[metadata]
algolia_content_type: How to
algolia_product_filter: Cloudflare Fundamentals
description: Learn how to create a token to perform actions using the Cloudflare API.
generator: Astro v7.1.4
generator: Nimbus v0.2.2
image: https://developers.cloudflare.com/og-docs.png
og:description: Learn how to create a token to perform actions using the Cloudflare API.
og:image: https://developers.cloudflare.com/og-docs.png
og:locale: en
og:site_name: Cloudflare Docs
og:title: Create API token
og:title: Create API token · Cloudflare Fundamentals docs
og:type: article
og:url: https://developers.cloudflare.com/fundamentals/api/get-started/create-token/
pcx_additional_products: Cloudflare Fundamentals,API documentation
pcx_content_group: Core platform
pcx_content_type: How to
pcx_last_modified: 109
pcx_product: Cloudflare Fundamentals
twitter:card: summary_large_image
twitter:image: https://developers.cloudflare.com/og-docs.png
twitter:site: @cloudflare
viewport: width=device-width, initial-scale=1

[canonical-links]
https://developers.cloudflare.com/fundamentals/api/get-started/create-token/

[document-links]
/
/cdn-cgi/ endpoint: /fundamentals/reference/cdn-cgi-endpoint/
AI Security: https://www.cloudflare.com/solutions/ai-security/
API deprecations: /fundamentals/api/reference/deprecations/
API token permissions: /fundamentals/api/reference/permissions/
API token template URLs: /fundamentals/api/how-to/account-owned-token-template/
API token templates: /fundamentals/api/reference/template/
API: /api/
About: https://www.cloudflare.com/about/
Account API token: /fundamentals/api/get-started/account-owned-tokens/
Account API tokens: /fundamentals/api/get-started/account-owned-tokens/
Account and domain management best practices: /fundamentals/reference/best-practices/
Account recovery: /fundamentals/user-profiles/account-recovery/
Accounts, zones, and profiles: /fundamentals/concepts/accounts-and-zones/
Add abuse contact: /fundamentals/account/account-security/abuse-contact/
Add multiple sites via automation: /fundamentals/manage-domains/add-multiple-sites-automation/
Agent setup ↗: /agent-setup/
Agent setup: /agent-setup/
Allow Cloudflare access: /fundamentals/account/account-security/cloudflare-access/
App innovation report: https://www.cloudflare.com/resource/app-innovation-report/
Athenian Project: https://www.cloudflare.com/athenian/
Audit Logs - v2: /fundamentals/account/account-security/audit-logs/
Authentik: /fundamentals/account/account-security/scim-setup/authentik/
Authorizing an application: /fundamentals/oauth/authorizing-an-application/
Available RSS Feeds: /fundamentals/new-features/available-rss-feeds/
Blocked Content: /fundamentals/reference/report-abuse/blocked-content/
Blog: https://blog.cloudflare.com/
Careers: https://www.cloudflare.com/careers/
Case studies: https://www.cloudflare.com/case-studies/
Change Super Administrator: /fundamentals/account/change-super-admin/
Change your domain version: /fundamentals/manage-domains/domain-version/
Changelog: /changelog/
Cloudflare AI Cloud: https://www.cloudflare.com/solutions/ai/
Cloudflare Cookies: /fundamentals/reference/policies-compliances/cloudflare-cookies/
Cloudflare Docs llms-full.txt ↗: /llms-full.txt
Cloudflare Docs llms.txt ↗: /llms.txt
Cloudflare Fundamentals llms-full.txt ↗: /fundamentals/llms-full.txt
Cloudflare Fundamentals llms.txt ↗: /fundamentals/llms.txt
Cloudflare Fundamentals: /fundamentals/
Cloudflare HTTP headers: /fundamentals/reference/http-headers/
Cloudflare IP addresses: /fundamentals/concepts/cloudflare-ip-addresses/
Cloudflare Radar: https://radar.cloudflare.com/
Cloudflare Ray ID: /fundamentals/reference/cloudflare-ray-id/
Cloudflare Skills ↗: https://github.com/cloudflare/skills
Cloudflare and Google Analytics: /fundamentals/reference/google-analytics/
Cloudflare crawlers: /fundamentals/reference/cloudflare-site-crawling/
Cloudflare dashboard ↗: https://dash.cloudflare.com/profile/api-tokens/
Cloudflare for Campaigns: https://www.cloudflare.com/campaigns/
Cloudy AI agent Beta: /fundamentals/reference/cloudy-ai-agent/
