Create an API token
If you plan to use the Cloudflare API to manage your account programmatically, you need an API token (or API key) to authenticate your requests.
The benefit of an API token - as opposed to an API key - is that you can limit tokens to specific permissions, zones, IP addresses, and a specific validity period.
-
Determine if you want a user token or an Account Owned Token. Use Account Owned Tokens if you prefer service tokens that are not associated with users and your desired API endpoints are compatible.
-
From the Cloudflare dashboard ↗, go to My Profile > API Tokens for user tokens. For Account Tokens, go to Manage Account > API Tokens.
-
Select Create Token.
-
Select a template from the available API token templates or create a custom token. The following example uses the Edit zone DNS template.
-
Add or edit the token name to describe why or how the token is used. Templates are prefilled with a token name and permissions.
-
Modify the token’s permissions. After selecting a permissions group (Account, User, or Zone), choose what level of access to grant the token. Most groups offer
Edit
orRead
options.Edit
is full CRUDL (create, read, update, delete, list) access, whileRead
is the read permission and list where appropriate. Refer to the available token permissions for more information. -
Select which resources the token is authorized to access. For example, granting
Zone DNS Read
access to a zoneexample.com
will allow the token to read DNS records only for that specific zone. Any other zone will return an error for DNS record reads operations. Any other operation on that zone will also return an error. -
(Optional) Restrict how a token is used in the Client IP Address Filtering and TTL (time to live) fields.
-
Select Continue to summary.
-
Review the token summary. Select Edit token to make adjustments. You can also edit a token after creation.
-
Select Create Token to generate the token’s secret.
-
Copy the secret to a secure place.
The token secret page also includes an example command to test the token. Use the /user/tokens/verify
endpoint to fetch the current status of the given token.
The result:
With this you have successfully created an API token and can start working with the Cloudflare API. After creating your first API token, you can create additional API tokens via the API.