When you authorize a third-party OAuth application, you grant it permission to access specific Cloudflare resources on your behalf. Cloudflare provides tools to view, manage, and revoke these authorizations at any time.
When a third-party application requests access to your Cloudflare account, you will see a consent screen that displays:
- Application name and logo: The name and branding of the requesting application
- Publisher domain: The domain and verification status of the application publisher
- Account selection: Choose which Cloudflare account(s) the application can access
- Requested permissions: After selecting the account(s) the application may access, the specific scopes the application is requesting will be displayed before consent is complete. To finish the authorization process, review the permissions the application is requesting and click “Authorize”
Each shield icon indicates who owns the application and whether its domain ownership is verified:
- Green filled shield: Cloudflare owns and manages the application.
- Blue outlined shield: A third-party application with verified ownership of its domain.
- Amber filled shield: A third-party application without verified ownership of a domain.
Domain verification only confirms that the application owner controls the displayed domain.
Application authorizations may be viewed and revoked at any time from the profile page on the Cloudflare dashboard.
- Log in to the Cloudflare dashboard.
- Go to Manage OAuth authorizations ↗
- View the list of applications you have authorized.
- If you wish to revoke access to an application, click the “Revoke” button for that row
If an account is not available for selection during the consent flow, it may be due to an administrator of that account disabling access to account resources via OAuth.
Account administrators can restrict OAuth applications from accessing account resources via Manage Account > Members > Settings > Public OAuth App access.