Code Mode MCP Server ↗: https://github.com/cloudflare/mcp
Community: https://community.cloudflare.com/
Complaint types: /fundamentals/reference/report-abuse/complaint-types/
Compliance documentation: /fundamentals/reference/policies-compliances/compliance-docs/
Compliance resources: https://www.cloudflare.com/trust-hub/compliance-resources/
Connection limits: /fundamentals/reference/connection-limits/
Consuming RSS Feeds: /fundamentals/new-features/consuming-rss-feeds/
Contact sales: https://www.cloudflare.com/resource/contact-enterprise-sales/
Content Security Policies (CSPs): /fundamentals/reference/policies-compliances/content-security-policies/
Control API Access: /fundamentals/api/how-to/control-api-access/
Create API token: /fundamentals/api/get-started/create-token/
Create account: /fundamentals/account/create-account/
Create tokens via API: /fundamentals/api/how-to/create-via-api/
Create your OAuth client: /fundamentals/oauth/create-an-oauth-client/
Cryptographic Attestation of Personhood: /fundamentals/reference/cryptographic-personhood/
Customer abuse report obligations: /fundamentals/reference/report-abuse/abuse-report-obligations/
Data Protection: https://www.cloudflare.com/trust-hub/gdpr/
Delete your Cloudflare account: /fundamentals/user-profiles/delete-account/
Delivering Videos with Cloudflare: /fundamentals/reference/policies-compliances/delivering-videos-with-cloudflare/
Directory: /directory/
Docs: /
Documentation: https://developers.cloudflare.com/
Domain name search: https://domains.cloudflare.com/
Domain-specific MCP Servers ↗ MCP: https://github.com/cloudflare/mcp-server-cloudflare
Edit page: https://github.com/cloudflare/cloudflare-docs/edit/production/src/content/docs/fundamentals/api/get-started/create-token.mdx
Email address and password: /fundamentals/user-profiles/change-password-or-email/
Error responses: /fundamentals/reference/error-responses/
Events: https://www.cloudflare.com/events/
Find a partner: https://partnerlocator.cloudflare.com/dashboard
Find account and zone IDs: /fundamentals/account/find-account-and-zone-ids/
Frontend Development Platform: https://www.cloudflare.com/solutions/frontends/
Get Global API key (legacy): /fundamentals/api/get-started/keys/
Get Origin CA keys Deprecated: /fundamentals/api/get-started/ca-keys/
Get started: /fundamentals/get-started/
Global network: https://www.cloudflare.com/network/
Glossary: /fundamentals/reference/glossary/
GraphQL API ↗: /analytics/graphql-api/
Home: /
How Cloudflare DNS works: /fundamentals/concepts/how-cloudflare-works/
Impact/ESG: https://www.cloudflare.com/impact/
Improve SEO: /fundamentals/performance/improve-seo/
Integrate your OAuth client with Cloudflare: /fundamentals/oauth/integrate-with-cloudflare/
Investors: https://cloudflare.net/
Leaked Password Notifications: /fundamentals/account/account-security/leaked-password-notifications/
Learning center: https://www.cloudflare.com/learning/
Licenses: /fundamentals/reference/policies-compliances/licenses/
Limitations and troubleshooting: /fundamentals/organizations/limitations/
Log In: https://dash.cloudflare.com/login
Log in to Cloudflare: /fundamentals/user-profiles/login/
Log in: https://dash.cloudflare.com/
Maintenance mode: /fundamentals/performance/maintenance-mode/
Make API calls: /fundamentals/api/how-to/make-api-calls/
Manage active sessions: /fundamentals/account/account-security/manage-active-sessions/
Manage subdomains: /fundamentals/manage-domains/manage-subdomains/
Manage: /fundamentals/manage-members/manage/
Markdown for Agents Beta: /fundamentals/reference/markdown-for-agents/
Members and permissions: /fundamentals/manage-members/
Microsoft Entra: /fundamentals/account/account-security/scim-setup/entra/
Minimize downtime: /fundamentals/performance/minimize-downtime/
Move a domain between Cloudflare accounts: /fundamentals/manage-domains/move-domain/
Multi-Factor Email Authentication: /fundamentals/user-profiles/multi-factor-email-authentication/
Multi-Tenant Platform Development: https://www.cloudflare.com/solutions/platforms/
