- Overview
- How to connect
- Automated checks
- Useful links
DSALTA connects to Cloudflare using read-only API access to collect compliance evidence automatically. Data feeds into your Data Library modules. Compliance checks re-run once a day at 02:00 America/New_York.
Read-only access. DSALTA never modifies, creates, or deletes resources in your Cloudflare environment.
What DSALTA reads
DSALTA reads the Cloudflare user roster — names, emails, roles, active status and each member’s two-factor status (Yes, No, or Unknown), which appears on your Access page; and your Cloudflare resources — zones, KV namespaces, R2 buckets and Worker scripts — which appear on your Inventory page.It calls these Cloudflare endpoints:/user/tokens/verify/accounts/accounts/{accountId}/members/accounts/{accountId}/storage/kv/namespaces/accounts/{accountId}/r2/buckets/accounts/{accountId}/workers/scripts/zones/zones/{zoneId}/settings/{setting}
Account:Read, SSL and Certificates:Read and Zone:Read. These three cover the compliance checks. To populate the Inventory page as well, build the token from Cloudflare’s Read all resources template, which adds the separate read permissions that Workers KV namespaces, R2 buckets and Worker scripts each require.Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Cloudflare environment.Troubleshooting
Integration shows Disconnected
Integration shows Disconnected
There is no Reconnect button. Open Integrations → Connected, click Manage on the Cloudflare card, and check the Status tab — it shows either Connected and working properly or Connection issues detected. To restore a broken connection you must Disconnect and connect again, which permanently deletes the data and tests collected from Cloudflare. This usually happens when API tokens expire.
Data is not syncing
Data is not syncing
Verify the connected account still holds the permissions listed under Before you begin. Then open Integrations in the DSALTA sidebar, stay on the Connected tab, and click Sync from integrations at the top right. That button refreshes every connected integration at once — there is no per-integration sync control.
.png?fit=max&auto=format&n=tsMQJyneJ1xquFUo&q=85&s=4d401cc03b547d99b6f75a6bd170c334)