Skip to main content
Connect the Cloudflare WAF so Myrmex can review your zone custom rules, rate limiting, managed rulesets, IP Lists, and Security Events — and, with approval, help you manage them. Myrmex reaches the Cloudflare API through a Collector on your network, querying it in real time.

What Myrmex Can Do

Rules & rate limiting

Review zone custom rules and rate limiting, and propose adjustments.

Managed rulesets

Inspect deployed managed rulesets and their configuration.

IP Lists

Review account IP Lists used across your rules.

Security Events

Query Security Events during investigations, in real time.

Before You Start

  • A Collector that can reach the Cloudflare API (https://api.cloudflare.com) over HTTPS. See Deploying the agent.
  • Your Cloudflare Zone ID (for zone WAF rules and events) and Account ID (for IP Lists and managed rulesets).
  • Permission to create an API token.

Step 1 — Create the API Token in Cloudflare

The credential Myrmex needs is an API token, used as a Bearer token, with WAF permissions.
1

Open API Tokens

In the Cloudflare dashboard, go to My Profile → API Tokens → Create Token, and start a custom token.
2

Grant WAF permissions

Add Zone → Zone WAF and Zone → Firewall Services (for custom rules, rate limiting, and Security Events), plus account-level permissions for IP Lists and managed rulesets — read-only for analysis, edit to allow changes.
3

Create and copy the token

Finish creating the token and copy it now — it is shown only once.
4

Find your Zone ID and Account ID

The Zone ID is on the zone’s overview page; the Account ID is on your account home page.
Prefer least privilege: grant read-only permissions first, and add edit scopes only when you want the agents to apply changes.

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → Cloudflare WAF, then fill in:

Connect

Click Connect to validate the token and finish. The Cloudflare WAF then appears under Environment → Integrations, and you can start asking Hydra about it in the Workspace.
Your API token is stored securely and resolved server-side — it never passes through the AI, and Myrmex queries Cloudflare on demand rather than storing its data.