Cloudflare Docs
Api
Visit API on GitHub
Set theme to dark (⇧+D)

API token permissions

Below is a list of the available token permissions.

To obtain an updated list of token permissions, including the permission ID and the scope of each permission, use the List permission groups API method.

​​ User permissions

The applicable scope of user permissions is com.cloudflare.api.user.

NameDescription
API Tokens ReadGrants read access to user’s API Tokens.
API Tokens WriteGrants write access to user’s API Tokens.
Memberships ReadGrants read access to a user’s account memberships.
Memberships WriteGrants write access to a user’s account memberships.
User Details ReadGrants read access to user details.
User Details WriteGrants write access to user details.

​​ Account permissions

The applicable scope of account permissions is com.cloudflare.api.account.

NameDescription
Access: Apps and Policies ReadGrants read access to Cloudflare Access account resources.
Access: Apps and Policies RevokeGrants ability to revoke all tokens to Cloudflare Access account resources.
Access: Apps and Policies WriteGrants write access to Cloudflare Access account resources.
Access: Audit Logs ReadGrants read access to Cloudflare Access audit logs.
Access: Certificates ReadGrants read access to Cloudflare Access mTLS certificates.
Access: Certificates WriteGrants write access to Cloudflare Access mTLS certificates.
Access: Device Posture ReadGrants read access to Cloudflare Access Device Posture.
Access: Device Posture WriteGrants write access to Cloudflare Access Device Posture.
Access: Organizations, Identity Providers, and Groups ReadGrants read access to Cloudflare Access account resources.
Access: Organizations, Identity Providers, and Groups RevokeGrants ability to revoke user sessions to Cloudflare Access account resources.
Access: Organizations, Identity Providers, and Groups WriteGrants write access to Cloudflare Access account resources.
Access: Service Tokens ReadGrants read access to Cloudflare Access Service Tokens.
Access: Service Tokens WriteGrants write access to Cloudflare Access Service Tokens.
Account Analytics ReadGrants read access to analytics.
Account Firewall Access Rules ReadGrants read access to account firewall access rules.
Account Firewall Access Rules WriteGrants write access to account firewall access rules.
Account Rule Lists ReadGrants read access to Rule Lists.
Account Rule Lists WriteGrants write access to Rule Lists.
Account Rulesets ReadGrants read access to Account Rulesets.
Account Rulesets WriteGrants write access to Account Rulesets.
Account Settings ReadGrants read access to Account resources, account membership, and account level features.
Account Settings WriteGrants write access to Account resources, account membership, and account level features.
Account WAF ReadGrants read access to Account WAF.
Account WAF WriteGrants write access to Account WAF.
Cloudflare Tunnel ReadGrants access to view Cloudflare Tunnels.
Cloudflare Tunnel WriteGrants access to create and delete Cloudflare Tunnels.
Billing ReadGrants read access to billing profile, subscriptions, and access to fetch invoices and entitlements.
Billing WriteGrants write access to billing profile, subscriptions, and access to fetch invoices and entitlements.
DDoS Protection ReadGrants read access to DDoS protection.
DDoS Protection WriteGrants write access to DDoS protection.
DNS Firewall ReadGrants read access to DNS Firewall.
DNS Firewall WriteGrants write access to DNS Firewall.
IP Prefixes: BGP On Demand ReadGrants access to read IP prefix BGP configuration.
IP Prefixes: BGP On Demand WriteGrants access to read and change IP prefix BGP configuration.
IP Prefixes: ReadGrants access to read IP prefix settings.
IP Prefixes: WriteGrants access to read/write IP prefix settings.
Images ReadGrants read access to Images.
Images WriteGrants write access to upload Images.
L4 DDoS Managed Ruleset ReadGrants read access to L4 DDoS Managed Ruleset.
L4 DDoS Managed Ruleset WriteGrants write access to L4 DDoS Managed Ruleset.
Load Balancing: Monitors and Pools ReadGrants read access to account level load balancer resources.
Load Balancing: Monitors and Pools WriteGrants write access to account level load balancer resources.
Logs ReadGrants read access to logs using Logpull or Instant Logs.
Logs WriteGrants read and write access to Logpull, Logpush and read access to Instant Logs.
Magic Firewall Packet Captures - Read PCAPs APIGrants read access to Packet Captures.
Magic Firewall Packet Captures - Write PCAPs APIGrants write access to Packet Captures.
Magic Firewall ReadGrants read access to Magic Firewall.
Magic Firewall WriteGrants write access to Magic Firewall.
Magic Transit Prefix ReadGrants read access to manage a user’s Magic Transit prefixes.
Magic Transit Prefix WriteGrants write access to manage a user’s Magic Transit prefixes.
Bulk URL Redirects ReadGrants read access to Bulk URL Redirects.
Bulk URL Redirects WriteGrants write access to Bulk URL Redirects.
Rule Policies ReadGrants read access to Rule Policies.
Rule Policies WriteGrants write access to Rule Policies.
Stream ReadGrants read access to Cloudflare Stream.
Stream WriteGrants write access to Cloudflare Stream.
Teams ReadGrants read access to teams.
Teams ReportGrants reporting access to teams.
Teams WriteGrants write access to teams.
Transform Rules ReadGrants read access to Transform Rules.
Transform Rules WriteGrants write access to Transform Rules.
Workers KV Storage ReadGrants read access to Cloudflare Workers KV Storage.
Workers KV Storage WriteGrants write access to Cloudflare Workers KV Storage.
Workers R2 Storage ReadGrants read access to Cloudflare R2 Storage.
Workers R2 Storage WriteGrants write access to Cloudflare R2 Storage.
Workers Scripts ReadGrants read access to Cloudflare Workers scripts.
Workers Scripts WriteGrants write access to Cloudflare Workers scripts.
Workers Tail ReadGrants wrangler tail read permissions.

