Skip to main content
Connect Cloudflare One (Zero Trust) so Myrmex can review your Gateway policies and lists, Access apps and policies, enrolled devices, and logs — and, with approval, help you manage them. Myrmex reaches the Cloudflare API through a Collector on your network, querying it in real time.

What Myrmex Can Do

Gateway policies & lists

Review Zero Trust Gateway policies and lists — read and, on approval, adjust.

Access apps & policies

Inspect Access applications and their policies for gaps and overly broad rules.

Devices & logs

Review enrolled devices and query logs during investigations, in real time.

Posture audit

Run a Security Posture audit against your Zero Trust configuration.

Before You Start

  • A Collector that can reach the Cloudflare API (https://api.cloudflare.com) over HTTPS. See Deploying the agent.
  • Your Cloudflare Account ID.
  • Permission to create an API token on the account.

Step 1 — Create the API Token in Cloudflare

The credential Myrmex needs is an account-scoped API token, used as a Bearer token.
1

Open API Tokens

In the Cloudflare dashboard, go to My Profile → API Tokens → Create Token, and start a custom token.
2

Grant Zero Trust permissions

Add account-scoped permissions for Zero Trust (Gateway), Access: Apps and Policies, and read access to devices and logs — read-only for analysis, edit to allow changes.
3

Create and copy the token

Finish creating the token and copy it now — it is shown only once.
4

Find your Account ID

In the dashboard, open your account; the Account ID is listed on the account home page.
Prefer least privilege: grant read-only permissions first, and add edit scopes only when you want the agents to apply changes.

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → Cloudflare One, then fill in:

Connect

Click Connect to validate the token and finish. Cloudflare One then appears under Environment → Integrations, and you can start asking Hydra about it in the Workspace.
Your API token is stored securely and resolved server-side — it never passes through the AI, and Myrmex queries Cloudflare on demand rather than storing its data.