Skip to content
Providers / Cloudflare

Cloudflare

Verified
www.cloudflare.com

Privacy-conscious zone traffic and security analytics for evidence-bounded incident review.

What you can do with Cloudflare

Answer what changed in one Cloudflare zone with sample-aware traffic totals and privacy-conscious security evidence before anyone edits production settings.

Useful workflows

  • Read estimated requests, visits, response bytes, and hourly groups for an explicit UTC range.
  • Inspect firewall actions by source and country without requesting IPs, paths, queries, or user agents.
  • Compare two windows and preserve correlation, sampling, and root-cause limits in an incident brief.

Connection and permissions

Use a zone-scoped Cloudflare API token with Zone Analytics Read and the exact 32-character zone ID; no edit permission is needed.

Pricing basis

Cloudflare does not publish a separate per-request charge for these analytics reads; ToolRouter charges the displayed skill price and failed paid calls do not charge.

Evidence limits

  • Traffic queries are limited to 31 days and preserve Cloudflare sampling notes.
  • Security-event queries are limited to seven days and 1,000 non-identifying rows.
  • The tool never edits DNS, cache, rate limits, WAF rules, firewall configuration, or zone state.

Official provider documentation: Cloudflare GraphQL Analytics, Cloudflare firewall-event query, Cloudflare API permissions

Frequently Asked Questions

Can ToolRouter explain a Cloudflare traffic spike?

It can quantify the observed sampled change and nearby rule-action evidence, but it does not claim a deployment, campaign, attack, or outage caused the spike without separate evidence.

Does the Cloudflare tool expose visitor IP addresses?

No. Its security query deliberately omits IP addresses, request paths, query strings, and user agents and returns only action, source, country, ASN, and timestamp fields.

Can the Cloudflare traffic auditor change WAF or DNS settings?

No. Every skill is read-only and the required token needs Zone Analytics Read only, so configuration changes remain outside this tool.