Linking Cloudflare as a source

Let AI connect your sources for you

Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

Learn more
PostHog Wizard hedgehog

Contents

The Cloudflare connector syncs your Cloudflare configuration, security, and usage data into PostHog.

Beta release

The Cloudflare source is currently in beta. It syncs configuration data from Cloudflare's v4 REST API. High-volume analytics data from Cloudflare's GraphQL API is not yet supported.

Creating a Cloudflare API token

Before linking Cloudflare, create an API token with the required permissions:

  1. Go to the Cloudflare dashboard API tokens page.
  2. Click Create Token.
  3. Click Create Custom Token > Get started.
  4. Give your token a descriptive name (e.g. "PostHog Data Warehouse").
  5. Under Permissions, add the following with Read access:

ResourcePermissionDescription
Account SettingsReadRequired for accounts, billing, and audit data
ZoneReadRequired for zones and zone-scoped configuration
DNSReadRequired for dns_records and dns_analytics_report
Firewall ServicesReadRequired for firewall_rules, filters, rulesets, rate_limits, bot_management, page_shield tables
LogsReadRequired for audit_logs and logpush_jobs
Workers RoutesReadRequired for workers_routes and workers_scripts
Access: Apps and PoliciesReadRequired for access_apps, access_policies, access_groups, access_users

Grant only the permissions for the tables you want to sync. Zones and accounts the token can't access are skipped.

  1. Under Account Resources, select the accounts you want to sync.
  2. Under Zone Resources, select the zones you want to sync. Choose All zones to sync DNS records from every zone.
  3. Click Continue to summary, then Create Token.
  4. Copy the token – you won't be able to see it again.

Linking Cloudflare

  1. In PostHog, go to the Data pipeline page and select the Sources tab.
  2. Click New source and select Cloudflare by clicking Link.
  3. Paste your Cloudflare API token.
  4. Optional: Add a prefix to your table names.
  5. Click Next.
  6. Select the tables you want to import.
  7. Click Import.

PostHog validates your token against Cloudflare's /user/tokens/verify endpoint before starting the sync.

The data warehouse then starts syncing your Cloudflare data. You can see details and progress in the data pipeline sources tab.

Troubleshooting

If token validation fails when linking Cloudflare, you'll see one of the following messages:

  • "Couldn't reach Cloudflare to verify your API token. Please try again in a moment." – Cloudflare's API is unreachable due to a network error, timeout, rate limiting (429), or a server error (5xx). Your token may be fine – wait a moment and try again.

  • "Invalid Cloudflare API token. Please check the token has read permissions and hasn't been revoked." – Cloudflare rejected the token (401, 403, or the verification endpoint returned success: false). Verify your token has the required permissions and hasn't been revoked.

Available tables

TableDescription
accountsCloudflare accounts accessible by the API token
zonesZones (domains) managed in those accounts
dns_recordsDNS records for each zone, with a _zone_id field linking each record to its parent zone

DNS records are synced from every zone the token can access. Each DNS record row includes a _zone_id field so you can join it back to the zones table.

Sync modes

Most Cloudflare tables use full refresh syncing, re-importing all records on each sync.

The audit_logs table supports incremental syncing using the when timestamp field. On incremental syncs, only new audit events are fetched.

Configuration

OptionTypeRequired
API tokenpasswordYes

Supported tables

TableDescriptionSync methodIncremental fieldPrimary key
accounts

A Cloudflare account that the API token can access.

Full refresh
zones

A zone — a domain and its DNS/configuration managed in Cloudflare.

Full refresh
dns_records

A DNS record belonging to a zone (A, CNAME, MX, TXT, and so on).

Full refresh
firewall_rules

A legacy firewall rule that applies an action to requests matching a filter.

Full refresh
filters

A filter expression that firewall rules match requests against.

Full refresh
rulesets

A zone ruleset from the Ruleset Engine (WAF, transform, redirect, and other phases).

Full refresh
rate_limits

A rate limiting rule that mitigates traffic exceeding a threshold in a time period.

Full refresh
bot_management

The Bot Management configuration for a zone. One row per zone.

Full refresh
load_balancers

A zone load balancer, including its pools and steering configuration.

Full refresh
healthchecks

A standalone health check monitoring an origin server for a zone.

Full refresh
waiting_rooms

A waiting room that queues visitors for a host and path in a zone.

Full refresh
pagerules

A Page Rule that overrides settings or redirects requests matching a URL pattern.

Full refresh
snippets

A snippet, the JavaScript code Cloudflare runs at the edge for a zone.

Full refresh
spectrum_apps

A Spectrum application proxying a TCP or UDP port through Cloudflare.

Full refresh
workers_routes

A route mapping a URL pattern in a zone to the Worker script that handles it.

Full refresh
logpush_jobs

A Logpush job that ships a zone's logs to a destination.

Full refresh
custom_hostnames

A custom hostname (SSL for SaaS) pointing a third-party domain at a zone.

Full refresh
ssl_certificate_packs

A certificate pack Cloudflare orders and deploys for a zone's hostnames.

Full refresh
custom_certificates

A customer-uploaded SSL certificate installed on a zone.

Full refresh
page_shield_scripts

A JavaScript file Page Shield observed loading on a zone's pages.

Full refresh
page_shield_connections

An outbound connection Page Shield observed a zone's pages making.

Full refresh
api_gateway_operations

An API endpoint (method and path) API Shield tracks on a zone.

Full refresh
dns_analytics_report

Authoritative DNS query counts for a zone, grouped by query type and response code.

Full refresh
audit_logs

An audit log entry recording a change made in a Cloudflare account.

Incremental, Full refreshwhen
billing_usage

Billable product usage for an account, one row per time period.

Full refresh
billable_usage

A billable usage and cost record for an account, in the FOCUS billing format.

Full refresh
access_apps

A Zero Trust Access application protecting a domain or resource.

Full refresh
access_policies

A reusable Zero Trust Access policy deciding who can reach an application.

Full refresh
access_groups

A Zero Trust Access group, a reusable set of rules matching users.

Full refresh
access_users

A user seen by Zero Trust in an account, with their seat and device counts.

Full refresh
workers_scripts

A Worker script deployed in an account.

Full refresh
r2_buckets

An R2 object storage bucket in an account.

Full refresh
kv_namespaces

A Workers KV namespace in an account.

Full refresh
d1_databases

A D1 SQL database in an account.

Full refresh
stream_usage

Stream billable minutes viewed for an account, one row per time period.

Full refresh
security_center_insights

A Security Center insight, a security issue Cloudflare found in an account.

Full refresh

Community questions

Was this page useful?