InfraNestInfraNest
Cloudflare

Cloudflare integration

Manage Cloudflare DNS, domains and certificates in one place

Connect your Cloudflare account with one API token and every zone, record, domain and certificate it holds appears in InfraNest — in the same lists as the ones you keep at every other provider. Edit a record, check an expiry date or purge the cache without opening the Cloudflare dashboard.

Free plan · About 3 minutes · You choose what the token is allowed to do

  • Zones and records imported the moment you connect
  • DNS in plain English, not a wall of acronyms
  • Domain and certificate expiry dates in one list
  • Cache and security changes on a trigger
DNSManage DNS records across all your zones and provider accounts.+ Add zone
ZoneSecurityRecords
northwind-api.devPendingOpenprovider · 7 records · synced 2h ago7
northwind-app.devCloudflare · 7 records · synced 15m ago7
northwind-docs.comCloudflare · 7 records · synced 37m ago7
northwind-mail.comTransIP · 8 records · synced 10m ago8
northwind.cloudHetzner · 4 records · synced 54m ago4
northwind.comCloudflare · 7 records · synced 15m ago7
Showing 6 of 13 zones
northwind-app.devCloudflare · 7 records · synced 15m ago7
northwind-docs.comCloudflare · 7 records · synced 37m ago7
northwind.comCloudflare · 7 records · synced 15m ago7
northwind.ioCloudflare · 7 records · synced 15m ago7
nwcloud.coCloudflare · 4 records · synced 15m ago4
nwcloud.ioDynadot · 4 records · synced 4h ago4
northwind.cloudHetzner · 4 records · synced 54m ago4
northwind.deHetzner · 7 records · synced 54m ago7
northwind-api.devPendingOpenprovider · 7 records · synced 2h ago7
northwind.euOpenprovider · 7 records · synced 2h ago7
northwind.shopPorkbun · 7 records · synced 2h ago7
northwind-mail.comTransIP · 8 records · synced 10m ago8
northwind.nlTransIP · 7 records · synced 10m ago7

Edit Cloudflare DNS without opening Cloudflare

Connect the account and every zone you have at Cloudflare is found and imported — there is nothing to re-enter. From then on those records live in the same editor as the records you keep everywhere else: create them, change them, delete them, proxied setting included. The editor groups each zone by what the records actually do — the website, email, everything else — so you can see which rows keep the site up and which keep mail flowing, instead of reading a column of acronyms and hoping.

  • Create, edit and delete records in any Cloudflare zone, proxied setting included
  • Existing zones and their records imported automatically when you connect
  • Grouped by purpose — the website, email, everything else
  • One editor for Cloudflare and every other DNS provider you use
northwind.io

7 records at Cloudflare · read from the provider 15m ago

RecordsMail & securityActivitySettings
+ Add record
TypeNameTTL
The website5 record(s)
A@5.75.140.205 min
Awww5.75.140.205 min
AAAA@2a01:4f8:1c1e:9a10::15 min
CNAMEapinorthwind.io5 min
CNAMEappnorthwind.io5 min
Email1 record(s)
TXT@v=spf1 -all1 hour
Verification1 record(s)
TXT_acme-challengenorthwind-demo-validation-token2 min
A2 record(s)
A@5.75.140.205 min
Awww5.75.140.205 min
AAAA1 record(s)
AAAA@2a01:4f8:1c1e:9a10::15 min
CNAME2 record(s)
CNAMEapinorthwind.io5 min
CNAMEappnorthwind.io5 min
TXT2 record(s)
TXT@v=spf1 -all1 hour
TXT_acme-challengenorthwind-demo-validation-token2 min

Domains registered at Cloudflare, in the same list as the rest

Names you bought at Cloudflare sit next to the ones you bought anywhere else, with expiry date, auto-renew and transfer lock as columns you can sort. Change auto-renew, WHOIS privacy or the transfer lock without a separate login, pull the transfer code when a name needs to move, and hear about a renewal date long before it arrives rather than the week after it passed.

