> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oasm.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Cloudflare

> Sync Cloudflare zones and DNS records into your attack surface as targets and assets

The Cloudflare integration reads the zones and DNS records in your Cloudflare account and adds them to your workspace. Each zone becomes a scan target, and the hostnames inside it become assets under that target.

## Prerequisites

* A Cloudflare account that contains the zones you want to sync.
* A Cloudflare **API token** with read access to zones and DNS records — the `Zone:Read` and `DNS:Read` permissions.
* Access to create tokens in the Cloudflare dashboard (**My Profile → API Tokens → Create Token**).

<Info>
  Use a scoped API token rather than a global API key. A token can be limited to specific zones and permissions, and revoked without affecting other tooling.
</Info>

## Connect Cloudflare

<Steps>
  <Step title="Open the Applications tab">
    In the console sidebar, open **Integrations** and select the **Applications** tab.
  </Step>

  <Step title="Open Cloudflare">
    Select the **Cloudflare** card.
  </Step>

  <Step title="Enter a name and API token">
    Enter an **Integration name**, then paste your Cloudflare **API Token**.
  </Step>

  <Step title="Set a sync schedule (optional)">
    Turn on **Sync schedule** and build a cron schedule, or leave it off to sync manually. See [Schedule asset syncs](/integrations/overview#schedule-asset-syncs).
  </Step>

  <Step title="Connect">
    Select **Connect**. OASM validates the token against Cloudflare before saving the integration.
  </Step>
</Steps>

## What Cloudflare sync finds

The sync reads every zone the token can see, then each zone's DNS records.

* The **zone apex** — for example, `example.com` — becomes a **domain** target.
* Every other hostname in the zone becomes an **asset** under that target.
* The sync reads `A`, `AAAA`, `CNAME`, `MX`, `NS`, `SOA`, and `TXT` records. Other record types are ignored.
* Wildcard records such as `*.example.com` are counted but not added, because a wildcard is not a single scan target. The same applies to placeholder addresses.

<Info>
  Hostnames come back from Cloudflare in punycode form and are stored as-is. DNS records discovered by scanning can extend an asset that a later sync also touches; the sync only adds or updates records, it does not remove records found by scanners.
</Info>

## Test and sync

* **Test Integration** reads the zones with a dry run and confirms the token works. It writes nothing.
* **Sync now** queues a real sync. The detail sheet shows the last run time.
* A scheduled sync uses the same code path as **Sync now**.

## Troubleshooting

<Accordion title="Connect fails with an authorization error">
  The token is invalid, expired, or missing a permission. Confirm the token has `Zone:Read` and `DNS:Read`, and that it is scoped to the zones you expect to see.
</Accordion>

<Accordion title="A zone is missing from the sync">
  The token can only read zones in its scope. Edit the token's zone resources in Cloudflare to include the missing zone, then run **Sync now**.
</Accordion>

<Accordion title="A hostname is missing">
  Wildcard records are not materialized as targets or assets. If a hostname is not a wildcard, confirm it has a DNS record of a supported type.
</Accordion>

<Accordion title="A sync stops early on a large account">
  The sync bounds how many zones and records it reads per run to protect the queue. Run **Sync now** again to continue, or narrow the token's zone scope.
</Accordion>

## Related

<Card icon="crosshair" title="Targets" horizontal href="/target">
  Review the zones Cloudflare sync adds as targets
</Card>

<Card icon="box" title="Assets" horizontal href="/asset">
  See the hostnames discovered under each zone
</Card>

<Card icon="plug" title="Integrations overview" horizontal href="/integrations/overview">
  Learn how connections, secrets, and schedules work
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.