Network Layers: /fundamentals/reference/network-layers/
Network ports: /fundamentals/reference/network-ports/
Next Get Global API key (legacy): /fundamentals/api/get-started/keys/
Okta: /fundamentals/account/account-security/scim-setup/okta/
Onboard a domain: /fundamentals/manage-domains/add-site/
Optimize site speed ↗: /speed/
Organizations for Enterprise: /fundamentals/organizations/for-enterprise/
Organizations for MSSP and Distributors: /fundamentals/organizations/for-mssp-distributors/
Overview: /fundamentals/
Overview: /fundamentals/account/account-security/scim-setup/
Overview: /fundamentals/manage-domains/
Overview: /fundamentals/oauth/
Overview: /fundamentals/organizations/
Overview: /fundamentals/reference/report-abuse/
Overview: /fundamentals/user-profiles/
Partners: /fundamentals/reference/partners/
Partners: https://www.cloudflare.com/partners/
Pause Cloudflare: /fundamentals/manage-domains/pause-cloudflare/
Plans: https://www.cloudflare.com/plans/
Policies: /fundamentals/manage-members/policies/
Policy sharing: /fundamentals/organizations/policy-sharing/
Prepare for surges or spikes in web traffic ↗: /learning-paths/surge-readiness/concepts/
Press kit: https://www.cloudflare.com/press/press-kit/
Press: https://www.cloudflare.com/press/
Prevent DDoS attacks ↗: /learning-paths/prevent-ddos-attacks/concepts/
Previous Under a DDoS attack?: /fundamentals/security/under-ddos-attack/
Privacy policy: https://www.cloudflare.com/policies/privacy/
Profile settings: /fundamentals/user-profiles/customize-account/
Project Cybersafe Schools: /fundamentals/reference/policies-compliances/cybersafe/
Project Fairshot: https://www.cloudflare.com/fair-shot/
Project Galileo: https://www.cloudflare.com/galileo/
Protect your origin server: /fundamentals/security/protect-your-origin-server/
Providing specific URLs: /fundamentals/reference/report-abuse/provide-specific-urls/
REST API ↗ API: /api/
Rate limits: /fundamentals/api/reference/limits/
Recovering from a hacked site: /fundamentals/security/recovering-from-hacked-site/
Redirect one domain to another: /fundamentals/manage-domains/redirect-domain/
Redirects: /fundamentals/reference/redirects/
Remove a domain: /fundamentals/manage-domains/remove-domain/
Report abuse: https://www.cloudflare.com/trust-hub/abuse-approach/
Report issue: https://github.com/cloudflare/cloudflare-docs/issues/new/choose
Report security issues: https://www.cloudflare.com/disclosure/
Responsible AI: https://www.cloudflare.com/trust-hub/responsible-ai/
Restrict tokens: /fundamentals/api/how-to/restrict-tokens/
Review abuse policies: https://www.cloudflare.com/trust-hub/abuse-approach/
Review audit logs - v1: /fundamentals/account/account-security/review-audit-logs/
Role scopes: /fundamentals/manage-members/scope/
Roles: /fundamentals/manage-members/roles/
Roll tokens: /fundamentals/api/how-to/roll-token/
SCIM migration: /fundamentals/reference/migration-guides/scim-virtual-groups-migration/
SDK ecosystem support policy: /fundamentals/reference/sdk-ecosystem-support-policy/
SDKs: /fundamentals/api/reference/sdks/
SSE and SASE platform: https://www.cloudflare.com/sase/
Scan for PCI compliance: /fundamentals/security/pci-scans/
Scans and penetration testing policy: /fundamentals/reference/scans-penetration/
Secure compromised account: /fundamentals/account/account-security/secure-a-compromised-account/
Secure your website ↗: /learning-paths/application-security/account-security/
Set up SSO ↗: /fundamentals/manage-members/dashboard-sso/
Set up dashboard SSO: /fundamentals/manage-members/dashboard-sso/
Star domains: /fundamentals/manage-domains/star-zones/
Start Building: https://dash.cloudflare.com/sign-up
Startups: https://www.cloudflare.com/startups/
Status: https://www.cloudflarestatus.com/
Support: https://support.cloudflare.com/
TCP connections: /fundamentals/reference/tcp-connections/
Terms of use: https://www.cloudflare.com/policies/terms/
Test speed: /fundamentals/performance/test-speed/
Token formats: /fundamentals/api/get-started/token-formats/
