Cloud · Secret guide

Leaked Cloudflare API Token / Key: what to do in the first hour

High severityDetected onlyLast verified · 5 min read

A Cloudflare credential can be as small as a token that edits DNS for one zone, or as large as a key that acts as the whole account. Either way, the target is the same: your domain. Someone who can change DNS records can send visitors and email to a server they control, and someone who can edit rules or Workers can intercept traffic without touching your origin. Find out which kind of credential leaked, replace it, and then review the zone.

Check your GitHub account for leaked secrets — free

Provider
Cloudflare
Severity
High
Impact
Cloud infrastructure access
Checked live by LeakWatch
No

What a Cloudflare API credential looks like

Cloudflare has several credentials that are easy to mix up:

<40 characters>   scoped API token, sent as a Bearer header (masked)
<37 hex>          legacy Global API Key, used with X-Auth-Email (masked)
v1.0-…XXXX        Origin CA key (masked)

An API token is the modern credential: you choose its permissions and the zones it applies to, and you can set an expiry. The Global API Key is the legacy credential and acts with the full authority of your account, which is why Cloudflare discourages it. An Origin CA key is used to issue certificates for the connection between Cloudflare and your server. A Zone ID or Account ID is an identifier, not a secret.

None of these has a distinctive prefix, so they are recognized by the code around them, which is covered below.

How Cloudflare credentials get leaked

  • Infrastructure as code. A token in a Terraform provider block, a Pulumi config or an Ansible variable file.
  • DNS automation. ACME clients, dynamic-DNS scripts and certificate tools keep a token in a config file to prove domain ownership.
  • Worker and CI configuration. A wrangler environment file or a deployment workflow that exposes the token to the build.
  • Shell history and curl examples. Commands with X-Auth-Key or an Authorization header pasted into issues, wikis and chat.
  • Dotfiles and backups. A home directory or server backup published with its configuration.

What to do in the first hour

  1. Identify what leaked. A scoped API token, the Global API Key and an Origin CA key are rotated in different places. Check the variable name and header around the value in the file you found: Bearer means a scoped token, X-Auth-Key means the Global API Key.
  2. Roll or delete it. In the Cloudflare dashboard open My Profile → API Tokens. For a scoped token, use Roll to issue a new secret or delete the token. For the Global API Key, use the API Keys section to roll it, since viewing it requires your password.
  3. Replace it with a narrow token. Create a new API token limited to one permission group and one zone, ideally with an IP restriction and an expiry. Do not create another Global API Key.
  4. Review DNS. Compare every record in every zone with your expectations. Look for changed A, AAAA and CNAME targets, new MX and TXT records (email hijack and domain verification), and records that point at addresses you do not own.
  5. Review rules, Workers and access. Check redirect and transform rules, Page Rules, Workers routes and scripts, firewall rules, and Zero Trust settings. Look at the account’s members, other API tokens and recent logins.
  6. Read the audit log. In the account’s audit log filter by the period since the exposure and look for actions made with an API token or key.

Not sure what else leaked? Run a free scan.

  1. Then clean the repository: remove the value and rewrite history if you want to. See I accidentally pushed an API key to GitHub.

If the account supports it, enable two-factor authentication, since rolling the Global API Key does nothing about a stolen password.

Not sure what else leaked? Run a free scan.

Revoke it at Cloudflare

Sign in to the Cloudflare dashboard, open your profile menu and choose My Profile, then API Tokens. Scoped tokens are listed there with their permissions and expiry; roll the exposed one, which gives it a new secret and invalidates the old, or delete it. The Global API Key appears in the same page’s keys section behind a View action that asks for your password, and it can be rolled there. Origin CA keys have their own entry in that section. Tokens are tied to the user who created them, so a colleague’s token must be rolled from their own account.

How LeakWatch detects it

This type is matched by context, not by a prefix. The Cloudflare API Key rule looks for the word “cloudflare” near an assignment and then a 40-character value, while a companion rule looks for a 37-character hexadecimal key next to “cloudflare” or the X-Auth-Key header. That makes it good at catching a credential in a config file and blind to one stored under a generic name such as API_KEY with no Cloudflare mention. LeakWatch detects this format but does not check it live: it can tell you the credential is exposed, not whether it still works. Assume it does until you have revoked it.

LeakWatch detects this format but does not check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

FAQ

What is the difference between a token and the Global API Key?

A token has limited permissions and zones that you choose, and can be revoked on its own. The Global API Key has your full account authority and is tied to your login. If you are unsure which leaked, treat it as the Global one.

Can someone hijack my domain with a DNS token?

They can redirect traffic and email for the zones the token covers, which is serious but not a transfer of registration. Review DNS now and consider locking the domain at your registrar.

The key was in a repository I deleted. Am I safe?

No. Deleting the repository does not undo copies already taken. Roll the credential and review the zone regardless.

Get alerted next time a secret leaks — create a free account

LeakWatch is not affiliated with Cloudflare.