Connect Cloudflare
Mint a read-only API token yourself and paste it. Cloudflare publishes no third-party OAuth app, so you set the scope.
How the connection works
- Mint a tokenTwo Read permissions, created by you in Cloudflare's own dashboard.
- Paste and selectYour Pages projects are listed for you once the token is in.
- Detection stays onEach scan re-reads the project and its variable names.
What it looks like once connected
An illustration of this connection inside your Poliogo dashboard — not live data.
Detected in this project
- STRIPE_SECRET_KEYname only — value never read
- POSTHOG_API_KEYname only — value never read
- SUPABASE_URLname only — value never read
- OPENAI_API_KEYname only — value never read
Exact permissions requested
Every permission this connection asks for, named as Cloudflare names it on its own consent screen — so you can compare this table to what you are shown.
| Permission | Grant | What it is used for |
|---|---|---|
| Account → Cloudflare Pages → Read | Read | List your Pages projects and their addresses. |
| Account → Account Settings → Read | Read | Read the account name the token is scoped to, so the right one is shown. |
| Everything else | Not requested | A token with only those two permissions cannot change anything in your account. You mint it, and you can revoke it. |
Setting it up
What you do, and what you will be looking at while you do it.
Open your Cloudflare API tokens page
In the Cloudflare dashboard go to My Profile → API Tokens, then Create Token → Create Custom Token.
Give it exactly two Read permissions
Account → Cloudflare Pages → Read, and Account → Account Settings → Read. Nothing else. A token holding only those two cannot change, deploy or delete anything in your account — which is why this connector asks you to mint it rather than handing us an OAuth grant.
Scope it to one account if you like
Under Account Resources you can narrow the token to a single account. Poliogo reads the account name only, to show you which one the token belongs to.
Copy it once and paste it into Poliogo
Cloudflare shows the token exactly once. Paste it during setup; it is stored encrypted and used only to list your Pages projects. If you ever lose track of it, roll it in Cloudflare and paste the new one.
Pick a Pages project and generate
Your Pages projects and their addresses are listed for you. Review the detected services and generate.
Choose how to scan your app
Pick one. We scan your code and settings to find the services your app uses — the scan keeps that list, not your files.
Paste a read-only Cloudflare API token and pick a Pages project — nothing else to type.
Paste a read-only Cloudflare API token
In Cloudflare: My Profile → API Tokens → Create Token → Custom token.
Pick a Pages project
Environment variables detected
STRIPE_SECRET_KEYStripePOSTHOG_API_KEYPostHogSUPABASE_URLSupabaseNames only. No value is requested, and no table in the database has a column to keep one in.
Read my projectWhat Poliogo detects from Cloudflare
The right-hand column is the part worth reading: it is what this connection cannot reach even if we wanted it to.
What it reads
- Your project or site list, so you can pick the right one instead of typing an address.
- The production URL, which is what your policies name as the service they cover.
- Environment variable names — enough to prove which services you use.
What it never reads
- Environment variable values. They are never requested and never stored.
- Anything the two Read permissions do not cover — the token cannot write, deploy or delete.
- Your source code — connect the repository Cloudflare Pages builds from for that.
Ready to connect Cloudflare?
The free plan covers one project with no credit card. You approve everything before a single document is written.
Poliogo is a compliance management platform, not a law firm. What it produces is not legal advice. See exactly what each connection reads.