Connect Cloudflare when you want Cedros to create and maintain DNS records for your site using a scoped API token. Your domain must already be active in Cloudflare, and you must be ready for Cedros to apply the website and available mail records.
If you only want to point a website address at Cedros while keeping manual control of DNS, use Connecting a domain you already own.
Before you connect
You need access to Settings → Site → Domains in the correct Cedros site, plus permission to create a token for the domain's Cloudflare account. Cloudflare requires API Token Provisioning capabilities or Super Administrator status to create account tokens; the token cannot grant permissions its creator does not have. See Cloudflare's Account API token guide.
Confirm these details first:
- The domain is in the intended Cloudflare account and its zone status is Active.
- The website destination is correct. If Cedros shows Server target, use the public IP or routing hostname supplied by your host.
- You have a copy of the existing DNS records, including website, email, and verification records.
- Your Cedros mail setup matches the email services you intend to use.
Connecting Cloudflare is a live configuration action. It can change where website traffic goes. Keep the previous website available while you test the connection.
If Cloudflare is not your DNS provider yet
Adding a domain to a Cloudflare account is not enough to make it active. For a normal full setup, follow Cloudflare's nameserver setup guide: review the imported records, preserve the records for services you use, and update the nameservers at your registrar.
Follow that guide's DNSSEC migration steps too; old DNSSEC information can cause resolution failures after a nameserver change. Wait until Cloudflare reports the zone as active before connecting it in Cedros.
You can keep the domain registered with its current registrar. Moving DNS to Cloudflare and transferring domain registration are separate actions.
Understand what Cedros will manage
Cedros uses the token for more than checking that you own a domain:
- Website DNS: It creates or updates the website record for the selected domain. The automatic Domain-card setup uses Cloudflare's proxy for that record.
- Mail DNS: It applies available records from Cedros Native Mail and the configured outbound email provider. Mail records are kept DNS-only.
- Public-page caching: It configures Cedros's public HTML cache rule. This is why the token instructions include Cache Settings access.
- Optional improvements: With the optional permissions below, it can enable HTTP/2 to the origin and visitor-location headers for analytics.
A website update can replace an existing record. Mail automation has conflict checks, but those checks are not a substitute for reviewing your mail setup. If your domain uses Google Workspace, Microsoft 365, or another mail service, keep its working records and resolve any conflicting Cedros mail configuration before running automation.
There is no website-only checkbox in the Cloudflare connection form. If you are not ready to apply the available mail records, use the manual DNS path for the website and finish planning your mail setup separately.
Create the Cloudflare API token
Use an Account API token, following the instructions shown inside Cedros. A Global API Key or a token from another DNS provider is not the credential this form expects.
- Sign in to the Cloudflare account that contains the domain. Open Manage account → Account API tokens, then select Create Token.
- Give it a recognizable name, such as Cedros — example.com.
- Under Permission policies, choose Start from scratch. Set the scope to Specified Domains and select the Cloudflare zone that contains your website address.
- Add the permissions below. Keep the policy restricted to that zone; you do not need an account-wide policy for this setup.
- Choose an expiration that fits your rotation schedule, or No expiration if that is your policy. Cedros continues to use the token for later updates. Leave Client IP address filtering empty unless your administrator has confirmed the Cedros server’s outgoing IP addresses. Do not enter your laptop’s IP; Cloudflare receives these requests from Cedros.
- Review the policy using Review token or Continue to summary, then select Create Token. Copy the secret when Cloudflare displays it and keep it in your approved secret store until setup is complete.
For www.example.com, the zone is normally example.com. Choose the actual zone containing the hostname, not an unrelated domain in the same account. If your organization uses a separately delegated subdomain zone, ask its DNS administrator which zone to select.
Token permissions
In the Cedros instructions, selecting Edit also selects Read. The permission names may be shown with Write in Cloudflare's API reference.
| Permission | Access and purpose |
|---|---|
| Zone under DNS & Zones | Read — required. Lets Cedros find the domain's active zone. |
| DNS under DNS & Zones | Edit — required. Lets Cedros read and update DNS records. |
| Cache Settings under Cache & Performance | Edit — required for Cedros's cache setup. Lets Cedros manage the public-page cache rule. |
| Zone Settings under DNS & Zones | Edit — optional. Allows the HTTP/2-to-origin improvement. |
| Managed headers under Rules & Configuration | Edit — optional. Allows visitor-location headers used for analytics. |
Leave unrelated permissions unchecked. Cache Settings is the permission for Cache Rules; do not substitute Cache Purge. Cloudflare documents these as separate capabilities in its API token permissions reference.
If your organization requires IP restrictions, have its administrator confirm the Cedros server's outbound addresses before applying them. An expired token or a restriction that excludes the server will prevent later updates.
Connect the token in Cedros
Open Settings → Site → Domains. Follow the path matching your screen.
When you see Domain name and Server target
- Confirm Domain name and Server target. These site settings save automatically, so do not edit them just to test the form.
- Expand Set up automatically with Cloudflare. If a connection already exists, expand Cloudflare DNS instead.
