---
title: Connect Cloudflare
description: How to connect your Cloudflare account to Advisor through OAuth or a read-only API token, and how to follow the first sync.
updated: 2026-09-27
---

The connection gives Advisor read access to your Cloudflare account. Once the connection is active, the first sync starts automatically, and the score shows up when collection finishes.

## Before you start

- You need a tenant role that can manage connections, such as **Tenant Admin**.
- In Cloudflare, you need access to the account you are connecting.
- Each tenant connects **one** Cloudflare account.

:::note
Neither method uses write permissions. Advisor does not change any setting in your Cloudflare account.
:::

## Connect with OAuth

This is the recommended method. You approve the permissions on Cloudflare's own screen, with no token to create or store.

1. In Advisor, go to **Administração** (Administration) > **Integrações** (Integrations).
2. Select **Adicionar conexão** (Add connection).
3. Select **Conectar com a Cloudflare** (Connect with Cloudflare).
4. On the Cloudflare screen, choose the account and approve the read permissions.
5. Back in Advisor, the connection shows up on the **Cloudflare Edge** card and the first sync is queued.

## Connect with an API token

Use this method when OAuth is not available in your environment or when your company policy requires a dedicated token.

1. In the Cloudflare dashboard, go to **My Profile** > **API Tokens** and select **Create Token**.
2. Build the token with the permissions in the table below, all with **Read** access.
3. Copy the **Account ID**, shown on the account home page and in the sidebar of any zone.
4. In Advisor, go to **Administração** > **Integrações** > **Adicionar conexão** and choose **ou use um token de API** (or use an API token).
5. Paste the **Account ID** and the **Token de API** (API token) and confirm the connection.

The connection name comes from Cloudflare itself.

### Token permissions

Names match Cloudflare's token builder. All permissions use **Read** access.

| Scope | Permissions |
|---|---|
| Account | Account Settings, Account Analytics, Account Rulesets, Account Firewall Access Rules |
| Zone | Zone, Zone Settings, DNS, DNS Settings, Zone WAF, Analytics, Firewall Services, Transform Rules, Managed Headers, Dynamic Redirect, Cache Settings, Config Settings |

:::caution
When the token expires or is revoked, collection stops. Replace it in **Integrações** > **Editar token** (Edit token). The connection's Account ID does not change.
:::

## After connecting

Advisor collects four kinds of data, each with its own sync:

| Sync | What it brings |
|---|---|
| Métricas (Metrics) | Traffic, WAF and plans for the period. On the first collection, up to 12 months back. |
| Postura (Posture) | The configuration checked against the rules, which produces the score and the risks. |
| Alterações (Changes) | The log of who changed what in the Cloudflare account. |
| DNS | The records that make up the Inventory and origin exposure probing. It is the slowest kind. |

While the first collection runs, Advisor shows the **Sincronização em andamento** (Sync in progress) notice. After that, collection runs every day at 02:00 (Brasília time). For details, refer to [Connections and sync](/en/advisor/conceitos/conexoes-e-sincronizacao/).

Once the score is ready, refer to [how the Maturity Score is calculated](/en/advisor/conceitos/score-de-maturidade/).

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/primeiros-passos/conectar-cloudflare/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
