Skip to main content

Connecting Vanta & Cloudflare

The read-only Cloudflare integration fetches your cloud and security resources directly to Vanta, allowing you to quickly demonstrate that your company's networks are secure and monitored.

To find the Cloudflare integration in Vanta:

  • To connect, go to the Integrations page and search for Cloudflare. For help navigating the Integrations page, see Integrations Page.

  • Choose Cloudflare if your organization uses a standard, commercial Cloudflare account, as opposed to Cloudflare for Government.

  • Click Connect.

Prerequisites

  • Permissions to create API tokens in Cloudflare

  • Admin permissions in Vanta

  • Vanta currently supports user‑owned API tokens only

Procedure

  • From your Cloudflare dashboard, navigate to "My Profile" by clicking on the user icon on the top right of the page.

Screenshot_2023-05-03_at_5.18.46_pm.png
  • Click on API tokens from the left hand menu, then click on Create Token.

Screenshot_2023-05-03_at_5.20.45_pm.png
  • Click on 'Use template' next to the Read all resource's option.

    Screenshot_2023-05-03_at_5.23.32_pm.png

  • Edit the Token Name field to something easy to identify, for example, 'VantaToken'.

Screenshot_2023-05-03_at_5.26.12_pm.png
  • Scroll down to the Permissions list and leave all the default permissions as they are. Changing any of these permissions may result in the connection failing.

  • Scroll down to the Account Resources and Zone Resources sections, below the permissions list.

    • If your Cloudflare login only has access to a single account, you can leave these on their default settings.

    • If your Cloudflare login has access to multiple accounts, do not leave these set to All accounts because this can cause the connection to fail with 403 errors on specific endpoints, even when the token's permissions are otherwise correct.

      • Under Account Resources, select Include > [your specific Cloudflare account]. To connect more than one account, add an additional Account Resources row for each account.

      • Under Zone Resources, select Include > All zones from an account > [the same account], repeating for each account added above.

    • If you're connecting multiple accounts this way, you'll choose which of them to sync from Vanta's account/zone selection during setup.
      ​​

  • Click on Continue to summary. You should be shown the API token name, and a summary of all the permission.

    Screenshot_2023-05-03_at_5.27.24_pm.png

  • Click on Create Token. Once the token is generated, please ensure to copy the token before navigating away from the page, as there will be no way to retrieve this once you exit the page.​

Screenshot_2023-05-03_at_5.27.56_pm.png
  • Navigate back to Vanta, and on the Cloudflare connection page, click 'Save API Token details'. Enter the API Token Name and paste the copied API Token.

    Screenshot_2023-03-31_at_4.47.12_pm.png

  • Click Done. Cloudflare should now be connected!

Troubleshooting

If you receive a 403 Unauthorized error on specific resources (for example, SSL/TLS settings) even though your token uses the "Read all resources" template and its permissions look correct, check whether your Cloudflare login has access to multiple accounts. If so, the token's Account Resources and Zone Resources need to be explicitly scoped to the specific account you're connecting — see the steps above.

Vanta supports both commercial Cloudflare and Cloudflare for Government.

  • Choose Cloudflare if your organization uses a standard, commercial Cloudflare account.

  • Choose Cloudflare for Government if your organization uses Cloudflare for government. Please follow this article for help connecting the commercial Cloudflare integration.

  • Vanta behaves the same for both, but they connect to different tenancies. Your API token, log destination, and admin/onboarding live in the same tenancy, so using the wrong tile will cause the connection or log collection to fail.
    ​​