Skip to main content

Cloudflare Zero Trust

Cloudflare Zero Trust connects your WARP-enrolled device inventory and Access user directory into Navigator.

At a glance

Data providedDevices, Users
AuthenticationAPI Token
Where to configureConnectors → Add a Connector → Cloudflare Zero Trust

Required permissions

Create an API Token (not the legacy Global API Key) with these permissions:

PermissionWhy it’s needed
Zero Trust ReadRead WARP-enrolled device inventory
Access: Users ReadRead Zero Trust Access user accounts
Zero Trust: PII ReadRead personal fields (name, email) attached to devices and users

You’ll also need your Cloudflare Account ID, found on your Account Home page in the Cloudflare dashboard.

Setup

  1. In the Cloudflare dashboard, go to My Profile → API Tokens → Create Token and create a custom token with the permissions listed above.
  2. Copy the token value. Cloudflare only shows it once.
  3. Find your Account ID on the Account Home page (or under Workers & Pages → Account details).
  4. In Navigator, go to Connectors → Add a Connector → Cloudflare Zero Trust.
  5. Enter your Account ID and API Token.
  6. Save. Navigator validates the credentials and enqueues a first sync immediately.

Vendor documentation

Cloudflare’s own instructions: Create an API token.

What data this connector provides

  • Devices: every device enrolled in your WARP client fleet, including hostname, operating system, serial number, manufacturer, model, MAC address, and the most recently signed-in user.
  • Users: your Zero Trust Access user directory, including email and name.

Every device reported by this connector is treated as having agent-based coverage, since being enrolled in Zero Trust at all requires the WARP client to be installed.

Known limitations

  • No internal or external network IP address is currently populated for devices. Cloudflare’s device inventory reports the device’s WARP tunnel address, not its real network address, so this connector doesn’t map it to avoid showing a misleading value.
  • Disk encryption status isn’t available for devices.
  • Group membership, MFA status, and admin role aren’t available for Zero Trust users. Cloudflare’s Access user directory doesn’t expose these fields today.
  • This connector was built from Cloudflare’s published API reference rather than tested against a live account. If you notice a field that looks wrong or missing, let us know so it can be corrected against real data.