Cloudflare
Connect
Connect Cloudflare from the terminal. Pass --help for the flags Cloudflare accepts, plus --no-browser for headless environments.
polylane cloud connect --provider cloudflareAccount-owned API token with operational access.
Cloudflare connects with an account-owned API token. Unlike most providers, Polylane requests operational (edit) access so agents can act on your infrastructure, not just read it. Your token is encrypted before it is stored, and the agent never sees it.
Setup
- In the connection form, click Create token. It opens Cloudflare's account API token screen with every permission Polylane needs pre-selected.
- Select the account you want to connect. You must be a Super Administrator on that account to create an account-owned token.
- Review the pre-filled permissions, then click Continue to summary and Create Token.
- Copy the token and paste it back into Polylane.
- Polylane validates the token and starts syncing.
Choose Read-only if you want Polylane to investigate and explain issues without ever changing anything in your account. Choose Read and write to let agents fix issues directly (deploys, config, rollbacks). Every write is confirmed with you first.
You must be on the Workers Paid plan for full resource discovery.
Permissions
The pre-configured link creates an account-owned token: a durable service principal that keeps working even if the person who created it leaves the account. With read and write access it requests broad edit permissions:
- Developer Platform: Workers, KV, R2, D1, Queues, Pipelines, Hyperdrive, Durable Objects, Containers, Secrets Store, Artifacts, and more
- AI & Machine Learning: Workers AI, AI Gateway, AutoRAG, Vectorize, AI Search
- DNS & Zones: DNS, zone settings, registrar, DNS firewall
- Network Services: Load Balancing, Magic Transit/WAN, Spectrum, tunnels
- App Security: WAF, rulesets, DDoS, bot management, page rules, certificates
- Cache, Email, Media, Rules, Analytics & Logs
Deliberately scoped down for safety:
- Zero Trust / Cloudflare One is granted read-only.
- No billing changes, API-token management, or SSO/SCIM/OAuth identity writes.
Disconnecting
Disconnect the account in Polylane, then revoke the API token from your Cloudflare dashboard under My Profile → API Tokens (or Manage Account → API Tokens for account-owned tokens).
Tools
14Operations agents can perform in threads and automations.
Supported resources
46Resource types that show up in your infrastructure graph.
Automation triggers
4Events from Cloudflare that can start an automation.
Automation templates
6Pre-built automations that use Cloudflare. Open one to see its trigger, instructions, and actions.