Permissions are segmented into three categories based on resource:
- Zone permissions
- Account permissions
- User permissions
Each category contains permission groups related to those resources. DNS permissions belong to the Zone category, while Billing permissions belong to the Account category. Below is a list of the available token permissions.
To obtain an updated list of token permissions, including the permission ID and the scope of each permission, use theList permission groups endpoint.
The applicable scope of user permissions iscom.cloudflare.api.user
.
Name | Description |
---|---|
API Tokens Read | Grants read access to user'sAPI tokens. |
API Tokens Edit | Grants write access to user'sAPI tokens. |
Memberships Read | Grants read access to a user'saccount memberships. |
Memberships Edit | Grants write access to a user'saccount memberships. |
User Details Read | Grants read access to user details. |
User Details Edit | Grants write access to user details. |
Name | Description |
---|---|
API Tokens Read | Grants read access to user'sAPI tokens. |
API Tokens Write | Grants write access to user'sAPI tokens. |
Memberships Read | Grants read access to a user'saccount memberships. |
Memberships Write | Grants write access to a user'saccount memberships. |
User Details Read | Grants read access to user details. |
User Details Write | Grants write access to user details. |
The applicable scope of account permissions iscom.cloudflare.api.account
.
Name | Description |
---|---|
Access: Apps and Policies Read | Grants read access toCloudflare Access applications and policies |
Access: Apps and Policies Revoke | Grants ability to revokeCloudflare Access application tokens |
Access: Apps and Policies Edit | Grants write access toCloudflare Access applications and policies |
Access: Audit Logs Read | Grants read access toCloudflare Access audit logs. |
Access: Custom Pages Read | Grants read access toCloudflare Access custom block pages. |
Access: Custom Pages Edit | Grants write access toCloudflare Access custom block pages. |
Access: Device Posture Read | Grants read access toCloudflare Access device posture. |
Access: Device Posture Edit | Grants write access toCloudflare Access device posture. |
Access: Mutual TLS Certificates Read | Grants read access toCloudflare Access mTLS certificates. |
Access: Mutual TLS Certificates Edit | Grants write access toCloudflare Access mTLS certificates. |
Access: Organizations, Identity Providers, and Groups Read | Grants read access toCloudflare Access account resources. |
Access: Organizations, Identity Providers, and Groups Revoke | Grants ability to revoke user sessions toCloudflare Access account resources. |
Access: Organizations, Identity Providers, and Groups Edit | Grants write access toCloudflare Access account resources. |
Access: Service Tokens Read | Grants read access toCloudflare Access service tokens. |
Access: Service Tokens Edit | Grants write access toCloudflare Access service tokens. |
Access: SSH Auditing Read | Grants read access toCloudflare Access SSH CAs. |
Access: SSH Auditing Edit | Grants write access toCloudflare Access SSH CAs. |
Account Analytics Read | Grants read access toaccount analytics. |
Account Custom Pages Read | Grants read access to account-levelError Pages. |
Account Custom Pages Edit | Grants write access to account-levelError Pages. |
Account Filter Lists Read | Grants read access to Account Filter Lists. |
Account Filter Lists Edit | Grants write access to Account Filter Lists. |
Account Firewall Access Rules Read | Grants read access to account firewall access rules. |
Account Firewall Access Rules Edit | Grants write access to account firewall access rules. |
Account Rulesets Read | Grants read access toAccount Rulesets. |
Account Rulesets Edit | Grants write access toAccount Rulesets. |
Account Settings Read | Grants read access toAccount resources, account membership, and account level features. |
Account Settings Edit | Grants write access toAccount resources, account membership, and account level features. |
