Skip to content
Help Center

Cloudflare integration overview

View Markdown Contact support Contact support 4 min read
On this page

Overview

Cloudflare gives a range of internet services, including content delivery network (CDN) services, cloud cybersecurity, DDoS mitigation, and domain registration.

The Persona Cloudflare integration gets Cloudflare account membership data into Persona workflows. Teams can then automate access checks and do fewer manual follow-ups during onboarding, investigations, or internal reviews. With the integration, you can find the Cloudflare accounts that a user can access and get detailed membership data. You can also reply to pending account invitations programmatically.

To use Persona as an identity provider that controls access to applications through Cloudflare Access (Zero Trust), read Configure Persona as an Authentication Method in Cloudflare Access. That integration is separate from the workflow integration in this article.

Benefits

Centralized Access Context: Show Cloudflare membership details (for example, account information, roles, and permissions) in Persona. Reviewers then have the correct data when they make decisions.

Automated Access Reviews: Automatically find memberships and filter results (for example, by status). This supports repeatable checks in workflows that follow your policies.

Faster Provisioning & Offboarding: Accept or reject pending Cloudflare account invitations directly from Persona. Teams can complete the process without manual clicks in different tools.

Integration Features

The Persona Cloudflare integration helps teams manage workflows for Cloudflare memberships directly from Persona. Important capabilities are:

  • List memberships: Get the Cloudflare account memberships that a user can access. Filters, sorting, and pagination are optional.
  • Retrieve membership details: Get a specific membership. Later workflow steps can then use the latest account and access data.
  • Respond to invitations: Accept or reject a pending Cloudflare account invitation. This supports closed-loop provisioning workflows.

Setting up the Cloudflare integration

Prerequisites

To set up the Cloudflare integration, make sure that you have:

  • Admin access to your Cloudflare account.
  • The necessary API permissions to access Cloudflare credentials.

Setting up the Cloudflare Credentials

  1. In the Cloudflare dashboard, create an API token with the permissions that the membership actions you will run need. (Cloudflare recommends that you use API tokens when possible.)
  2. In the Persona Dashboard, go to Integrations > Marketplace and select Cloudflare.
  3. Click Add Credential.
  4. Enter a Nickname for Credential. Your team can then identify this connection later.
  5. Do the steps that the Dashboard shows to add your Cloudflare API token. Then save the credential.
  6. Click Test to make sure that the credential works.

Using the Cloudflare integration in a Workflow

  1. Create a new workflow, or open an existing workflow that you want to update.
  2. Add a new action step > Integrations.
  3. Select the Cloudflare integration and select your saved Cloudflare credential.
  4. Select the operation that you want to run (for example, List Memberships or Update Membership). Configure the input fields.
  5. Save and publish the workflow.

Cloudflare Operations Overview

Persona can sync field values. It can also use the Cloudflare API to list memberships, get membership details, and accept or reject account invitations. These actions support two-way workflows. Teams can manage investigations and do not have to change platforms.

Below is a full list of the Workflow Action steps and configurations for the Cloudflare integration:

List Memberships Workflow Action Step

Lists the Cloudflare account memberships that the connected user can access. This is useful when you must find applicable accounts dynamically (for example, during onboarding). It is also useful to show only specific membership states, for example pending invitations.

Configuration Steps:

  • Optionally add:
    • Account name filter
    • Name filter
    • Status (accepted, pending, rejected)
    • Sorting (field + direction)
    • Pagination (page and results per page)

Retrieve Membership Workflow Action Step

Gets one Cloudflare membership with its identifier, so that you can access the latest details for that membership. This is useful when a workflow already has a membership ID (for example, from a previous step). The workflow can then get authoritative account data, for example roles, permissions, or current status, before it does an action.

Configuration Steps:

  • Provide values for required fields:
    • Membership ID

Update Membership Workflow Action Step

Updates a pending membership with a reply to an account invitation. With this step, you can accept or reject an invitation in a controlled workflow. Teams can then put provisioning decisions into operation and keep Cloudflare access aligned with internal policy.

Configuration Steps:

  • Provide values for required fields:
    • Membership ID
    • Status (accepted or rejected)

FAQs

What Cloudflare data can Persona access with this integration?

Persona can get Cloudflare membership information, including membership status. If the membership response includes related account data (for example, account details, roles, permissions, and policies), Persona can get it too.

What do membership statuses mean in Cloudflare?

Memberships can be accepted, pending, or rejected. A pending membership usually shows an open invitation. You can reply to it with the Update Membership action.

Can I limit which memberships are returned when listing memberships?

Yes. When you list memberships, you can filter by fields, for example account name or status. You can also sort and paginate results for larger environments.

Plans Explained

Cloudflare Integration by plan

Startup ProgramEssential PlanGrowth PlanEnterprise Plan
Cloudflare IntegrationNot AvailableNot AvailableLimitedAvailable

Learn more about pricing and plans.

Was this page helpful?If something is missing, let us know and we will take a look.
Thanks for the feedback. It helps us improve these docs.