SECOPS

Cloudflare API Token Creation Watchdog

Watches the Cloudflare audit log for new API token and service-token creation, archives the full event to S3 for compliance.

CategorySecOps
Enginesim
Difficultyintermediate
Triggerschedule
Steps6
Setup~15 min

How it runs

The automated pipeline, trigger to output.

  • TriggerEvery 10 minutes, poll Cloudflare audit logCloudflareCloudflare
  • LogicKeep only API/service token creation actions
  • ActionArchive full event to S3 for complianceAWS S3
  • LogicFlag broad scopes or unapproved issuer
  • ActionOpen Linear ticket per flagged tokenLinearLinear
  • OutputReturn archive keys and ticket IDs

What it does

Focuses specifically on credential creation — new API tokens and service tokens are a favorite persistence mechanism for attackers. Every token-creation event is archived to S3 for your compliance trail, then evaluated: if the token was minted with broad or write scopes, or by an actor not on the approved token-issuer list, the workflow opens a Linear review ticket so secops can verify and, if needed, revoke it.

When to use it

Use this when you need an audit-grade record of who created which Cloudflare credentials and want to be alerted immediately to over-scoped or unexpected token grants.

How it works

  1. 1A schedule polls the Cloudflare audit log every 10 minutes for new entries.
  2. 2A filter keeps only API-token and service-token creation actions.
  3. 3An action writes each full token-creation event to an S3 bucket as an immutable compliance record.
  4. 4A logic step flags tokens with broad/write scopes or an unapproved issuing actor.
  5. 5An action opens a Linear ticket for each flagged token with scope details and a revoke checklist.
  6. 6The archived object keys and ticket IDs are returned as output.

Set it up

What you configure once, before turning it on.

  1. 1
    Connect CloudflareWorkers, Pages, R2, KV — the edge stack.
  2. 2
    Connect AWS S3Buckets, objects, signed URLs.
  3. 3
    Connect LinearIssues, projects, cycles, triage.
  4. 4
    Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
  5. 5
    Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
  6. 6
    Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.

Run this workflow in your colony.

14-day trial. No DevOps. No Sales call. Provisioned in under a minute.