Account: SSL and Certificates Read | Grants read access toSSL and Certificates. |
Account: SSL and Certificates Edit | Grants write access toSSL and Certificates. |
Account WAF Read | Grants read access toAccount WAF. |
Account WAF Edit | Grants write access toAccount WAF. |
Address Maps Edit | Grants write access toAddress Maps |
Address Maps Read | Grants read access toAddress Maps |
Allow Request Tracer Read | Grants read access to Request Tracer. |
API Gateway Read | Grants read access toAPI Gateway (including API Shield) for all domains in an account. |
API Gateway Edit | Grants write access toAPI Gateway (including API Shield) for all domains in an account. |
Billing Read | Grants read access tobilling profile, subscriptions, and access to fetch invoices and entitlements. |
Billing Edit | Grants write access tobilling profile, subscriptions, and access to fetch invoices and entitlements. |
Bulk URL Redirects Read | Grants read access toBulk Redirects. |
Bulk URL Redirects Edit | Grants write access toBulk Redirects. |
China Network Steering Read | Grants read access toChina Network Steering. |
China Network Steering Edit | Grants write access toChina Network Steering. |
Cloudchamber Read | Grants read access to Cloudchamber deployments. |
Cloudchamber Edit | Grants write access to Cloudchamber deployments. |
Cloudflare Realtime Read | Grants read access to Cloudflare Realtime. |
Cloudflare Realtime Edit | Grants write access to Cloudflare Realtime. |
Cloudflare DEX Read | Grants read access toDigital Experience Monitoring. |
Cloudflare DEX Edit | Grants write access toDigital Experience Monitoring. |
Cloudflare Images Read | Grants read access toCloudflare Images. |
Cloudflare Images Edit | Grants write access toCloudflare Images. |
Cloudflare One Connector: cloudflared Read | Grants read access tocloudflared connectors |
Cloudflare One Connector: cloudflared Edit | Grants write access tocloudflared connectors |
Cloudflare One Connector: WARP Read | Grants read access toWARP Connectors |
Cloudflare One Connector: WARP Edit | Grants write access toWARP Connectors |
Cloudflare One Connectors Read | Grants read access to Cloudflare One connectors |
Cloudflare One Connectors Edit | Grants write access to Cloudflare One connectors |
Cloudflare One Networks Read | Grants read access to Cloudflare One routes and virtual networks |
Cloudflare One Networks Edit | Grants write access to Cloudflare One routes and virtual networks |
Cloudflare Pages Read | Grants access to viewCloudflare Pages projects. |
Cloudflare Pages Edit | Grants access to create, edit and deleteCloudflare Pages projects. |
Cloudflare Tunnel Read | Grants access to viewCloudflare Tunnels. |
Cloudflare Tunnel Edit | Grants access to create and deleteCloudflare Tunnels. |
Cloudforce One Read | Grants read access to Cloudforce One. |
Cloudforce One Edit | Grants write access to Cloudforce One. |
Email Security Read | Grants read access toCloud Email Security. |
Email Security Edit | Grants write access toEmail Security. |
Constellation Read | Grants read access toConstellation. |
Constellation Edit | Grants write access toConstellation. |
D1 Read | Grants read access toD1. |
D1 Edit | Grants write access toD1. |
DDoS Botnet Feed Read | Grants read access to Botnet Feed reports. |
DDoS Botnet Feed Edit | Grants write access to Botnet Feed configuration. |
DDoS Protection Read | Grants read access toDDoS protection. |
DDoS Protection Edit | Grants write access toDDoS protection. |
DNS Firewall Read | Grants read access toDNS Firewall. |
DNS Firewall Edit | Grants write access toDNS Firewall. |
Email Routing Addresses Read | Grants read access toEmail Routing Addresses. |
Email Routing Addresses Edit | Grants write access toEmail Routing Addresses. |
Hyperdrive Read | Grants read access toHyperdrive. |
Hyperdrive Edit | Grants write access toHyperdrive. |
Intel Read | Grants read access toIntel. |
Intel Edit | Grants write access toIntel. |
Integration Edit | Grants write access to integrations. |
IOT Read | Grants read access toIOT ↗. |