  • Expiry, auto-renew and transfer lock in one sortable list
  • WHOIS privacy, auto-renew and transfer lock changed without logging in to Cloudflare
  • The transfer (EPP) code for a Cloudflare-registered domain, on the page
  • Renewal warnings across every registrar you use, not just this one
DomainRenewal/yr
ClearAuto-renew onAuto-renew offSet contactAdd tag

Cloudflare certificates, with expiry dates you can actually see

Certificates issued through Cloudflare appear in your certificate list with their expiry dates, instead of being checked one zone at a time — beside the ones your servers issued themselves and any you uploaded by hand. They are then watched like the rest: you are told when one is expiring, weak, revoked, or simply not the certificate that was supposed to be there.

  • Cloudflare certificates listed with their expiry dates, not checked zone by zone
  • Warned about certificates that are expiring, weak, revoked or unexpected
  • One list for every source — Cloudflare, your servers, manual uploads
  • The hostnames each certificate actually covers, spelled out
CertificatesEvery SSL/TLS certificate we see across your infrastructure — discovered automatically from your monitors, with expiry tracking and alerts.+ Add certificate
All sourcesCloudflareDigitalOceanHetznerManualMonitorPublic log (crt.sh)TransIP
SubjectExpires
northwind.com5 certificates4 auto-renew · 2 discovered, not monitored
api.northwind.comLet's Encrypt (R3) · rsa 2048 · found by Monitorin 3 months
cdn.northwind.comWildcardCloudflare Inc ECC CA-3 · ecdsa 256 · found by Cloudflarein 10 months
docs.northwind.comLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 2 months
northwind.com+1Let's Encrypt (R3) · rsa 2048 · found by Monitorin 2 months
shop.northwind.comGlobalSign GCC R6 AlphaSSL CA 2023 · rsa 2048 · found by Public log (crt.sh)in 3 months
northwind-app.dev2 certificates2 auto-renew
northwind-app.devWildcardLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 21 days
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
Showing 7 of 11 certificates
northwind.com1 certificates1 auto-renew · 1 discovered, not monitored
cdn.northwind.comWildcardCloudflare Inc ECC CA-3 · ecdsa 256 · found by Cloudflarein 10 months
northwind-app.dev1 certificates1 auto-renew
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
northwind.cloud1 certificates1 auto-renew · 1 discovered, not monitored
*.northwind.cloudWildcardLet's Encrypt (R11) · ecdsa 256 · found by Hetznerin 2 months
vpn.northwind.example1 certificates1 discovered, not monitored
vpn.northwind.examplevpn.northwind.example · rsa 4096 · found by Manual12 days ago
northwind.com3 certificates3 auto-renew
api.northwind.comLet's Encrypt (R3) · rsa 2048 · found by Monitorin 3 months
docs.northwind.comLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 2 months
northwind.com+1Let's Encrypt (R3) · rsa 2048 · found by Monitorin 2 months
northwind-app.dev2 certificates2 auto-renew
northwind-app.devWildcardLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 21 days
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
northwind.com1 certificates1 discovered, not monitored
shop.northwind.comGlobalSign GCC R6 AlphaSSL CA 2023 · rsa 2048 · found by Public log (crt.sh)in 3 months
northwind-mail.com1 certificates1 auto-renew · 1 discovered, not monitored
northwind-mail.com+2Let's Encrypt (R3) · rsa 2048 · found by TransIPin 3 months
northwind.nl1 certificates1 discovered, not monitored
northwind.nl+1Sectigo RSA Organization Validation Secure Server CA · rsa 2048 · found by TransIPin 5 months

Purge the cache or raise the security level automatically

Four Cloudflare controls are available as steps in a rule rather than as things you have to remember: purge the cache, turn development mode on or off, adjust always-online, and change the security level. What sets them off can come from anywhere else you have connected — a DNS record that changed, a certificate getting close to expiry, a domain renewing. You build the rule by choosing when it runs and what it should do, and nothing happens until you switch it on.

