π Overview
When installing OTTO via Cloudflare, it is essential to use an account-level API token β not a personal API token. Using a personal token may show a "Connected" status in Search Atlas, but OTTO will not complete installation on your site. This article walks you through creating the correct token so your OTTO installation works immediately.
β οΈ Why Personal API Tokens Do Not Work
Cloudflare offers two types of API tokens:
- Personal API tokens β scoped to individual user profiles and found at dash.cloudflare.com/profile/api-tokens. These do not grant the account-level permissions required for OTTO to deploy its worker scripts.
- Account-level API tokens β created from within your Cloudflare account dashboard. These provide the necessary permissions for worker creation and script deployment, which OTTO requires to install correctly.
Even though Search Atlas may display "Connected" with a personal token, the underlying worker deployment will silently fail. Always use an account-level token to ensure full functionality.
π οΈ How to Create a Cloudflare Account-Level API Token
- Log in to your Cloudflare account at dash.cloudflare.com.
- From the top navigation, select the account you want to connect to OTTO (not your user profile).
- In the left sidebar, click Manage Account, then select API Tokens.
- Click Create Token.
- Choose Create Custom Token to configure the required permissions manually.
- Under Permissions, add the following:
- Account β Workers Scripts β Edit
- Account β Workers Routes β Edit
- Zone β Zone β Read
- Zone β DNS β Edit
- Under Account Resources, set the token to apply to your specific account.
- Under Zone Resources, select All zones or the specific zone (domain) where OTTO will be installed.
- Click Continue to Summary, review your settings, then click Create Token.
- Copy the generated token immediately β Cloudflare will only display it once.
π How to Connect the Token in Search Atlas
- In Search Atlas, navigate to Left sidebar β OTTO SEO.
- Open or create the OTTO project for your domain.
- When prompted for your Cloudflare credentials, paste the account-level API token you just created.
- Complete the connection flow. Search Atlas should display "Connected" and OTTO should begin installing on your site immediately.
β How to Confirm OTTO Installed Successfully
After connecting with the correct token, verify the installation was successful by checking the following:
- The OTTO status in your project shows as Active (visible under Left sidebar β OTTO SEO).
- The Cloudflare Workers section of your account shows a new worker script deployed by OTTO.
- Your website loads correctly with no disruption to DNS or page performance.
π‘ Common Mistakes to Avoid
- Using a personal API token β always create the token from the account dashboard, not your user profile page.
- Missing permissions β ensure all four permission sets (Workers Scripts, Workers Routes, Zone Read, DNS Edit) are included. Missing any one of them can prevent deployment.
- Wrong zone scope β if the token is scoped to the wrong zone, OTTO cannot access your domain. Double-check the zone resources during token creation.
- Token copied incorrectly β the token is shown only once. If you missed copying it, delete it and generate a new one.
π¬ Need Help?
If you need further assistance, open the chat widget in the bottom-right corner of the platform and type human teammate to be instantly connected with a member of our team.