IOT Edit | Grants write access toIOT ↗. |
IP Prefixes: Read | Grants access to read IP prefix settings. |
IP Prefixes: Edit | Grants access to read/write IP prefix settings. |
IP Prefixes: BGP On Demand Read | Grants access to read IP prefix BGP configuration. |
IP Prefixes: BGP On Demand Edit | Grants access to read and change IP prefix BGP configuration. |
L3/4 DDoS Managed Ruleset Read | Grants read access toL3/4 DDoS managed ruleset. |
L3/4 DDoS Managed Ruleset Edit | Grants write access toL3/4 DDoS managed ruleset. |
Load Balancing: Monitors and Pools Read | Grants read access to account levelload balancer resources. |
Load Balancing: Monitors and Pools Edit | Grants write access to account levelload balancer resources. |
Logs Read | Grants read access to logs usingLogpull or Instant Logs. |
Logs Edit | Grants read and write access toLogpull, Logpush, and Instant Logs. |
Magic Firewall Read | Grants read access toMagic Firewall. |
Magic Firewall Edit | Grants write access toMagic Firewall. |
Magic Firewall Packet Captures Read | Grants read access toPacket Captures. |
Magic Firewall Packet Captures Edit | Grants write access toPacket Captures. |
Magic Network Monitoring Read | Grants read access toMagic Network Monitoring. |
Magic Network Monitoring Edit | Grants write access toMagic Network Monitoring. |
Magic Transit Read | Grants read access to manage a user'sMagic Transit prefixes. |
Magic Transit Edit | Grants write access to manage a user'sMagic Transit prefixes. |
Notifications Read | Grants read access toNotifications. |
Notifications Edit | Grants write access toNotifications. |
Page Shield Read | Grants read access toPage Shield. |
Page Shield Edit | Grants write access toPage Shield. |
Workers Pipelines Read | Grants read access to Cloudflare Pipelines. |
Workers Pipelines Edit | Grants write access to Cloudflare Pipelines. |
Pub/Sub Read | Grants read access toPub/Sub. |
Pub/Sub Edit | Grants write access toPub/Sub. |
Queues Read | Grants read access toQueues. |
Queues Edit | Grants write access toQueues. |
Rule Policies Read | Grants read access to Rule Policies. |
Rule Policies Edit | Grants write access to Rule Policies. |
Stream Read | Grants read access toCloudflare Stream. |
Stream Edit | Grants write access toCloudflare Stream. |
Transform Rules Read | Grants read access toTransform Rules. |
Transform Rules Edit | Grants write access toTransform Rules. |
Turnstile Read | Grants read access toTurnstile. |
Turnstile Edit | Grants write access toTurnstile. |
URL Scanner Read | Grants read access toURL Scanner. |
URL Scanner Edit | Grants write access toURL Scanner. |
Vectorize Read | Grants read access toVectorize. |
Vectorize Edit | Grants write access toVectorize. |
Workers AI Read | Grants read access toWorkers AI. |
Workers AI Edit | Grants write access toWorkers AI. |
Workers CI Read | Grants read access toWorkers CI. |
Workers CI Edit | Grants write access toWorkers CI. |
Workers KV Storage Read | Grants read access toCloudflare Workers KV Storage. |
Workers KV Storage Edit | Grants write access toCloudflare Workers KV Storage. |
Workers R2 Storage Read | Grants read access toCloudflare R2 Storage. |
Workers R2 Storage Edit | Grants write access toCloudflare R2 Storage. |
Workers Scripts Read | Grants read access toCloudflare Workers scripts. |
Workers Scripts Edit | Grants write access toCloudflare Workers scripts. |
Workers Tail Read | Grantswrangler tail read permissions. |
Zero Trust Read | Grants read access toCloudflare Zero Trust resources. |
Zero Trust Report | Grants reporting access toCloudflare Zero Trust. |
Zero Trust Edit | Grants write access toCloudflare Zero Trust resources. |
Zero Trust: PII Read | Grants read access toCloudflare Zero Trust PII. |
Zero Trust: Seats Edit | Grants write access to the number ofZero Trust seats your organization can use (and be billed for). |
Name | Description |
---|---|
Access: Apps and Policies Read | Grants read access toCloudflare Access applications and policies |
Access: Apps and Policies Revoke | Grants ability to revokeCloudflare Access application tokens |