Trademark: https://www.cloudflare.com/trademark/
Traffic flow through Cloudflare: /fundamentals/concepts/traffic-flow-cloudflare/
Transparency report: https://www.cloudflare.com/transparency/
Troubleshooting: /fundamentals/account/account-security/scim-setup/troubleshooting/
Troubleshooting: /fundamentals/api/troubleshooting/
Troubleshooting: /fundamentals/reference/troubleshooting/
Trust Hub: https://www.cloudflare.com/trust-hub/
Two-factor authentication: /fundamentals/user-profiles/2fa/
Under Attack mode: /fundamentals/reference/under-attack-mode/
Under a DDoS attack?: /fundamentals/security/under-ddos-attack/
Under attack?: https://www.cloudflare.com/under-attack-hotline/
User Groups New: /fundamentals/manage-members/user-groups/
Verify email address: /fundamentals/user-profiles/verify-email-address/
View and submit reports: /fundamentals/reference/report-abuse/submit-report/
View as Markdown: index.md
Web Security Platform: https://www.cloudflare.com/solutions/security/
Wrangler API ↗: /workers/wrangler/api/
Zone holds: /fundamentals/account/account-security/zone-holds/
available token permissions: /fundamentals/api/reference/permissions/
desired API endpoints are compatible: /fundamentals/api/get-started/account-owned-tokens/#compatibility-matrix
find your zone and account IDs: /fundamentals/account/find-account-and-zone-ids/
https://github.com/cloudflare/cloudflare-docs
scannable format: /fundamentals/api/get-started/token-formats/
via the API: /fundamentals/api/how-to/create-via-api/

[structured-data]
{"@context":"https://schema.org","@id":"https://developers.cloudflare.com/fundamentals/api/get-started/create-token/#page","@type":"TechArticle","dateModified":"2026-04-20","description":"Learn how to create a token to perform actions using the Cloudflare API.","headline":"Create API token · Cloudflare Fundamentals docs","image":"https://developers.cloudflare.com/og-docs.png","inLanguage":"en","isPartOf":{"@id":"https://developers.cloudflare.com/#website","@type":"WebSite","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"},"publisher":{"@type":"Organization","name":"Cloudflare","url":"https://www.cloudflare.com/"},"url":"https://developers.cloudflare.com/fundamentals/api/get-started/create-token/"}

[content]
Create API token · Cloudflare Fundamentals docs
Skip to content
Documentation Index
Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt
Use this file to discover all available pages before exploring further.
Docs
Directory
API
SDKs
Changelog
Search
⌘
K
Log in
Cloudflare Fundamentals
/
Overview
Concepts
How Cloudflare DNS works
Traffic flow through Cloudflare
Accounts, zones, and profiles
Cloudflare IP addresses
Get started
Accounts
Create account
Account security
Add abuse contact
Allow Cloudflare access
Leaked Password Notifications
Manage active sessions
Review audit logs - v1
Audit Logs - v2
SCIM provisioning
Overview
Authentik
Microsoft Entra
Okta
Troubleshooting
Secure compromised account
Set up SSO ↗
Zone holds
Find account and zone IDs
Change Super Administrator
Organizations
Beta
Overview
Organizations for Enterprise
Organizations for MSSP and Distributors
Policy sharing
Limitations and troubleshooting
Members and permissions
Members and permissions
Manage
Policies
Roles
Role scopes
User Groups
New
Set up dashboard SSO
User profiles
Overview
Verify email address
Log in to Cloudflare
Profile settings
Account recovery
Delete your Cloudflare account
Email address and password
Multi-Factor Email Authentication
Two-factor authentication
Domains
Overview
Add multiple sites via automation
Change your domain version
Manage subdomains
Move a domain between Cloudflare accounts
Onboard a domain
Pause Cloudflare
Redirect one domain to another
Remove a domain
Star domains
Performance
Improve SEO
Maintenance mode
Minimize downtime
Optimize site speed ↗
Prepare for surges or spikes in web traffic ↗
Test speed
Security
Prevent DDoS attacks ↗
Protect your origin server
Recovering from a hacked site
Scan for PCI compliance
Secure your website ↗
Under a DDoS attack?
