# **🔍 Overview**

When connecting OTTO SEO to your site via Cloudflare, the diagnostics tool may show validation errors even when your API token permissions and worker routes appear to be set up correctly. This article walks you through the exact fixes a support agent used to resolve this, so you can self-serve without waiting for help.

# **⚠️ The Most Common Cause: Incorrect Zone-DNS Permission**

A frequent source of validation failure is a misconfigured Cloudflare API token permission. Specifically, the **Zone - DNS** permission must be set to **Edit**, not **Read**.

To fix this in Cloudflare:

1. Log in to your Cloudflare dashboard.
2. Navigate to **My Profile → API Tokens**.
3. Find the API token you created for OTTO and click **Edit**.
4. Locate the **Zone - DNS** permission row.
5. Change the permission level from **Read** to **Edit**.
6. Save your changes.

This single change resolves a large proportion of validation failures. After saving, move on to the next step.

# **🔄 Re-Engage the OTTO Worker After Fixing Permissions**

Once the API token is corrected, you must re-engage the OTTO worker inside the platform for the changes to take effect. Validation errors will persist if the worker is not refreshed after updating your Cloudflare credentials.

1. Go to **Left sidebar → OTTO SEO → Overview** in Search Atlas.
2. Use the **Engage OTTO** action available on that page to re-initiate the worker connection.
3. Allow a few moments for the process to complete, then re-run diagnostics to check whether the validation errors have cleared.

In most cases, correcting the Zone-DNS permission to **Edit** and then re-engaging the worker will fully resolve the issue.

# **🚫 Excluding Click-Tracking from the Worker (If Applicable)**

If your setup involves click-tracking scripts or third-party analytics that conflict with the Cloudflare worker, you may need to configure an exclusion on the Cloudflare side. Your support agent can provide specific instructions tailored to your worker route configuration if this applies to your situation.

# **🐛 Known Issue: Diagnostics Tool May Still Show Errors After a Correct Setup**

In some cases, the OTTO diagnostics tool itself may report errors even when the worker is correctly installed and functioning. This is a known bug that has been escalated to the engineering team. If you have followed all the steps above and your site appears to be working correctly, the remaining diagnostic error may be a display issue rather than a real configuration problem.

The engineering team is actively working on improvements to the diagnostics tool, including per-check results with detailed reason codes and version tracking for the Cloudflare worker. These updates will make it easier to pinpoint the exact cause of any failure in the future.

# **✅ Summary Checklist**

- **Zone - DNS permission is set to Edit** (not Read) in your Cloudflare API token.
- **Worker routes are correctly configured** in Cloudflare for your domain.
- **OTTO worker has been re-engaged** via Left sidebar → OTTO SEO → Overview after any credential changes.
- **Click-tracking exclusions** are in place if your setup requires them.
- If diagnostics still show an error but your site is functioning, **this may be a known display bug** — see the note above.

# **💬 Still Need Help?**

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type **human teammate** to be connected with a member of our team.