Access: Apps and Policies Write | Grants write access toCloudflare Access applications and policies |
Access: Audit Logs Read | Grants read access toCloudflare Access audit logs. |
Access: Custom Pages Read | Grants read access toCloudflare Access custom block pages. |
Access: Custom Pages Write | Grants write access toCloudflare Access custom block pages. |
Access: Device Posture Read | Grants read access toCloudflare Access device posture. |
Access: Device Posture Write | Grants write access toCloudflare Access device posture. |
Access: Mutual TLS Certificates Read | Grants read access toCloudflare Access mTLS certificates. |
Access: Mutual TLS Certificates Write | Grants write access toCloudflare Access mTLS certificates. |
Access: Organizations, Identity Providers, and Groups Read | Grants read access toCloudflare Access account resources. |
Access: Organizations, Identity Providers, and Groups Revoke | Grants ability to revoke user sessions toCloudflare Access account resources. |
Access: Organizations, Identity Providers, and Groups Write | Grants write access toCloudflare Access account resources. |
Access: Service Tokens Read | Grants read access toCloudflare Access service tokens. |
Access: Service Tokens Write | Grants write access toCloudflare Access service tokens. |
Access: SSH Auditing Read | Grants read access toCloudflare Access SSH CAs. |
Access: SSH Auditing Write | Grants write access toCloudflare Access SSH CAs. |
Account Analytics Read | Grants read access toaccount analytics. |
Account Custom Pages Read | Grants read access to account-levelError Pages. |
Account Custom Pages Write | Grants write access to account-levelError Pages. |
Account Rule Lists Read | Grants read access to Account Filter Lists. |
Account Rule Lists Write | Grants write access to Account Filter Lists. |
Account Firewall Access Rules Read | Grants read access to account firewall access rules. |
Account Firewall Access Rules Write | Grants write access to account firewall access rules. |
Account Rulesets Read | Grants read access toAccount Rulesets. |
Account Rulesets Write | Grants write access toAccount Rulesets. |
Account Settings Read | Grants read access toAccount resources, account membership, and account level features. |
Account Settings Write | Grants write access toAccount resources, account membership, and account level features. |
Account: SSL and Certificates Read | Grants read access toSSL and Certificates. |
Account: SSL and Certificates Write | Grants write access toSSL and Certificates. |
Account WAF Read | Grants read access toAccount WAF. |
Account WAF Write | Grants write access toAccount WAF. |
Address Maps Write | Grants write access toAddress Maps |
Address Maps Read | Grants read access toAddress Maps |
Allow Request Tracer Read | Grants read access to Request Tracer. |
Account API Gateway Read | Grants read access toAPI Gateway (including API Shield) for all domains in an account. |
Account API Gateway Write | Grants write access toAPI Gateway (including API Shield) for all domains in an account. |
Billing Read | Grants read access tobilling profile, subscriptions, and access to fetch invoices and entitlements. |
Billing Write | Grants write access tobilling profile, subscriptions, and access to fetch invoices and entitlements. |
Bulk URL Redirects Read | Grants read access toBulk Redirects. |
Bulk URL Redirects Write | Grants write access toBulk Redirects. |
China Network Steering Read | Grants read access toChina Network Steering. |
China Network Steering Write | Grants write access toChina Network Steering. |
Cloudchamber Read | Grants read access to Cloudchamber deployments. |
Cloudchamber Write | Grants write access to Cloudchamber deployments. |
Realtime Read | Grants read access to Cloudflare Realtime. |
Realtime Write | Grants write access to Cloudflare Realtime. |
Cloudflare DEX Read | Grants read access toDigital Experience Monitoring. |
Cloudflare DEX Write | Grants write access toDigital Experience Monitoring. |
Images Read | Grants read access toCloudflare Images. |
