Poliogo

Connect Cloudflare

Mint a read-only API token yourself and paste it. Cloudflare publishes no third-party OAuth app, so you set the scope.

How it connects
A scoped read-only API token you create
Setup time
Two or three minutes
Access
Read-only, two permissions

How the connection works

  1. Mint a tokenTwo Read permissions, created by you in Cloudflare's own dashboard.
  2. Paste and selectYour Pages projects are listed for you once the token is in.
  3. Detection stays onEach scan re-reads the project and its variable names.

What it looks like once connected

An illustration of this connection inside your Poliogo dashboard — not live data.

Live sync activeExample
acme-web · pages.dev

Detected in this project

  • STRIPE_SECRET_KEYname only — value never read
  • POSTHOG_API_KEYname only — value never read
  • SUPABASE_URLname only — value never read
  • OPENAI_API_KEYname only — value never read
Last scan: 14 minutes ago3 documents up to date
Variable names only. Poliogo never requests a value, and no table in the database has a column to keep one in.

Exact permissions requested

Every permission this connection asks for, named as Cloudflare names it on its own consent screen — so you can compare this table to what you are shown.

PermissionGrantWhat it is used for
Account → Cloudflare Pages → ReadReadList your Pages projects and their addresses.
Account → Account Settings → ReadReadRead the account name the token is scoped to, so the right one is shown.
Everything elseNot requestedA token with only those two permissions cannot change anything in your account. You mint it, and you can revoke it.

Setting it up

What you do, and what you will be looking at while you do it.

  1. Open your Cloudflare API tokens page

    In the Cloudflare dashboard go to My Profile → API Tokens, then Create Token → Create Custom Token.

  2. Give it exactly two Read permissions

    Account → Cloudflare Pages → Read, and Account → Account Settings → Read. Nothing else. A token holding only those two cannot change, deploy or delete anything in your account — which is why this connector asks you to mint it rather than handing us an OAuth grant.

  3. Scope it to one account if you like

    Under Account Resources you can narrow the token to a single account. Poliogo reads the account name only, to show you which one the token belongs to.

  4. Copy it once and paste it into Poliogo

    Cloudflare shows the token exactly once. Paste it during setup; it is stored encrypted and used only to list your Pages projects. If you ever lose track of it, roll it in Cloudflare and paste the new one.

  5. Pick a Pages project and generate

    Your Pages projects and their addresses are listed for you. Review the detected services and generate.

Poliogo · New projectExample

Choose how to scan your app

Pick one. We scan your code and settings to find the services your app uses — the scan keeps that list, not your files.

Hosting PlatformVercel, Netlify, Railway — connect your account. Cloudflare — paste a read-only token.Choose another way
VercelNetlifyRailwayCloudflare

Paste a read-only Cloudflare API token and pick a Pages project — nothing else to type.

Paste a read-only Cloudflare API token

In Cloudflare: My Profile → API Tokens → Create Token → Custom token.

Account → Cloudflare Pages → ReadRead
Account → Account Settings → ReadRead
Everything elseNot requested
Connect CloudflareToken valid · read-only, and revocable by you at any time

Pick a Pages project

acme-webacme-web.pages.dev
acme-webacme-web.pages.devacme-web-stagingacme-web-staging.pages.devacme-docsacme-docs.pages.dev

Environment variables detected

STRIPE_SECRET_KEYStripe
POSTHOG_API_KEYPostHog
SUPABASE_URLSupabase

Names only. No value is requested, and no table in the database has a column to keep one in.

Read my project
Tell us what you use instead
The Poliogo setup screen for Cloudflare, drawn from the same catalogue the app reads. An illustration — not live data, and nothing here is clickable.

What Poliogo detects from Cloudflare

The right-hand column is the part worth reading: it is what this connection cannot reach even if we wanted it to.

What it reads

  • Your project or site list, so you can pick the right one instead of typing an address.
  • The production URL, which is what your policies name as the service they cover.
  • Environment variable names — enough to prove which services you use.

What it never reads

  • Environment variable values. They are never requested and never stored.
  • Anything the two Read permissions do not cover — the token cannot write, deploy or delete.
  • Your source code — connect the repository Cloudflare Pages builds from for that.

Ready to connect Cloudflare?

The free plan covers one project with no credit card. You approve everything before a single document is written.

Poliogo is a compliance management platform, not a law firm. What it produces is not legal advice. See exactly what each connection reads.