  • Purge cache, development mode, always-online and security level as rule steps
  • Started by DNS, certificate or domain events from any provider you connect
  • No scripts: pick a trigger, add the steps, read it back in plain English
  • Nothing runs until you turn the rule on — see how rules are built
Expiring domain → approve, then auto-renew
ActivePausedSave automation

When this happens

Domain expiring

A domain is approaching its expiry date.

Change

Runs at 09:00 · Europe/Amsterdam · it’s 15:49 there now

Next runs:Sat 19 Sept, 09:00Sun 20 Sept, 09:00Mon 21 Sept, 09:00

This automation only runs when you click “Run now”.

Only if — optional filters

MatchAllAnyNoneof these conditions

Tip: a value can reference another field or the time using a placeholder.

Do this — actions run in order, stop at the first failure

1Require approvalPause for a human to approve before the steps below run.
2Set auto-renewTurn the domain’s auto-renew on or off.
3Send notificationSend an alert to your channels or email addresses.

In plain English

When Domain expiring if Days left less or equal 15, then Require approval, Set auto-renew and Send notification.

See your own Cloudflare zones in InfraNest

Free plan, no credit card. Connect the account and your zones, records and domains appear on their own.

Connect Cloudflare in about three minutes

One API token, created in your own Cloudflare account. You decide what it may do there — give it read access first if you would rather look around before anything can be changed.

  1. 1

    Create a Cloudflare API token

    Generate a token with Zone: Read, DNS: Edit, Cache: Purge, Zone Settings: Edit, Domain Registrar: Admin and SSL and Certificates: Read.

  2. 2

    Open the Cloudflare integration

    Go to Integrations and open Cloudflare. Give the connection an optional Account label to tell it apart from other connections.

  3. 3

    Choose your features and paste the token

    Select which of DNS, Domains and Certificates to use, then paste your API token. Add your Account ID only if the domains feature can't detect it automatically.

  4. 4

    Connect

    Leave email warnings ticked if you want to be notified when the integration has problems, then select Connect. Your existing zones appear automatically.

That’s it — Cloudflare is connected.

Full setup guide

Set up with AI

I want to connect my Cloudflare account to InfraNest (infranest.io), which manages DNS, domains and certificates across providers. Walk me through creating a Cloudflare API token with these permissions: Zone: Read, DNS: Edit, Cache Purge: Purge, Zone Settings: Edit, Domain Registrar: Admin, and SSL and Certificates: Read. For each one, tell me where it is in the current Cloudflare dashboard, what it allows, and whether I can leave it out if I only want to manage DNS records at first. Then tell me how to check the token works before I paste it anywhere.

What syncs

What InfraNest keeps in sync with Cloudflare.

DNS zonesDNS zones and records
DomainsDomains, expiry dates, nameservers and lock state
CertificatesCertificates and their expiry

What still happens in Cloudflare

InfraNest can't transfer domains into Cloudflare or renew a transfer-in through this integration, and nameservers stay managed in the Cloudflare zone — both of those still happen in the Cloudflare dashboard. It also doesn't manage cloud infrastructure resources; those belong to a different integration.

Questions about the Cloudflare integration

#What happens if the API token is revoked or expires?

Authentication fails and InfraNest will show an error until a valid token is added back. Nothing on Cloudflare is changed while the connection is broken; you'll just lose visibility and editing until it's reconnected.

#Can InfraNest change settings on my Cloudflare account, not just read them?

Yes — with the scopes above it can edit DNS records, change zone settings, purge cache, and manage domain settings like auto-renew, WHOIS privacy and transfer lock for domains registered at Cloudflare.

#Can I register a new domain through InfraNest?

Only for domains already on Cloudflare. Brand-new registrations and transfers in still need to be done directly in the Cloudflare dashboard.

#Can I connect more than one Cloudflare account?

Yes, multiple Cloudflare accounts can be connected at once, each with its own label so you can tell them apart.

#Do I need to re-add my zones after connecting?

No — existing zones and their records are found and imported automatically as soon as the connection is made.

Bring Cloudflare into one dashboard

Connect it in about three minutes, then add the next provider. Everything you run, in one place.

Free plan · No credit card required · Set up in minutes