Data Connections

Connecting a Cloudflare account

Connect your Cloudflare account to DigiUsher with an Account ID and a read-only Billing API token to track usage-based spend across Cloudflare products.

Overview

To connect your Cloudflare account to DigiUsher, create an API token with the Billing: Read permission in the Cloudflare dashboard. Then enter that token and the Account ID in DigiUsher. This page gives the access that DigiUsher asks for, the reason for that access, and the credentials that you enter.

Self-serve Cloudflare accounts only

You need a Cloudflare self-serve account. DigiUsher does not support a Cloudflare Enterprise contract account. With an Enterprise contract, you cannot use this integration at this time.


Summary of Access Required

ComponentDetails
IdentityCloudflare API Token, read-only, for programmatic access only
Access levelRead-only. Billing and usage data at the level of the account
DataDaily billable usage per product per billing period
ScopeA single Cloudflare account (identified by Account ID)
CapabilityWhat It Provides
Spend by productWorkers, R2, D1, Workers AI, Vectorize, Images, Stream, and others
Usage quantitiesRequests, duration, storage, and bandwidth (product-dependent)
Credit rowsNegative-value rows captured as credits

DigiUsher cannot send traffic, cannot change DNS records or zones, and cannot change any part of your Cloudflare configuration.


Prerequisites

Information to Gather

ItemHow to FindDigiUsher Field
Account IDIn the Cloudflare dashboard, open the Overview page of the account. The Account ID is in the right sidebar.account_id
API TokenCloudflare dashboard → Manage Account → API Tokens → Create Token → Custom token → Permission: Account > Billing > Read → add your account under Account Resources. The page shows the token one time only, so save it in a safe place.api_token

Roles Required by the Person Performing Setup

Role / PermissionWhy
Account Administrator or Super AdministratorOnly these roles can create API tokens on a Cloudflare account.

Network & Email Access (For Regulated Environments)

If your organization restricts outbound internet access or email domains, make sure that these two items are in place before you start:

  • Domain allowlist. Add *.digiusher.com to the allowlist of your network and your firewall. The users of your organization can then open the DigiUsher platform in their browsers.
  • Email allowlist. Add digiusher.com as a permitted sender domain in your email security gateway. DigiUsher sends onboarding confirmations, alerts, and reports from @digiusher.com addresses.

Setup

Create an API Token

Create a separate API token for DigiUsher, with a limited scope.

  1. In the Cloudflare dashboard, open Manage Account → API Tokens.

    Cloudflare Account API Tokens page

  2. Click Create Token, then select Custom token.

  3. Give the token a name that you know again, for example digiusher-billing-read.

  4. Under Permissions, add Account → Billing → Read. Do not select Edit. Read is the minimum permission, and it is sufficient.

    Billing Read scope selected

  5. Under Account Resources, select Include → Specific account → <your account>, or Include → All accounts.

  6. For more security, you can set an expiration date or an IP address filter.

    Select key name and expiration

  7. Click Continue to summary, then Create Token.

  8. On the confirmation page, copy the API token. It starts with cfat_.

    Copy and save the token

Save your credential

CAUTION: Copy the API token now and save it in a safe place. The page shows the token one time only, and you cannot read it again. You enter this token in DigiUsher in the next section.

Collect the Account ID

In the Cloudflare dashboard, open the Overview page of the account that you want to connect. Copy the Account ID from the right sidebar.

Before you continue, make sure that you have these two values:

  • The Account ID of the account that you want to connect. This value is not the token, and it has no cfat_ prefix.
  • The API token, which starts with cfat_, with the permission Account > Billing > Read.

Connect in DigiUsher

In DigiUsher, go to Connectors > Add Source and select Cloudflare. On the Configure step, enter the values in the table. Then go to Connect and click Connect source:

FieldWhere to Find
Display NameAny label you prefer, for example Cloudflare Production
API TokenThe cfat_... token from Step 1
Account IDFrom Step 2

At the connection, DigiUsher makes sure that the token works with your account, and starts to import the billing data. The first sync covers three calendar months: the current month and the two months before it. This is approximately 85 days, and it is the full period that the billable-usage API of Cloudflare keeps. Every sync after the first one reads the last 40 days again, because Cloudflare changes the usage values until it finalizes them.


Setup Checklist

  • Paid Cloudflare self-serve account (an Enterprise contract does not work)
  • Account Administrator or Super Administrator role
  • Account ID found and copied
  • API token created with Account > Billing > Read, and not with Edit
  • API token saved in a safe place
  • Account ID and API token entered in DigiUsher
  • *.digiusher.com in the allowlist of your network and firewall (if your organization restricts this)
  • digiusher.com in the allowlist of permitted sender domains in your email security gateway (if your organization restricts this)

Security

What DigiUsher CAN Access (Read-Only)

  • Billable usage data for each product and each billing period
  • Usage quantities for each product: requests, storage, bandwidth, and duration

What DigiUsher CANNOT Do

  • Send traffic, or change a DNS record, a zone, a Worker, or any other Cloudflare resource
  • Create, rotate, or delete an API token
  • Read log content, request payloads, or personal data of users
  • Read or change the payment methods, the plan configuration, or the billing contacts
  • Buy a product or change your account

Monitoring

Open Manage Account → API Tokens to see the tokens that exist and the last time each token was used. Delete every token that you do not know.

Review API tokens list

Credential Rotation

  1. In the Cloudflare dashboard, create a new API token with Account > Billing > Read.
  2. Enter the new token in DigiUsher immediately.
  3. Delete the old token in the Cloudflare dashboard.

Avoid ingestion gaps

Create the new token and enter it in DigiUsher before you delete the old token. This prevents an interruption of the data collection.

Revocation

Delete the API token at Manage Account → API Tokens. Cloudflare then immediately invalidates the token and stops all access. DigiUsher cannot read billing data again until you give it a new token.


Troubleshooting

403 / invalid token

Make sure that the token has the permission Account > Billing > Read. Edit does not work, and another permission category does not work. Create the token again in the Cloudflare dashboard and enter it again in DigiUsher.

Account ID not recognized

Make sure that you copied the Account ID, and not a Zone ID. A Zone ID looks similar, but it belongs to one domain. The Account ID is in the right sidebar of the Overview page of the account, in the Cloudflare dashboard.

No billing data or incomplete data

Cloudflare finalizes the billing data for each billing period. The usage in the middle of a period can therefore be absent. Every sync reads the last 40 days again, so the values of those days change when Cloudflare finalizes them. Cloudflare keeps the data for approximately 90 days, and DigiUsher cannot read data from an earlier date.

Token restricted by IP filter

If you set an IP address filter on the token, make sure that the filter contains the egress IP addresses of DigiUsher. Write to DigiUsher support for the current list of egress IP addresses.


Need Help?

If this page does not answer your question, write to DigiUsher support at support@digiusher.com. The team will help you.

On this page