Reads your Cloudflare account live through the Cloudflare API: members, API tokens and the audit log, Zero Trust (Access applications, policies and users, WARP devices, Gateway rules, tunnels), and each zone's DNS records, TLS settings, certificates, WAF rules and Security Center findings.
For the general flow of adding a source, see Connect Data Sources.
Before you start
A Cloudflare account Super Administrator, to create an account-owned API token
Your account ID: 32 hexadecimal characters, shown on the account's home page
💡 HARVEN connects only with a read-only API token. The Global API Key is not accepted: it carries every right of its user and cannot be restricted.
Step 1 — Create an account-owned API token
In the Cloudflare dashboard, open Manage Account → Account API Tokens
Click Create Token, then Create Custom Token
Name it HARVEN
An account-owned token keeps working after the admin who created it leaves. A user-owned token (My Profile → API Tokens) works as well.
Step 2 — Grant the read-only permissions
The token is made of two policies. In each, open the categories below and select Read on the permissions listed, and nothing else.
Policy 1 — Resources: Entire Account (16 permissions)
Category | Permission | Used for |
|---|---|---|
App Security | Account Security Insights | Security Center findings |
Cloudflare One / Zero Trust | Access: Apps | Access applications |
Cloudflare One / Zero Trust | Access: Audit Logs | Last-seen identity of each user |
Cloudflare One / Zero Trust | Access: Device Posture | Device posture rules |
Cloudflare One / Zero Trust | Access: Identity Providers | Identity providers |
Cloudflare One / Zero Trust | Access: Organizations | Zero Trust settings |
Cloudflare One / Zero Trust | Access: Policies | Access policies |
Cloudflare One / Zero Trust | Access: SCIM Logs | SCIM provisioning events |
Cloudflare One / Zero Trust | Access: Service Tokens | Service tokens |
Cloudflare One / Zero Trust | Access: Users | Zero Trust users |
Cloudflare One / Zero Trust | Cloudflare One Connector: cloudflared | Tunnel routes |
Cloudflare One / Zero Trust | Zero Trust | WARP devices, Gateway rules |
Analytics & Logs | Account Analytics | SaaS usage, Access logins |
Account & Billing | Account API Tokens | API tokens |
Account & Billing | Account Settings | Account, members, audit log |
Other | Resource Library | SaaS applications (App Library) |
Policy 2 — Click Add policy, Resources: All Domains (5 permissions)
Category | Permission | Used for |
|---|---|---|
DNS & Zones | Zone | Zones |
DNS & Zones | Zone Settings | Zone security settings |
DNS & Zones | DNS | DNS records, DNSSEC |
App Security | Zone WAF | WAF rules |
Cache & Performance | SSL and Certificates | Edge certificates |
Choose the individual Access: … permissions above rather than the combined ones (Access, Access: Organizations, Identity Providers, and Groups), which also grant reading your Access groups. Account SSL & Certificates in the account list is a different permission and is not needed.
⚠️ Do not add Zero Trust: PII. HARVEN does not need un-redacted personal data.
Step 3 — Copy the token
Create the token and copy its value immediately. Cloudflare shows it only once, and the token ID shown afterwards does not work in its place
Copy the Account ID from the account's home page
What to enter in HARVEN
Account ID — the 32-character account ID, not the account name or a zone ID
API token — the token value from Step 3
When you save, HARVEN tests the connection: it reads the account with the token. A wrong account ID, a revoked token or a missing Account Settings permission shows up right away. The other permissions are checked when a query first reads a table that needs them: a missing one fails that query, and the error names the permission.
What HARVEN reads
account — The account and its Zero Trust settings: account (account_id, name, type, created_on), security (enforce_twofactor), Zero Trust (zt_auth_domain, zt_session_duration, zt_seat_expiration_inactive_time)
account_members — Dashboard members: member (member_id, user_id, email, first_name, last_name, status), access (roles, is_super_admin, is_admin), security (two_factor_enabled)
api_tokens — Account-owned API tokens: token (token_id, name, status, creator_email), rights (permission_groups, has_write, ip_restricted), lifetime (issued_on, modified_on, last_used_on, expires_on, not_before)
audit_logs — The account audit log: event (log_id, action_time, action_type, action_result, action_description), actor (actor_email, actor_type, actor_context, actor_ip, actor_token_id), resource (resource_product, resource_type, resource_id, zone_name)
access_apps — Applications protected by Cloudflare Access: app (app_id, aud, name, domain, type), login (allowed_idps, policy_ids, session_duration, auto_redirect_to_identity), activity (created_at, updated_at)
access_policies — Reusable Access policies: policy (policy_id, name, decision, app_count), rules (include, require, exclude), controls (mfa_required, approval_required, purpose_justification_required, session_duration), activity (updated_at)
access_identity_providers — Zero Trust login methods: provider (idp_id, name, type), provisioning (scim_enabled, scim_user_deprovision, scim_seat_deprovision)
access_users — Zero Trust users: user (user_id, email, name), seats (access_seat, gateway_seat), activity (last_successful_login, created_at, updated_at)
access_user_identities — Each user's identity at their last login: identity (user_id, email, idp_id, idp_type, issued_at), device (device_id, is_warp, is_gateway, device_posture), location (country)
