Connect Cloudflare
Watch Cloudflare Pages deployments, Worker errors and your zones.
- You need
- Custom API token, Read only My Profile › API Tokens dash.cloudflare.com
- The form asks
-
- Connector name
- API token
- You can watch
-
- Failed Pages deployments
- Worker errors
- Zone problems
- Access
- GET requests and GraphQL analytics queries only, with a token of Read permissions
On this page
CoIsland calls Cloudflare’s API straight from your Mac: there is no CoIsland server and no CoIsland account. The token stays in your login Keychain. Every request is a GET, except Worker errors, which are read with a query to the GraphQL Analytics API.
Create a Cloudflare API token
Use an API token, never the Global API Key.
- In the dashboard, open My Profile › API Tokens (
dash.cloudflare.com/profile/api-tokens) and click Create Token, then Create Custom Token. - Permissions, all Read, for what you will watch:
| Monitor | Permission |
|---|---|
| Failed Pages deployments | Account › Cloudflare Pages › Read |
| Worker errors | Account › Account Analytics › Read (Account › Workers Scripts › Read fills the Worker picker) |
| Zone problems | Zone › Zone › Read |
- Account Resources and Zone Resources: the account and zones to watch.
- Optionally an IP filter and a TTL, then Continue to summary and Create Token. Copy it: Cloudflare shows it only once.
Any member can create a user API token, but not one that exceeds their role: a read-only role gives a read-only token, and a role without Pages cannot read Pages. On Enterprise, a Super Administrator can turn off API access for the account or for you. Account API tokens need a Super Administrator to create, so CoIsland asks for your own.
Connect Cloudflare in CoIsland
| Field | What to enter |
|---|---|
| Connector name | What monitors call it. CoIsland suggests cloudflare |
| API token | The token you copied |
Test connector calls GET /client/v4/user/tokens/verify and GET /client/v4/accounts, and shows that the token is active, its expiry and the accounts it reads.
Watch Cloudflare: the three monitor kinds
| Kind | What alerts | What CoIsland calls |
|---|---|---|
| Failed Pages deployments | A deployment of the last 7 days whose latest stage failed | GET /accounts/{account}/pages/projects/{project}/deployments, the latest 25 per project |
| Worker errors | A Worker with at least the errors you set (1 unless you choose) in the window (15 minutes unless you choose, from 5 minutes to 24 hours) | POST /client/v4/graphql, workersInvocationsAdaptive summed by script |
| Zone problems | A zone paused, pending its nameservers, moved or deactivated | GET /client/v4/zones, 50 a page |
account:023e105f4ecef8ad9ca31a8372d0c353 project:web env:production branch:main
account:023e105f4ecef8ad9ca31a8372d0c353 script:api errors:50 window:1h
account:all
account:is the account’s ID, as the pickers fill it;account:allwatches every zone the token reads.- A Worker alerts when it starts throwing errors, and again after a quiet window.
- A retried deployment is a new one; a fixed zone leaves the result.
Clicking a row in the notch opens the alert in CoIsland: a failed deployment with its failing stage, every stage, branch, commit and the last 100 lines of its build log; a Worker with its errors and requests in the window; a zone with its status, its nameservers while pending, or “Active” once fixed. Open in Cloudflare goes to the deployment, the Workers list or the zone.
A Cloudflare monitor’s -- kind: is cloudflare.pages, cloudflare.workers or cloudflare.zones.
Troubleshooting Cloudflare connector errors
- “The API token was refused.” Cloudflare answered code 1000 “Invalid API Token”, 9109 “Invalid access token” or 6003 “Invalid request headers”: the token is wrong, expired or disabled, or it is the Global API Key.
- “Pages project web (needs Cloudflare Pages: Read): not allowed.” The token lacks the permission, or your role does not include it.
- “Workers analytics (needs Account Analytics: Read): not allowed.” The analytics query was refused for that account.
- “Rate limited.” Cloudflare allows 1,200 requests every 5 minutes per user, and about 300 analytics queries every 5 minutes; CoIsland waits, then retries.
Frequently asked questions
Why not the Workers logs?
Worker errors come from Workers Analytics, which counts every Worker’s errors without turning on logs. Reading exception messages needs Workers Observability, whose query API asks for a write permission; CoIsland does not ask for one.
Stuck? Open an issue on GitHub, or write to hello@coisland.app.