Cloudflare's API
Get started
Create API token
Get Global API key (legacy)
Get Origin CA keys
Deprecated
Token formats
Account API tokens
How to
Make API calls
Create tokens via API
Control API Access
Restrict tokens
Roll tokens
API token template URLs
Reference
REST API ↗
API
GraphQL API ↗
Wrangler API ↗
API token permissions
API deprecations
API token templates
Rate limits
SDKs
Troubleshooting
OAuth Applications on Cloudflare
Overview
Create your OAuth client
Integrate your OAuth client with Cloudflare
Authorizing an application
Reference
Migration guides
SCIM migration
Policies
Cloudflare Cookies
Compliance documentation
Content Security Policies (CSPs)
Delivering Videos with Cloudflare
Licenses
Project Cybersafe Schools
Abuse
Overview
Review abuse policies
Complaint types
Providing specific URLs
Customer abuse report obligations
View and submit reports
Blocked Content
SDK ecosystem support policy
Troubleshooting
/cdn-cgi/ endpoint
Account and domain management best practices
Cloudflare and Google Analytics
Cloudflare crawlers
Cloudflare HTTP headers
Cloudflare Ray ID
Cloudy AI agent
Beta
Connection limits
Cryptographic Attestation of Personhood
Error responses
Glossary
Markdown for Agents
Beta
Network Layers
Network ports
Partners
Redirects
Scans and penetration testing policy
TCP connections
Under Attack mode
RSS Feeds
Available RSS Feeds
Consuming RSS Feeds
Agent resources
Agent setup ↗
Cloudflare Skills ↗
Code Mode MCP Server ↗
Domain-specific MCP Servers ↗
MCP
Cloudflare Fundamentals llms.txt ↗
Cloudflare Fundamentals llms-full.txt ↗
Cloudflare Docs llms.txt ↗
Cloudflare Docs llms-full.txt ↗
Home
/
Cloudflare Fundamentals
/
…
Cloudflare's API
/
Get started
/
Create API token
Create API token
Last updated
Apr 20, 2026
|
Copy as Markdown
|
View as Markdown
|
Agent setup
Prerequisite
Before you begin,
find your zone and account IDs
.
Determine if you want a user token or an
Account API token
. Use Account API tokens if you prefer service tokens that are not associated with users and your
desired API endpoints are compatible
.
From the
Cloudflare dashboard
↗
, go to
My Profile
>
API Tokens
for user tokens. For Account Tokens, go to
Manage Account
>
API Tokens
.
Select
Create Token
.
Select a template from the available
API token templates
or create a custom token. The following example uses the
Edit zone DNS
template.
Add or edit the token name to describe why or how the token is used. Templates are prefilled with a token name and permissions.
Modify the token's permissions. After selecting a permissions group (
Account
,
User
, or
Zone
), choose what level of access to grant the token. Most groups offer
Edit
or
Read
options.
Edit
is full CRUDL (create, read, update, delete, list) access, while
Read
is the read permission and list where appropriate. Refer to the
available token permissions
for more information.
Select which resources the token is authorized to access. For example, granting
Zone DNS Read
access to a zone
example.com
will allow the token to read DNS records only for that specific zone. Any other zone will return an error for DNS record reads operations. Any other operation on that zone will also return an error.
(Optional) Restrict how a token is used in the
Client IP Address Filtering
and
TTL (time to live)
fields.
Select
Continue to summary
.
Review the token summary. Select
Edit token
to make adjustments. You can also edit a token after creation.
Select
Create Token
to generate the token's secret.
Copy the secret to a secure place.
Warning
The token secret is
only shown once
. Do not store the secret in plaintext where others can access it. Anyone with this token can perform the authorized actions against the resources that the token has access to.
The token secret page also includes an example command to test the token. Use the
/user/tokens/verify
endpoint to fetch the current status of the given token.
curl
"https://api.cloudflare.com/client/v4/user/tokens/verify"
\
--header
"Authorization: Bearer <API_TOKEN>"
The result:
{
"result"
: {
"id"
:
"100bf38cc8393103870917dd535e0628"
,
"status"
:
"active"
},
"success"
:
true
,
"errors"
: [],
"messages"
: [
{
"code"
:
10000
,
"message"
:
"This API Token is valid and active"
,
"type"
:
null
}
]
}
New API tokens use the
cfut_
prefixed
scannable format
, which allows credential scanning tools to detect leaked tokens.
With this you have successfully created an API token and can start working with the Cloudflare API. After creating your first API token, you can create additional API tokens
via the API
.
Previous
Under a DDoS attack?
Next
Get Global API key (legacy)
Was this helpful?
Yes
No
Edit page
Report issue
On this page
Overview
Was this helpful?
Yes
No
Edit page
Report issue
Getting started
Plans
Contact sales
Partners
Find a partner
Startups
Under attack?
Domain name search
Company
About
Careers
Investors
Press
Press kit
Global network
Public interest
Project Galileo
Athenian Project
Cloudflare for Campaigns
Project Fairshot
Impact/ESG
Compliance
Compliance resources
Trust Hub
Data Protection
Responsible AI
Transparency report
Report abuse
Resources
App innovation report
Cloudflare Radar
Case studies
Status
Support
Events
Blog
Developers
Documentation
Learning center
Community
Solutions
SSE and SASE platform
Cloudflare AI Cloud
AI Security
Frontend Development Platform
Multi-Tenant Platform Development
Web Security Platform
Start Building
Log In
© 2026 Cloudflare, Inc.
Privacy policy
|
Report security issues
|
Terms of use
|
Trademark
|
Your privacy choices
Docs