​​ Zone permissions

The applicable scope of zone permissions is com.cloudflare.api.account.zone.

NameDescription
Access: Apps and Policies ReadGrants read access to Cloudflare Access zone resources.
Access: Apps and Policies RevokeGrants ability to revoke all tokens to Cloudflare Access zone resources.
Access: Apps and Policies WriteGrants write access to Cloudflare Access zone resources.
Analytics ReadGrants read access to analytics.
Apps WriteGrants full access to Cloudflare Apps.
Bot Management ReadGrants read access to Bot Management.
Bot Management WriteGrants write access to Bot Management.
Cache PurgeGrants access to purge cache.
DNS ReadGrants read access to DNS.
DNS WriteGrants write access to DNS.
Firewall Services ReadGrants read access to Firewall resources.
Firewall Services WriteGrants write access to Firewall resources.
HTTP DDoS Managed Ruleset ReadGrants read access to HTTP DDoS Managed Ruleset.
HTTP DDoS Managed Ruleset WriteGrants write access to HTTP DDoS Managed Ruleset.
Health Checks ReadGrants read access to Health Checks.
Health Checks WriteGrants write access to Health Checks.
Load Balancers ReadGrants read access to load balancers and associated resources.
Load Balancers WriteGrants write access to load balancers and associated resources.
Logs ReadGrants read access to logs and Logpush jobs.
Logs WriteGrants write access to Logpush jobs.
Origin ReadGrants read access to Origin Rules.
Origin WriteGrants write access to Origin Rules.
Page Rules ReadGrants read access to Page Rules.
Page Rules WriteGrants write access to Page Rules.
SSL and Certificates ReadGrants read access to SSL configuration and certificate management.
SSL and Certificates WriteGrants write access to SSL configuration and certificate management.
Sanitize ReadGrants read access to sanitization.
Sanitize WriteGrants write access to sanitization.
Waiting Rooms ReadGrants read access to Waiting Rooms.
Waiting Rooms WriteGrants write access to Waiting Rooms.
Web3 Hostnames ReadGrants read access to Web3 Hostnames.
Web3 Hostnames WriteGrants write access to Web3 Hostnames.
Workers Routes ReadGrants read access to Cloudflare Workers and Workers KV Storage.
Workers Routes WriteGrants write access to Cloudflare Workers and Workers KV Storage.
Zone ReadGrants read access to zone management.
Zone Settings ReadGrants read access to zone settings.
Zone Settings WriteGrants write access to zone settings.
Zone Transform Rules ReadGrants read access to Transform Rules at zone level.
Zone Transform Rules WriteGrants write access to Transform Rules at zone level.
Zone WAF ReadGrants read access to Zone WAF.
Zone WAF WriteGrants write access to Zone WAF.
Zone WriteGrants write access to zone management.