Cloudflare Zero Trust
Cloudflare Zero Trust connects your WARP-enrolled device inventory and Access user directory into Navigator.
At a glance
| Data provided | Devices, Users |
|---|---|
| Authentication | API Token |
| Where to configure | Connectors → Add a Connector → Cloudflare Zero Trust |
Required permissions
Create an API Token (not the legacy Global API Key) with these permissions:
| Permission | Why it’s needed |
|---|---|
| Zero Trust Read | Read WARP-enrolled device inventory |
| Access: Users Read | Read Zero Trust Access user accounts |
| Zero Trust: PII Read | Read personal fields (name, email) attached to devices and users |
You’ll also need your Cloudflare Account ID, found on your Account Home page in the Cloudflare dashboard.
Setup
- In the Cloudflare dashboard, go to My Profile → API Tokens → Create Token and create a custom token with the permissions listed above.
- Copy the token value. Cloudflare only shows it once.
- Find your Account ID on the Account Home page (or under Workers & Pages → Account details).
- In Navigator, go to Connectors → Add a Connector → Cloudflare Zero Trust.
- Enter your Account ID and API Token.
- Save. Navigator validates the credentials and enqueues a first sync immediately.
Vendor documentation
Cloudflare’s own instructions: Create an API token.
What data this connector provides
- Devices: every device enrolled in your WARP client fleet, including hostname, operating system, serial number, manufacturer, model, MAC address, and the most recently signed-in user.
- Users: your Zero Trust Access user directory, including email and name.
Every device reported by this connector is treated as having agent-based coverage, since being enrolled in Zero Trust at all requires the WARP client to be installed.
Known limitations
- No internal or external network IP address is currently populated for devices. Cloudflare’s device inventory reports the device’s WARP tunnel address, not its real network address, so this connector doesn’t map it to avoid showing a misleading value.
- Disk encryption status isn’t available for devices.
- Group membership, MFA status, and admin role aren’t available for Zero Trust users. Cloudflare’s Access user directory doesn’t expose these fields today.
- This connector was built from Cloudflare’s published API reference rather than tested against a live account. If you notice a field that looks wrong or missing, let us know so it can be corrected against real data.