zones and DNS records — the Zone:Read and DNS:Read permissions.
  • Access to create tokens in the Cloudflare dashboard (My Profile → API Tokens → Create Token).
Use a scoped API token rather than a global API key. A token can be limited to specific zones and permissions, and revoked without affecting other tooling.

Connect Cloudflare

1

Open the Applications tab

In the console sidebar, open Integrations and select the Applications tab.
2

Open Cloudflare

Select the Cloudflare card.
3

Enter a name and API token

Enter an Integration name, then paste your Cloudflare API Token.
4

Set a sync schedule (optional)

Turn on Sync schedule and build a cron schedule, or leave it off to sync manually. See Schedule asset syncs.
5

Connect

Select Connect. OASM validates the token against Cloudflare before saving the integration.

What Cloudflare sync finds

The sync reads every zone the token can see, then each zone’s DNS records.
  • The zone apex — for example, example.com — becomes a domain target.
  • Every other hostname in the zone becomes an asset under that target.
  • The sync reads A, AAAA, CNAME, MX, NS, SOA, and TXT records. Other record types are ignored.
  • Wildcard records such as *.example.com are counted but not added, because a wildcard is not a single scan target. The same applies to placeholder addresses.
Hostnames come back from Cloudflare in punycode form and are stored as-is. DNS records discovered by scanning can extend an asset that a later sync also touches; the sync only adds or updates records, it does not remove records found by scanners.

Test and sync

  • Test Integration reads the zones with a dry run and confirms the token works. It writes nothing.
  • Sync now queues a real sync. The detail sheet shows the last run time.
  • A scheduled sync uses the same code path as Sync now.

Troubleshooting

The token is invalid, expired, or missing a permission. Confirm the token has Zone:Read and DNS:Read, and that it is scoped to the zones you expect to see.
The token can only read zones in its scope. Edit the token’s zone resources in Cloudflare to include the missing zone, then run Sync now.
Wildcard records are not materialized as targets or assets. If a hostname is not a wildcard, confirm it has a DNS record of a supported type.
The sync bounds how many zones and records it reads per run to protect the queue. Run Sync now again to continue, or narrow the token’s zone scope.

Targets

Review the zones Cloudflare sync adds as targets

Assets

See the hostnames discovered under each zone

Integrations overview

Learn how connections, secrets, and schedules work