Connect Cloudflare to Black Cat SSPM
Connect your Cloudflare account so Black Cat can review zone security settings, TLS configuration, firewall rules, DNS records, account members and AI Gateway settings.
≈ 5 min · audit access · no write-capable permission
What Black Cat reads, and why
| Permission | What it lets Black Cat do | Status |
|---|---|---|
Zone.Zone.Read | Lets Black Cat review each zone's TLS mode, HSTS, minimum TLS version and other security settings. | Required |
Zone.Zone WAF.Read | Lets Black Cat see whether the web application firewall is switched on for each zone. | Optional |
Account.Account WAF.Read | Lets Black Cat review account-wide firewall rules. | Optional |
Zone.DNS.Read | Lets Black Cat review DNS records for wildcards, private addresses and hosts left unproxied. | Required |
Account.Account Settings.Read | Lets Black Cat review account settings such as single sign-on and two-factor enforcement. | Required |
Account.Member Read | Lets Black Cat list account members, their roles and whether their access is still pending. | Required |
User.API Tokens.Read | Lets Black Cat list API tokens and how recently each one was used. | Optional |
Account.AI Gateway.Read | Lets Black Cat review AI Gateway settings such as logging and authentication. | Required |
Account.Workers Scripts.Read | Lets Black Cat inventory the Workers scripts deployed on the account. | Required |
What you'll need
- Account identifier Required — Shown in the right-hand column of your Cloudflare dashboard overview.
- Read-only API token Required — Created under My Profile in the Cloudflare dashboard, with the read permissions listed below.
Where to create it
- Setup guide (Cloudflare) ↗ (opens in new tab)
- Developer documentation (Cloudflare) ↗ (opens in new tab)