INTEGRITY Documentation

Authorizing an application

Overview

When you authorize a third-party OAuth application, you grant it permission to access specific Cloudflare resources on your behalf. Cloudflare provides tools to view, manage, and revoke these authorizations at any time.

Authorize a third-party application

When a third-party application requests access to your Cloudflare account, you will see a consent screen that displays:

Each shield icon indicates who owns the application and whether its domain ownership is verified:

Domain verification only confirms that the application owner controls the displayed domain.

Edit optional permissions

All requested permissions are selected by default. You can turn off optional permissions, but required permissions remain selected. Select Read only to include only optional scopes with read access, or Full access to include all optional scopes. If the client has no permissions configured as optional, editing controls do not appear.

  1. In Additional access, select Edit Permissions.
  2. Turn permissions on or off individually or by category.
  3. Select Authorize to grant required and selected optional permissions.

View and revoke authorized applications

Application authorizations may be viewed and revoked at any time from the profile page on the Cloudflare dashboard.

  1. Log in to the Cloudflare dashboard.
  2. Go to Manage OAuth authorizations ↗
  3. View the list of applications you have authorized.
    • If you wish to revoke access to an application, select the “Revoke” button for that row

Account administrator controls

If an account is not available for selection during the consent flow, it may be due to an administrator of that account disabling access to account resources via OAuth.

Account administrators can restrict OAuth applications from accessing account resources via Manage Account > Members > Settings > Public OAuth App access.