Your token is held in your browser only and used to talk to Cloudflare directly for this session. It is never stored on our servers and never logged. The connection auto-expires after 4 hours.
Add these two permissions:
• Zone → Zone WAF → Edit • Zone → Zone → Read
Under Zone Resources, choose specific zones or "All zones" to harden everything at once.
Create the token, copy it, and paste it below.
This token can only read your zone list and edit WAF custom rules, nothing else. After you're done you can delete the token from your Cloudflare Dashboard: dash.cloudflare.com/profile/api-tokens
Connected
2 Configure & deploy
0 selected
No zones loaded.
Visitors from outside these countries get a managed challenge. Space-separated 2-letter ISO codes, e.g. US CA GB. Find your country codes here. Getting this wrong challenges your real visitors.
Added to the Allow rule so wp-cron isn't blocked. IPv4 and/or IPv6, space-separated.
Paste any valid Cloudflare expression. Leave blank to use the default Allow Good Bots rule.
Cloudflare's free plan allows 5 custom rules. Enabling this combines the VPN/hosting/path rules into one (4 rules total) so your 5th slot is free for Cloudflare's native AI Crawl Control feature (Security → Bots).