- Paste the token into Cloudflare API token. Paste only the secret, without a command, surrounding quotes, or line breaks.
- Select Connect Cloudflare. If already configured, the button is Update Cloudflare DNS.
- Wait for the result and read the entire message, including any mail warning. Confirm that the connection shows the expected zone.
Cedros discovers the zone through Cloudflare; this form does not require you to enter a zone ID.
When you see Managed by Cedros Domains
For a domain you are adding, select Add domain → Connect a domain I own. Enter the existing domain, expand Automate DNS with Cloudflare, paste the Cloudflare API token, and select Connect domain.
For a domain already showing a Cloudflare DNS control in Your domains, open that control. Enter a replacement token and select Replace token and update DNS, or leave it blank and select Retry saved token and update DNS.
If an existing manually connected domain has no Cloudflare control, do not detach it just to make a button appear. Ask the site administrator or support to confirm the supported connection path for that domain.
Confirm the result
A Configured badge means Cedros has a saved connection for the domain. It does not prove that the token is still valid or that every DNS, cache, email, and HTTPS operation succeeded.
After connecting:
- Read the action result. If it reports a partial failure, follow the relevant recovery steps below before treating the setup as complete.
- In Cloudflare, inspect the website record's name and destination. Check any mail records that were applied, including their DNS-only status.
- In Cedros, use Check website DNS under Manual DNS instructions, or Test DNS / Check setup in the managed-domain flow.
- Open the exact website address over HTTPS in a private browser window. Confirm that the intended site and important published pages load without certificate warnings.
- Test sending and receiving with the domain's existing email service if mail is in use.
A proxied website record returns Cloudflare addresses in public DNS, so a public IP lookup need not equal the origin IP in Server target. Check the configured destination in Cloudflare rather than changing a correct record to match the public answer. See Cloudflare's proxy-status explanation.
Website DNS verification does not establish email delivery or HTTPS readiness. For an independently hosted site, the host still needs to configure the origin server and certificate for the chosen hostname. Do not bypass a certificate warning or weaken encryption settings to make the page load.
Reuse or replace a saved token
Cedros does not display saved token secrets. A blank token field on a configured connection is expected.
To retry with the saved token, leave the field blank and use Update Cloudflare DNS on the Domain card, or Retry saved token and update DNS on the managed-domain control. These actions can write DNS again; they are not read-only connection tests.
To rotate a token, create a replacement with the same intended zone and permissions, enter it in the appropriate connection form, and run the update. Check the result and the affected records before revoking the old token in Cloudflare. Confirm that the old token is not used by another integration first.
If a token was exposed, have the Cloudflare account administrator revoke it promptly and replace it in Cedros. Do not include token secrets in screenshots, support messages, or shared documents.
Revoking a token removes its ability to make future changes. It does not undo records already written. If you want to stop automation or move DNS elsewhere, plan the existing records and ongoing mail updates with your administrator rather than treating token revocation as a rollback.
If setup does not complete
The connection button is unavailable
On the Domain card, confirm that the domain is a valid public hostname, Server target is valid, and you have settings-write access. A first connection needs a token; a configured connection can reuse its saved token. Wait for any connection check or update already in progress.
If the page reports an access problem while applying mail records, ask an administrator with the relevant email-provider permissions to complete the setup. See Why can’t I see or edit a feature?.
The token is rejected or the zone cannot be found
Check the Cloudflare account, token expiration, selected zone, and Zone Read permission. Confirm the zone is active and any nameserver change has completed. A token can be valid but unable to see the intended zone.
For a malformed-token message, copy the secret again without line breaks or extra text. Do not paste a Global API Key. If the saved zone does not contain the hostname, check that you are editing the correct domain and ask support for help if reconnecting still reports a mismatch.
DNS or cache changes are rejected
Check DNS Edit for record updates and Cache Settings Edit for the cache rule. Do not grant all permissions as a shortcut.
A website record can succeed while another part of setup needs attention. A DNS success message is not independent proof that caching is configured. Review the reported failure and existing records before retrying; some changes may already be saved.
If Cedros cannot read the saved connection, use Retry connection check when offered. This refreshes status. Update Cloudflare DNS performs an update and has different effects.
The website connected, but mail is pending
Read the reason in the message. Mail may still need a Native Mail domain, an outbound provider, provider-generated values, or resolution of conflicting records.
If the Domain-card result says the remaining mail DNS will be retried automatically, complete the named mail setup and follow that message; you do not need to repeatedly submit the token form. In the managed-domain flow, follow its instructions to finish mail setup and retry the saved Cloudflare connection.
Keep current working mail records until the replacement service is ready and verified. Do not add a second SPF policy or remove another provider's records merely to clear an error. Have the mail administrator resolve the intended configuration.
Cloudflare is unreachable or an update only partly finished
Record the exact message and check the current DNS state before retrying. A failed overall request does not mean every earlier change was rolled back. Once the provider issue is resolved, retry the intended update using the saved token where available.
If the problem persists, send support the domain, site address, expected Cloudflare zone, exact error, time of the attempt, and whether the website or mail is affected. Include the permission names and whether the token is active, but never the token itself. Use Getting help and reporting a problem.