Your token is held in your browser only and used to talk to Cloudflare directly for this session. It is never stored on our servers and never logged. The connection auto-expires after 4 hours.
Add these two permissions:
• Zone → Zone WAF → Edit • Zone → Zone → Read
Under Zone Resources, choose specific zones or "All zones" to harden everything at once.
Create the token, copy it, and paste it below.
This token can only read your zone list and edit WAF custom rules, nothing else. After you're done you can delete the token from your Cloudflare Dashboard: dash.cloudflare.com/profile/api-tokens
Connected
2 Configure & deploy
0 selected
No zones loaded.
Space-separated 2-letter ISO codes, e.g. US CA GB. Find your country codes here. Visitors from outside these countries get a managed challenge. Getting this wrong challenges your real visitors.
Added to the Allow rule so wp-cron isn't blocked. IPv4 and/or IPv6, space-separated.
The standard Good Bots rule is always deployed. Check this to add extra services on top of it.
This is a beta feature. Enter the access code to use it.
These conditions are appended to your standard Good Bots rule with or. The base rule is always included.
Use this only if you need a completely different Rule 1. Overrides the standard Good Bots rule and any extra services above.
Paste a complete Cloudflare expression. This fully replaces Rule 1 — the standard Good Bots rule will not be included.
Cloudflare's free plan allows 5 custom rules. Enabling this combines the VPN/hosting/path rules into one (4 rules total) so your 5th slot is free for Cloudflare's native AI Crawl Control feature (Security → Bots).