Connect a Cloudflare account

PruneOps needs a read-only Cloudflare API token to inventory Zones, Workers, R2 Buckets and Pages Projects, and to read billable usage and plan subscriptions for the costs dashboard.

How it works

One token, read-only.

01
API token

On the account's credentials tab, click "Create token on Cloudflare" — it opens the Cloudflare dashboard with a Custom Token pre-filled with read permissions on Zone, Account Settings, Workers Scripts, Workers R2 Storage, Cloudflare Pages and Billing. Review and confirm to create it.

02
Account ID

Optional — the 32-character account tag from the Cloudflare dashboard. Resolved automatically from the token when left empty.

03
Read-only scope

Scope the token to read-only when generating it — nothing PruneOps does ever needs write access.

API token

Covers Zones, Workers, R2 Buckets, Pages and billing.

  1. Use the Create token on Cloudflare button on the account's Credentials tab — it opens the Cloudflare dashboard with a Custom Token pre-filled with read permissions on Zone, Account Settings, Workers Scripts, Workers R2 Storage, Cloudflare Pages and Billing. Review the permissions, then click Continue to summary → Create Token. Nothing this app does ever needs write access.
  2. Go to Organization → Integrations → Cloud Accounts → Add Account, pick Cloudflare, and paste the token.

Account ID (optional)

The 32-character account tag shown in the Cloudflare dashboard sidebar.

Leave it empty and it is resolved automatically from the token — only fill it in if the token can see several accounts and you want to pin one.

Costs

Imported daily from the Cloudflare billing API.

Metered usage (Workers requests, R2 storage and operations, ...) arrives as daily billable-usage rows, and fixed-price subscriptions (zone plans, Load Balancing, ...) as one row per billing cycle. Both appear in the costs dashboard grouped by service and zone — no CSV export needed.

First sync

Once the account is saved, inventory runs on the next hourly cycle — or trigger it immediately from the account's detail page. Discovered Zones, Workers, R2 Buckets and Pages Projects appear under Audit → Cloudflare.