Images Write | Grants write access toCloudflare Images. |
Cloudflare One Connector: cloudflared Read | Grants read access tocloudflared connectors |
Cloudflare One Connector: cloudflared Write | Grants write access tocloudflared connectors |
Cloudflare One Connector: WARP Read | Grants read access toWARP Connectors |
Cloudflare One Connector: WARP Write | Grants write access toWARP Connectors |
Cloudflare One Connectors Read | Grants read access to Cloudflare One connectors |
Cloudflare One Connectors Write | Grants write access to Cloudflare One connectors |
Cloudflare One Networks Read | Grants read access to Cloudflare One routes and virtual networks |
Cloudflare One Networks Write | Grants write access to Cloudflare One routes and virtual networks |
Pages Read | Grants access to viewCloudflare Pages projects. |
Pages Write | Grants access to create, edit and deleteCloudflare Pages projects. |
Cloudflare Tunnel Read | Grants access to viewCloudflare Tunnels. |
Cloudflare Tunnel Write | Grants access to create and deleteCloudflare Tunnels. |
Cloudforce One Read | Grants read access to Cloudforce One. |
Cloudforce One Write | Grants write access to Cloudforce One. |
Cloud Email Security: Read | Grants read access toCloud Email Security. |
Cloud Email Security: Write | Grants write access toEmail Security. |
Constellation Read | Grants read access toConstellation. |
Constellation Write | Grants write access toConstellation. |
D1 Read | Grants read access toD1. |
D1 Write | Grants write access toD1. |
DDoS Botnet Feed Read | Grants read access to Botnet Feed reports. |
DDoS Botnet Feed Write | Grants write access to Botnet Feed configuration. |
DDoS Protection Read | Grants read access toDDoS protection. |
DDoS Protection Write | Grants write access toDDoS protection. |
DNS Firewall Read | Grants read access toDNS Firewall. |
DNS Firewall Write | Grants write access toDNS Firewall. |
Email Routing Addresses Read | Grants read access toEmail Routing Addresses. |
Email Routing Addresses Write | Grants write access toEmail Routing Addresses. |
Hyperdrive Read | Grants read access toHyperdrive. |
Hyperdrive Write | Grants write access toHyperdrive. |
Intel Read | Grants read access toIntel. |
Intel Write | Grants write access toIntel. |
Integration Write | Grants write access to integrations. |
IOT Read | Grants read access toIOT ↗. |
IOT Write | Grants write access toIOT ↗. |
IP Prefixes: Read | Grants access to read IP prefix settings. |
IP Prefixes: Write | Grants access to read/write IP prefix settings. |
IP Prefixes: BGP On Demand Read | Grants access to read IP prefix BGP configuration. |
IP Prefixes: BGP On Demand Write | Grants access to read and change IP prefix BGP configuration. |
L4 DDoS Managed Ruleset Read | Grants read access toL3/4 DDoS managed ruleset. |
L4 DDoS Managed Ruleset Write | Grants write access toL3/4 DDoS managed ruleset. |
Load Balancing: Monitors and Pools Read | Grants read access to account levelload balancer resources. |
Load Balancing: Monitors and Pools Write | Grants write access to account levelload balancer resources. |
Logs Read | Grants read access to logs usingLogpull or Instant Logs. |
Logs Write | Grants read and write access toLogpull, Logpush, and Instant Logs. |
Magic Firewall Read | Grants read access toMagic Firewall. |
Magic Firewall Write | Grants write access toMagic Firewall. |
Magic Firewall Packet Captures - Read PCAPs API | Grants read access toPacket Captures. |
Magic Firewall Packet Captures - Write PCAPs API | Grants write access toPacket Captures. |
Magic Network Monitoring Read | Grants read access toMagic Network Monitoring. |
Magic Network Monitoring Write | Grants write access toMagic Network Monitoring. |
Magic Transit Read | Grants read access to manage a user'sMagic Transit prefixes. |
Magic Transit Write | Grants write access to manage a user'sMagic Transit prefixes. |
Notifications Read | Grants read access toNotifications. |
Notifications Write | Grants write access toNotifications. |
Page Shield Read | Grants read access toPage Shield. |
