Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Cloudflare

Connect Cloudflare as an access review source using a scoped API Token so Probo can list account members, roles, and MFA status for review.

View as Markdown

Probo reads your Cloudflare account’s members through the Cloudflare API so you can review who has access.

  • Probo organization administrator access
  • Membership in the Cloudflare account you want to review, with privileges to grant account-level read permissions (Super Administrator - All Privileges is sufficient; an account Administrator also works)
  • The token scoped to include every account whose members should be reviewed (Account Resources set to All accounts or the specific accounts), since Probo only sees accounts the token is authorized for
Probo fieldCloudflare fieldNotes
Namefirst_name and last_nameCombined into the member’s display name
Emailemail
Roleroles[].nameDefaults to Member when the member has no roles
Adminroles[].nameFlagged as an administrator when a role is Super Administrator - All Privileges or Administrator
StatusstatusA member is active when status is accepted
MFAtwo_factor_authentication_enabledWhether two-factor authentication is enabled for the member
Last loginNot supported
External IDidStable identifier used to track the account across reviews
Created atNot supported
  1. In the Cloudflare dashboard, go to My Profile > API Tokens > Create Token, then choose Get started under Custom token.
  2. Name it (e.g. Probo Access Review), add the permission Account > Account Settings > Read, and set Account Resources to Include > All accounts (or the specific accounts to review). Read access is enough, since Probo only issues read requests.
  3. Create the token, then copy it and store it securely. It’s shown only once.
  1. In Probo, go to Access Review > Connections.
  2. Find Cloudflare, click API Key, paste the token, and click Connect.

Probo pulls members from every Cloudflare account included in the token’s scope. When the token covers several accounts, the source name uses the first account returned by Cloudflare even though the campaign includes members from all of them.

  • Token rejected. Confirm it’s a scoped API Token with Account Settings: Read permission. A Global API Key won’t work, because it uses X-Auth-Email and X-Auth-Key headers instead of Authorization: Bearer.
  • No members appear. The token must be scoped to include the account you’re reviewing (Account Resources), and its creator must be a member of that account with permission to read the account’s membership.