Skip to content

Getting Started

Cloudflare Manager uses a Cloudflare API Token to manage domains, DNS records, SSL/TLS settings, cache policies, and site activity data on mobile.

1. Create an API Token

Create a dedicated Cloudflare API Token for mobile management, and grant only the minimum permissions required for the domains you want to manage.

Go to https://dash.cloudflare.com/profile/api-tokens to create your token.

Recommended capability scope:

Permissions

TypePermissionAccess
AccountWorkers R2 SQLRead
AccountWorkers R2 Data CatalogEdit
AccountWorkers R2 StorageEdit
AccountAccount AnalyticsRead
AccountAccount SettingsRead
UserMembershipRead
UserUser DetailsRead
ZoneZoneEdit
ZoneDNSEdit
ZoneAnalyticsRead
ZoneZone SettingsEdit
ZoneSSL and CertificatesRead

SSL/TLS page permission details:

FeatureRequired permissionNotes
SSL/TLS encryption modeZone Settings · EditView and update ssl (Off / Flexible / Full / Full strict)
Minimum TLS versionZone Settings · EditView and update min_tls_version
Always Use HTTPSZone Settings · EditView and update always_use_https
Automatic HTTPS RewritesZone Settings · EditView and update automatic_https_rewrites
TLS 1.3Zone Settings · EditView and update tls_1_3
Opportunistic EncryptionZone Settings · EditView and update opportunistic_encryption
HTTP Strict Transport Security (HSTS)Zone Settings · EditView and update security_header (status, max age, include subdomains, preload, no-sniff header)
Certificate packsSSL and Certificates · ReadView Universal / Advanced / Custom certificate packs

If a permission is missing, that feature is grayed out with “No permission” and does not block other authorized features.

Account resources

IncludeAll accounts

Zone resources

IncludeAll zones

Client IP address filtering (optional)

Restrict the token to your own IP address if needed.

Done

Copy the token you receive and paste it into the app on your phone.