Page Shield Write | Grants write access toPage Shield. |
Pipelines Read | Grants read access to Cloudflare Pipelines. |
Pipelines Write | Grants write access to Cloudflare Pipelines. |
Pubsub Configuration Read | Grants read access toPub/Sub. |
Pubsub Configuration Write | Grants write access toPub/Sub. |
Queues Read | Grants read access toQueues. |
Queues Write | Grants write access toQueues. |
Rule Policies Read | Grants read access to Rule Policies. |
Rule Policies Write | Grants write access to Rule Policies. |
Stream Read | Grants read access toCloudflare Stream. |
Stream Write | Grants write access toCloudflare Stream. |
Transform Rules Read | Grants read access toTransform Rules. |
Transform Rules Write | Grants write access toTransform Rules. |
Turnstile Sites Read | Grants read access toTurnstile. |
Turnstile Sites Write | Grants write access toTurnstile. |
URL Scanner Read | Grants read access toURL Scanner. |
URL Scanner Write | Grants write access toURL Scanner. |
Vectorize Read | Grants read access toVectorize. |
Vectorize Write | Grants write access toVectorize. |
Workers AI Read | Grants read access toWorkers AI. |
Workers AI Write | Grants write access toWorkers AI. |
Workers CI Read | Grants read access toWorkers CI. |
Workers CI Write | Grants write access toWorkers CI. |
Workers KV Storage Read | Grants read access toCloudflare Workers KV Storage. |
Workers KV Storage Write | Grants write access toCloudflare Workers KV Storage. |
Workers R2 Storage Read | Grants read access toCloudflare R2 Storage. |
Workers R2 Storage Write | Grants write access toCloudflare R2 Storage. |
Workers Scripts Read | Grants read access toCloudflare Workers scripts. |
Workers Scripts Write | Grants write access toCloudflare Workers scripts. |
Workers Tail Read | Grantswrangler tail read permissions. |
Zero Trust Read | Grants read access toCloudflare Zero Trust resources. |
Zero Trust Report | Grants reporting access toCloudflare Zero Trust. |
Zero Trust Write | Grants write access toCloudflare Zero Trust resources. |
Zero Trust: PII Read | Grants read access toCloudflare Zero Trust PII. |
Zero Trust: Seats Write | Grants write access to the number ofZero Trust seats your organization can use (and be billed for). |
The applicable scope of zone permissions iscom.cloudflare.api.account.zone
.
Name | Description |
---|---|
Access: Apps and Policies Read | Grants read access toCloudflare Access zone resources. |
Access: Apps and Policies Revoke | Grants ability to revoke all tokens toCloudflare Access zone resources. |
Access: Apps and Policies Edit | Grants write access toCloudflare Access zone resources. |
Analytics Read | Grants read access toanalytics. |
API Gateway Read | Grants read access toAPI Gateway zone resources. |
API Gateway Edit | Grants write access toAPI Gateway zone resources. |
Apps Edit | Grants full access to Cloudflare Apps (deprecated, refer toWorkers instead). |
Bot Management Read | Grants read access toBot Management. |
Bot Management Edit | Grants write access toBot Management. |
Bot Management Feedback Read | Grants read access toBot Management feedback. |
Bot Management Feedback Edit | Grants write access toBot Management feedback. |
Cache Purge | Grants access topurge cache. |
Cache Rules Read | Grants read access toCache Rules. |
Cache Rules Edit | Grants write access toCache Rules. |
Cloud Connector Read | Grants read access toCloud Connector rules. |
Cloud Connector Edit | Grants write access toCloud Connector rules. |
Config Rules Read | Grants read access toConfiguration Rules. |
Config Rules Edit | Grants write access toConfiguration Rules. |
Custom Error Rules Read | Grants read access toCustom Error Rules. |
Custom Error Rules Edit | Grants write access toCustom Error Rules. |
Custom Pages Read | Grants read access toCustom Error Pages. |
Custom Pages Edit | Grants write access toCustom Error Pages. |
Dmarc Management Read | Grants read access toDMARC Management. |
Dmarc Management Edit | Grants write access toDMARC Management. |
DNS Read | Grants read access toDNS. |
