Skip to content

Manage Cloudflare tokens for organizations and domains

Use cPFence v4+ on the Enhance main control panel server, with a valid cPFence license, a saved Enhance API key and permission for Cloudflare actions on the selected websites.

  1. Open Tools & Utilities → ApiMachine Bulk Tools and choose Cluster scope or Select servers.
  2. Filter the websites, then check the intended rows. Filtering alone does not select them; Select all … filtered websites includes other pages.
  3. Open Choose action → Cloudflare and choose one task below.

Organization actions affect the organization owning each selected website, including its other domains. Domain actions apply to the selected domains. Check the owners as well as the website names before continuing.

  1. Choose Add Cloudflare token to Org.
  2. Enter a Friendly name and the complete Cloudflare API token privately.
  3. Select Review action and inspect the selected websites, servers and organization scope. Select Confirm and run only for the intended targets.
  4. Read each organization’s result and check its saved token in Enhance. An already-present matching token can be skipped.

Add Cloudflare token to Org form with Friendly name, an empty token field and target sections.

Enter the complete token privately. Check the organizations owning the selected websites before reviewing the action. Select the image to enlarge it; use your browser's Back command to return.

Keep the original token securely; you will need its friendly name and first five characters to identify it for the other tasks.

  1. Choose Remove Cloudflare token from Org.
  2. Enter its Friendly name and Token prefix (first 5 characters).
  3. Select Review action, check the organization scope, then Confirm and run.
  4. Check each result and the organization’s token list. A missing matching token is skipped without removing the organization’s other tokens.

Remove Cloudflare token from Org form showing Friendly name, Token prefix and target sections.

Identify the token using its friendly name and first five characters. Organization removal can affect its other domains and integrations. Select the image to enlarge it; use your browser's Back command to return.

The matching token must already exist in each target domain’s organization. Add it there first if needed.

  1. Choose Link token to domains.
  2. Enter the existing token’s Friendly name and Token prefix (first 5 characters).
  3. Select Review action, check the selected domains and warning, then Confirm and run.
  4. Check the resulting domain mapping and DNS state in Enhance/Cloudflare. A domain already linked to that token can be skipped.

Link token to domains form showing Friendly name, Token prefix and target sections.

Choose an existing organization token and check the selected domains. Review the DNS-record warning before proceeding. Select the image to enlarge it; use your browser's Back command to return.

This removes the domain’s link to the matching token; it does not delete the organization token.

  1. Choose Remove token from domains.
  2. Enter its Friendly name and Token prefix (first 5 characters).
  3. Select Review action, verify the intended domains, then Confirm and run.
  4. Read the results and check each domain’s mapping. A domain linked to a different token is left unchanged.

Remove token from domains form showing Friendly name, Token prefix and target sections.

Check the exact domains before removing their link to the matching token. Select the image to enlarge it; use your browser's Back command to return.

As root on the main control panel server, prepare and review the CLI site list. Replace the placeholders privately and run only the intended command:

Task Command
Add organization token cpfence --bulk-set-cloudflare-key-org "FRIENDLY_NAME,FULL_TOKEN"
Remove organization token cpfence --bulk-remove-cloudflare-key-org "FRIENDLY_NAME,FIRST_5_CHARACTERS"
Link token to domains cpfence --bulk-set-cloudflare-key-dom "FRIENDLY_NAME,FIRST_5_CHARACTERS"
Remove domain link cpfence --bulk-remove-cloudflare-key-dom "FRIENDLY_NAME,FIRST_5_CHARACTERS"

Read the targets and confirmation before answering yes. Keep token arguments and terminal history private. Do not regenerate the site list after reviewing your exclusions.

Check the friendly name, complete token versus five-character prefix, API permissions and token availability in the correct organization. Read which targets succeeded or were skipped. After a lost output stream, inspect the actual token/mapping state before retrying; do not replay an uncertain removal or zone change across the whole selection.