## **🔍 Overview**

Search Atlas can connect to your Cloudflare account to automate DNS and Workers configuration for your sites. For this to work, you must supply a **Custom Token** with the correct permissions — not a Global API Key. This article explains the two methods for enabling site automation and how to get your Cloudflare API token set up correctly.

**Important:** Connecting Cloudflare and installing the OTTO script are two separate methods for enabling site automation. Read the section below to understand which one applies to your setup before you begin.

## **⚡ Cloudflare Connection vs. OTTO Script Installation**

Search Atlas offers two ways to activate automation on a site. You will only ever use one of them per site — not both.

- **Cloudflare API connection** — Use this if your domain's DNS is managed through Cloudflare. Search Atlas connects directly to Cloudflare using an API token to handle automation on your behalf.
- **OTTO script installation** — Use this if your site is *not* on Cloudflare, or if you prefer to manage deployment manually. You paste a JavaScript snippet into your site's `<head>` tag or through a plugin such as WPCode.

If you have already installed the OTTO script, you do not need to connect Cloudflare. If you connect Cloudflare, you do not need to install the OTTO script.

## **🔑 Use a Custom Token, Not a Global API Key**

Search Atlas requires a **Cloudflare Custom Token**. Global API Keys grant unrestricted account access and are not accepted. Always create a scoped Custom Token with only the permissions needed for Search Atlas.

## **🛠️ How to Create the Correct Cloudflare API Token**

To create an API token with the right permissions for Search Atlas, log in to your Cloudflare dashboard and navigate to the API Tokens section of your profile. From there, create a new **Custom Token** (rather than using a template or a Global API Key) and grant it only the permissions required for the Search Atlas integration — these typically relate to Zone and DNS management for the specific domain you are connecting.

If your token is being rejected by Search Atlas, the most common causes are:

- Using a Global API Key instead of a Custom Token
- The token's permissions are missing required access for the domain
- The token is scoped to the wrong account or zone

If you are unsure which permissions to grant, or if your token continues to be rejected after verifying the above, our support team can help you confirm the correct configuration for your account.

## **📋 What to Have Ready When Contacting Support**

If you need help resolving a token rejection or setting up your Cloudflare connection, please have the following ready before reaching out:

- The exact error message shown when connecting the token in Search Atlas
- The domain (zone) you are trying to connect
- Whether you are using a Custom Token or a Global API Key
- A screenshot of the token's permission settings (with the token value itself hidden)

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type **human teammate** to be connected with a member of our team.