DNS Write | Grants write access toDNS. |
Email Routing Rules Read | Grants read access toEmail Routing Rules. |
Email Routing Rules Edit | Grants write access toEmail Routing Rules. |
Firewall Services Read | Grants read access to Firewall resources. |
Firewall Services Edit | Grants write access to Firewall resources. |
Health Checks Read | Grants read access toHealth Checks. |
Health Checks Edit | Grants write access toHealth Checks. |
HTTP DDoS Managed Ruleset Read | Grants read access toHTTP DDoS managed ruleset. |
HTTP DDoS Managed Ruleset Edit | Grants write access toHTTP DDoS managed ruleset. |
Load Balancers Read | Grants read access toload balancer resources. |
Load Balancers Edit | Grants write access toload balancer resources. |
Logs Read | Grants read access to logs usingLogpull. |
Logs Edit | Grants write access toLogpull and Logpush. |
Managed Headers Read | Grants read access toManaged Headers. |
Managed Headers Edit | Grants write access toManaged Headers. |
Origin Rules Read | Grants read access toOrigin Rules. |
Origin Rules Edit | Grants write access toOrigin Rules. |
Page Rules Read | Grants read access toPage Rules. |
Page Rules Edit | Grants write access toPage Rules. |
Page Shield Read | Grants read access toPage Shield. |
Page Shield Edit | Grants write access toPage Shield. |
Response Compression Read | Grants read access toResponse Compression. |
Response Compression Edit | Grants write access toResponse Compression. |
Sanitize Read | Grants read access to sanitization. |
Sanitize Edit | Grants write access to sanitization. |
Single Redirect Read | Grants read access to zone-levelSingle Redirects. |
Single Redirect Edit | Grants write access to zone-levelSingle Redirects. |
SSL and Certificates Read | Grants read access toSSL configuration and certificate management. |
SSL and Certificates Edit | Grants write access toSSL configuration and certificate management. |
Transform Rules Read | Grants read access toTransform Rules. |
Transform Rules Edit | Grants write access toTransform Rules. |
Waiting Room Read | Grants read access toWaiting Room. |
Waiting Room Edit | Grants write access toWaiting Room. |
Web3 Hostnames Read | Grants read access toWeb3 Hostnames. |
Web3 Hostnames Edit | Grants write access toWeb3 Hostnames. |
Workers Routes Read | Grants read access toCloudflare Workers andWorkers KV Storage. |
Workers Routes Edit | Grants write access toCloudflare Workers andWorkers KV Storage. |
Zaraz Read | Grants read access toZaraz zone level settings. |
Zaraz Edit | Grants write access toZaraz zone level settings. |
Zone Read | Grants read access to zone management. |
Zone Edit | Grants write access to zone management. |
Zone Settings Read | Grants read access to zone settings. |
Zone Settings Edit | Grants write access to zone settings. |
Zone Versioning Read | Grants read access toZone Versioning at zone level. |
Zone Versioning Edit | Grants write access toZone Versioning at zone level. |
Zone WAF Read | Grants read access toZone WAF. |
Zone WAF Edit | Grants write access toZone WAF. |
Name | Description |
---|---|
Access: Apps and Policies Read | Grants read access toCloudflare Access zone resources. |
Access: Apps and Policies Revoke | Grants ability to revoke all tokens toCloudflare Access zone resources. |
Access: Apps and Policies Write | Grants write access toCloudflare Access zone resources. |
Analytics Read | Grants read access toanalytics. |
Domain API Gateway Read | Grants read access toAPI Gateway zone resources. |
Domain API Gateway Write | Grants write access toAPI Gateway zone resources. |
Apps Write | Grants full access to Cloudflare Apps (deprecated, refer toWorkers instead). |
Bot Management Read | Grants read access toBot Management. |
Bot Management Write | Grants write access toBot Management. |
Bot Management Feedback Read | Grants read access toBot Management feedback. |
Bot Management Feedback Write | Grants write access toBot Management feedback. |
Cache Purge | Grants access topurge cache. |
Cache Settings Read | Grants read access toCache Rules. |