access_service_tokens — Machine credentials for Access: token (token_id, name, client_id, duration), lifetime (expires_at, last_seen_at, created_at, updated_at)
access_login_stats — Access logins per day: login (day, app_name, app_type, idp, login_type, outcome), volume (logins, users)
scim_events — Users and groups pushed by your identity provider over SCIM: event (logged_at, idp_id, resource_type, request_method, status, is_deprovision, error_description), target (user_email, group_name, cf_resource_id, idp_resource_id)
devices — WARP-enrolled devices: device (device_id, name, device_type, os_version, client_version, serial_number, manufacturer, model), activity (last_seen_at, last_seen_user_email, active_registrations, created_at, deleted_at)
device_posture_rules — Device posture checks: rule (rule_id, name, type, description, platforms, input), management (checks_management), schedule (schedule, expiration)
gateway_rules — Gateway filtering policies: rule (rule_id, name, action, enabled, precedence, filters), match (traffic, identity, device_posture), activity (created_at, updated_at)
saas_applications — Cloudflare's SaaS catalog with your review status: app (app_id, name, hostnames, supported), review (review_status), risk (confidence_score, gen_ai_score)
gateway_app_usage — SaaS usage seen by Gateway: app (app_id, review_status), volume (users, requests, bytes_sent, bytes_received), period (first_seen, last_seen, period_start, period_end)
tunnel_routes — Public routes of Cloudflare Tunnels: tunnel (tunnel_id, tunnel_name, tunnel_status, config_source, tunnel_created_at, conns_active_at), route (hostname, path, service, service_scheme, service_port), protection (access_required)
zones — Domains on Cloudflare: zone (zone_id, name, status, paused, type, plan_name), registration (name_servers, original_registrar), security (phishing_detected), activity (created_on, activated_on)
zone_security_settings — Edge security settings of each zone: zone (zone_id, zone_name), TLS (ssl_mode, min_tls_version, tls_1_3, always_use_https, automatic_https_rewrites), HSTS (hsts_enabled, hsts_max_age, hsts_include_subdomains, hsts_preload), protection (security_level, browser_check, dnssec_status)
dns_records — DNS records of every zone: record (record_id, zone_id, zone_name, type, name, content, ttl, proxied), notes (comment, tags), activity (created_on, modified_on)
certificates — Edge certificates of every zone: certificate (certificate_id, zone_id, zone_name, origin, pack_type, hosts, status), issuance (issuer, certificate_authority, validation_method), lifetime (uploaded_on, expires_on)
waf_rules — WAF rules of every zone: rule (zone_id, zone_name, phase, rule_id, description, action, enabled, expression), ruleset (managed_ruleset), activity (last_updated)
security_insights — Security Center findings: finding (insight_id, zone_id, subject, issue_type, issue_class, severity), status (status, dismissed, user_classification), detection (since, last_seen, detection_method), remediation (resolve_text, resolve_link)
How the tables are queried
HARVEN reads Cloudflare live on every query; nothing is copied or stored.
zone_security_settings, dns_records, certificates and waf_rules are read zone by zone, up to 100 zones per query. A filter on zone_id or zone_name limits the zones read, and on waf_rules a filter on phase saves calls too.
access_user_identities is read user by user, so it is always joined to access_users. A query without that join is refused rather than run. A user who never logged in has no row.
If Zero Trust Access is not enabled on the account, the Access tables return no rows instead of failing, and the zt_* columns of account stay empty.
audit_logs covers the last 30 days unless the query names a date range on action_time, and 90 days at most. scim_events also covers the last 30 days by default, and stays empty unless an identity provider pushes users to Cloudflare over SCIM.
gateway_app_usage and access_login_stats read Cloudflare's daily totals, not raw logs. They cover the last 30 days by default, up to 90 days per query and one year back. Over more than 30 days, users in gateway_app_usage is a minimum, since distinct users cannot be added across periods.
devices and gateway_app_usage need devices enrolled in WARP. tunnel_routes lists the routes of remotely managed tunnels; a locally managed tunnel keeps its routes on the origin host, so it appears with no route.
saas_applications is Cloudflare's whole catalog, about 1,500 applications. review_status shows which ones your team approved or marked unapproved.
Cloudflare allows 1,200 API requests per 5 minutes, shared with your team's own dashboard use. HARVEN paces its calls below that rate. If the quota runs out anyway, Cloudflare blocks API calls for 5 minutes, and a query that hits the block fails at once rather than waiting.
If the connection fails
"Cloudflare rejected the API token" — paste the token value shown once at creation, not its ID. If the token was revoked or has expired, create a new one
"The token cannot read this account" — check the account ID, and that the token was created in (or scoped to) this account
"Access forbidden (403)" — the token is missing the Account Settings permission from Step 2
"Must be the 32-character Cloudflare account ID" — copy the Account ID from the account's home page, not the account name
"Cloudflare rate limit reached" — wait a few minutes and save again
Official documentation
Need help? Contact [email protected].