# Change your Cloudflare zone from BetterShield

Raise your Cloudflare zone’s security level, carry sign-in lockouts to the edge and deploy the managed ruleset from BetterShield Ultra, each with a way back.

If your site is served through Cloudflare, **BetterShield › Ultra › Cloudflare** can make three changes to its zone. Each reads what is there first, so putting it back restores what was actually there. It is part of BetterShield Ultra and needs WordPress 7.0 or newer; on an older version, the tab says so.

## Connect a token

Ultra keeps no Cloudflare key of its own and has no field for one. WordPress holds the token.

1. Create an API token in your Cloudflare account.
2. On **Settings › Connectors**, add it under **Cloudflare**. The tab links there with **Add one on the Connectors screen** while no token is set. Or define `BETTERSHIELD_CLOUDFLARE_TOKEN` as a constant in wp-config.php, or as an environment variable on the server; either takes precedence over the stored token.
3. Open the **Cloudflare** tab. It says where the token comes from, checks it, finds the zone your site’s address belongs to, and shows **Connected, on the zone** followed by its name.

If Cloudflare refuses the token, or no zone matches the site’s address, the card quotes what Cloudflare said.

## What this site may change

The three controls wait until a zone has been found.

| Control | What it does | The way back |
|---|---|---|
| **Challenge every visitor** | **Raise the level** asks once more, then sets the zone to Cloudflare’s highest security level: every visitor, shoppers at checkout included, sees a short check before the page loads. The control then shows **Raised from here**. | **Put the level back** sets the level the zone was on before. |
| **Block a locked-out network at the edge** | With **Carry sign-in lockouts out to the edge** on, each sign-in lockout on this site is also applied at Cloudflare to that network, so its requests stop reaching the site. | The rule comes off when the lockout ends. **Remove this block** takes one off early, and turning the switch off takes them all off. |
| **Deploy the managed ruleset** | **Deploy it** asks once more, then adds Cloudflare’s managed ruleset to the zone’s firewall, running on every request after the rules already there. The control then shows **Deployed from here**. | **Put the rules back** restores exactly what was there, including no rules at all. |

> **Note:** A raised level makes real people wait a few seconds. Use it while someone is working through your sign-in, and put it back after.

## Lockouts at the edge

- The network is the /24 or /64 that **Protect › Login & Access** already counts by, never a full address.
- The rule Cloudflare applies is a challenge, a check a person can pass in a browser, not an outright refusal.
- A network an administrator of this site has signed in from, and the network of the request making the change, are never sent to the edge. The lockout on the site still stands.
- One rule covers a network, however many lockouts run inside it.
- Rules are sent from the next dashboard page, WP-CLI run or hourly task, never while a visitor waits.
- When **Pause sign-in after repeated failures** is off on **Login & Access**, there are no lockouts to carry: the switch shows **Paused**, and any rule still on the zone comes off at the next pass.

The card lists each network blocked from here, or says none is. If Cloudflare refused the last change, the card says so and quotes it.

## Safe mode and the record

- While safe mode is on, nothing new is sent to Cloudflare. Putting a change back still works.
- Every change and every put-back is in the activity log as **Network edge changed** and **Network edge change put back**. A rule Cloudflare refused is logged too.
- Deactivating Ultra puts back the changes it made to the zone, where it can.

## Good to know

- A change already running on the zone is not started twice, so a double click does not make two.
- On multisite, when sites share one zone, each site’s lockout rules are its own, and one site never takes off another’s.
- With **Ask for my password before an action that removes a protection** on (**Settings › General**), opening this tab and using its controls asks for your password.
- What is sent to Cloudflare is listed on [What BetterShield contacts](/docs/what-bettershield-contacts/).

## Related

- [Login & Access](/docs/login-and-access/)
- [Locked out](/docs/locked-out/)
- [What BetterShield contacts](/docs/what-bettershield-contacts/)
- [Install Ultra](/docs/install-ultra/)
