# Connect Cloudflare

> Verify a Cloudflare site and let SEOFixBot past its firewall, either automatically with a scoped API token or by adding the record and rule yourself.

Source: https://seofix.ai/help/connect-cloudflare · Category: Sites & firewalls · Updated: 2026-10-08

If your site's DNS is on Cloudflare, one setup does two things: a TXT record proves you own the domain, and a WAF skip rule lets SEOFixBot through challenges. Open the site page, choose the **Cloudflare** method on the ownership card, then pick **Connect automatically** (with an API token) or **Do it myself** (no API token). Both add the same record and rule.

Cloudflare setup is in the web app only. There is no `/v1` endpoint or MCP tool for it.

## Connect automatically (with an API token)

1. On the site page, open the **Cloudflare** method and choose **Connect Cloudflare**.
2. Choose **Open Cloudflare**. It opens Cloudflare's *Create API token* page pre-filled with a template named `SEOFix (<your host>)` and these permissions:

   | Permission | Why |
   |---|---|
   | Zone → Zone → Read | Find your domain's zone |
   | Zone → DNS → Edit | Add the verification TXT record |
   | Zone → Zone WAF → Edit | Add the firewall skip rule |

   Cloudflare's template link cannot pick the zone for you. Set **Zone Resources** to your site's zone, then create the token.
3. Back in SEOFix, paste the token under **Paste the token** and choose **Connect**.

The dialog then shows three results: **Verification record**, **Firewall rule** and **Ownership verified** (or **Waiting for DNS**: the record can take a few minutes to appear, and SEOFix re-checks automatically).

### What SEOFix creates

SEOFix looks up the zone of your site's registrable domain (`blog.example.com` → `example.com`) and adds:

- **One TXT record** at the zone apex: `seofix-verify=<verification token>`, with the comment "SEOFix ownership verification". If you already added the identical record by hand, SEOFix reuses it and never deletes it.
- **One custom rule** named **SEOFix crawler (auto)**, placed first in the zone's WAF custom rules (SEOFix creates the custom-rules list if your zone has none):
  - Expression: `any(http.request.headers["x-seofix-verify"][*] eq "<crawler secret>")`
  - Action: **Skip**, with *All remaining custom rules*, *All managed rules* and *All Super Bot Fight Mode rules*, plus Browser Integrity Check, Security Level, User Agent Blocking, Hotlink Protection and Zone Lockdown.
  - *All Super Bot Fight Mode rules* is left out automatically when your Cloudflare plan does not allow it.
  - Rate limiting rules are **not** skipped. SEOFixBot slows down when it is rate limited.

The rule matches your site's private **crawler secret**, which SEOFixBot sends in the `X-SEOFix-Verify` header. It never matches the public verification token, which anyone can read from your DNS.

### How the token is stored

As the app states: the token is **stored encrypted** and used only for that record and rule. SEOFix uses it for the zone lookup, the one TXT record and the one WAF rule, and never returns it in a response. You can revoke it any time in Cloudflare (My Profile → API Tokens), or choose **Disconnect** in SEOFix to remove both.

### Errors when connecting

| Message | Fix |
|---|---|
| This token cannot read your zone. | Edit the token in Cloudflare: add Zone → Zone → Read, and include this domain in Zone Resources. |
| This token can read your zone but cannot manage DNS records. | Add Zone → DNS → Edit. |
| This token can read your zone and DNS but cannot manage WAF custom rules. | Add Zone → Zone WAF → Edit. |
| Cloudflare is already connected for this site. Disconnect it first. | One connection per site. |
| Cloudflare could not be reached. Please try again. | Retry later. |

If any step fails, SEOFix removes what it already created in your zone before reporting the error.

### Disconnect

On the site page, the **Cloudflare** method shows the connected zone and **Disconnect**. Disconnecting removes the firewall rule and SEOFix's TXT record from Cloudflare, then deletes the token. The site stays verified only if another proof still passes. If Cloudflare refuses a removal (for example because you already revoked the token), the app tells you which item to delete in Cloudflare yourself.

Deleting the site removes the rule and record first. If that fails, the delete is refused with `409 cloudflare_connected`, so a skip rule is never left behind unmanaged.

## Do it myself (no API token)

Choose **Do it myself (no API token)** (or **Prefer not to share a token? Do it yourself**). The app lists the same two changes as steps.

### Step 1: Prove you own the domain

In Cloudflare, open your zone → DNS → Records → Add record:

| Name | Type | Value | TTL |
|---|---|---|---|
| `@` (your registrable domain) | TXT | `seofix-verify=<verification token>` | Auto |

Skip this step if the site is already verified another way. While the record is on screen, the card checks for it every 2 minutes for 60 minutes.

### Step 2: Let SEOFixBot through your firewall

1. Open Security → WAF → Custom rules for your zone and choose **Create rule**. **Open (zone)'s WAF rules** links there.
2. Name it **SEOFix crawler**, choose **Edit expression** and paste the expression. Use the copy button: the expression holds your crawler secret, which the page fetches only when you choose *Reveal* or *Copy*.

   ```text
   any(http.request.headers["x-seofix-verify"][*] eq "<crawler secret>")
   ```

3. Set the action to **Skip** and tick every item:
   - All remaining custom rules
   - All managed rules
   - All Super Bot Fight Mode rules (Pro plan and above; leave it out if it isn't offered)
   - Under "More components to skip": Browser Integrity Check, Security Level, User Agent Blocking, Hotlink Protection, Zone Lockdown
4. Place the rule **First**, then Deploy.

Leave rate limiting rules alone: SEOFixBot slows down instead.

### Step 3: Check that it works

Choose **Check my setup**. SEOFix looks up the TXT record and loads your start page twice as SEOFixBot, with and without the secret header. Each step shows **Passed**, **Needs attention** or **Note** with a hint. What the firewall results mean: [Let SEOFix through your firewall](https://seofix.ai/help/firewall-allowlisting.md#check-your-rule).

## Bot Fight Mode on the Free plan

On Cloudflare's Free plan, Bot Fight Mode cannot be skipped by any rule. If audits still show blocked pages after the rule is in place, turn Bot Fight Mode off while audits run.

## The crawler secret

- SEOFixBot sends the crawler secret only after the site is verified, only over HTTPS, and only to your site's host and its `www` / bare-domain twin.
- **Rotate secret** (next to the secret on the site page) issues a new value. With an automatic connection, SEOFix updates the Cloudflare rule in place. With a hand-built rule, paste the new expression right away, or audits (including one already running) may hit challenges.
- Keep it private: don't publish it or put it in your site's code.

## Related

- [Let SEOFix through your firewall](https://seofix.ai/help/firewall-allowlisting.md)
- [Blocked pages in your report](https://seofix.ai/help/blocked-pages.md)
- [Verify site ownership](https://seofix.ai/help/verifying-site-ownership.md)