Cache Settings Write | Grants write access toCache Rules. |
Cloud Connector Read | Grants read access toCloud Connector rules. |
Cloud Connector Write | Grants write access toCloud Connector rules. |
Config Settings Read | Grants read access toConfiguration Rules. |
Config Settings Write | Grants write access toConfiguration Rules. |
Custom Errors Read | Grants read access toCustom Error Rules. |
Custom Errors Write | Grants write access toCustom Error Rules. |
Custom Pages Read | Grants read access toCustom Error Pages. |
Custom Pages Write | Grants write access toCustom Error Pages. |
Email Security DMARC Reports Read | Grants read access toDMARC Management. |
Email Security DMARC Reports Write | Grants write access toDMARC Management. |
DNS Read | Grants read access toDNS. |
DNS Write | Grants write access toDNS. |
Email Routing Rules Read | Grants read access toEmail Routing Rules. |
Email Routing Rules Write | Grants write access toEmail Routing Rules. |
Firewall Services Read | Grants read access to Firewall resources. |
Firewall Services Write | Grants write access to Firewall resources. |
Health Checks Read | Grants read access toHealth Checks. |
Health Checks Write | Grants write access toHealth Checks. |
HTTP DDoS Managed Ruleset Read | Grants read access toHTTP DDoS managed ruleset. |
HTTP DDoS Managed Ruleset Write | Grants write access toHTTP DDoS managed ruleset. |
Load Balancers Read | Grants read access toload balancer resources. |
Load Balancers Write | Grants write access toload balancer resources. |
Logs Read | Grants read access to logs usingLogpull. |
Logs Write | Grants write access toLogpull and Logpush. |
Managed headers Read | Grants read access toManaged Headers. |
Managed headers Write | Grants write access toManaged Headers. |
Origin Read | Grants read access toOrigin Rules. |
Origin Write | Grants write access toOrigin Rules. |
Page Rules Read | Grants read access toPage Rules. |
Page Rules Write | Grants write access toPage Rules. |
Domain Page Shield Read | Grants read access toPage Shield. |
Domain Page Shield Write | Grants write access toPage Shield. |
Response Compression Read | Grants read access toResponse Compression. |
Response Compression Write | Grants write access toResponse Compression. |
Sanitize Read | Grants read access to sanitization. |
Sanitize Write | Grants write access to sanitization. |
Dynamic URL Redirects Read | Grants read access to zone-levelSingle Redirects. |
Dynamic URL Redirects Write | Grants write access to zone-levelSingle Redirects. |
SSL and Certificates Read | Grants read access toSSL configuration and certificate management. |
SSL and Certificates Write | Grants write access toSSL configuration and certificate management. |
Zone Transform Rules Read | Grants read access toTransform Rules. |
Zone Transform Rules Write | Grants write access toTransform Rules. |
Waiting Rooms Read | Grants read access toWaiting Room. |
Waiting Rooms Write | Grants write access toWaiting Room. |
Web3 Hostnames Read | Grants read access toWeb3 Hostnames. |
Web3 Hostnames Write | Grants write access toWeb3 Hostnames. |
Workers Routes Read | Grants read access toCloudflare Workers andWorkers KV Storage. |
Workers Routes Write | Grants write access toCloudflare Workers andWorkers KV Storage. |
Zaraz Read | Grants read access toZaraz zone level settings. |
Zaraz Write | Grants write access toZaraz zone level settings. |
Zone Read | Grants read access to zone management. |
Zone Write | Grants write access to zone management. |
Zone Settings Read | Grants read access to zone settings. |
Zone Settings Write | Grants write access to zone settings. |
Zone Versioning Read | Grants read access toZone Versioning at zone level. |
Zone Versioning Write | Grants write access toZone Versioning at zone level. |
Zone WAF Read | Grants read access toZone WAF. |
Zone WAF Write | Grants write access toZone WAF. |
- Resources
- API
- New to Cloudflare?
- Products
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- © 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark