Skip to content

Workspace Support

Cloudflare setup guide

Use this page when New Reward is handling website delivery for your team. Choose one of the two access paths below, then send the account and hostname details required to configure and verify delivery.

After you collect the items below, reply to your onboarding email or contact support.

Need the full setup packet?

If you also need the Google integration instructions, open the Google integrations access guide.

Video walkthrough

Watch the Cloudflare access walkthrough before starting if you want to see the exact screens.

Watch Cloudflare tutorial

What to send your workspace team

  • Confirmed access path: member invite or client-token fallback
  • Cloudflare account ID
  • Public delivery hostname, for example www.example.com
  • Dedicated origin/bypass hostname, for example origin.example.com

Path 1: Member invite, then New Reward scoped token

This is the preferred collaboration path when your policy allows a Cloudflare member invitation. The member roles let New Reward accept the handoff; after acceptance, New Reward creates and securely stores a scoped user API token limited to the required account, zone, and permissions.

  1. 1. Sign in to Cloudflare. Open dash.cloudflare.com and select the account that owns your website.
  2. 2. Copy the Cloudflare account ID. Copy the Account ID shown for the account that owns the website zone. New Reward needs this ID even when you use the member-invite path.
  3. 3. Confirm both hostnames. Record the public delivery hostname, such as www.example.com, and a dedicated origin/bypass hostname, such as origin.example.com. The origin hostname must resolve directly to the website origin, must not redirect back to the public hostname, and must stay outside the Worker route.
  4. 4. Open Members. In the left navigation, open Manage Account, then choose Members. This is the account-level access screen.
  5. 5. Invite New Reward. Click Invite members and enter newrewardplatformgmail.com.
  6. 6. Add these exact roles.
    • Account-level role: Workers Platform AdminThis is a broad account-scoped Developer Platform role. It does not grant billing or Super Administrator access.
    • Domain-level role: Domain AdministratorScope this role to the client website domain that New Reward will support.

    Workers Platform Admin is account-scoped and applies across the entire Cloudflare account, including all domains and broader Developer Platform products. Use this path only after reviewing that scope with your account owner.

    Do not grant billing access, Super Administrator access, or whole-account Administrator access unless New Reward explicitly asks for it later.

  7. 7. Send the invite. After sending, the Members table should show Pending until New Reward accepts the email invite.
  8. 8. Reply with the handoff details. Confirm the invite was sent and include the Cloudflare account ID, public delivery hostname, and dedicated origin/bypass hostname. Do not send an API token in ordinary email.

Token permissions used for either path

The deployment token must be limited to the required Cloudflare account, website zone, and these six permissions:

  • Account Analytics: Read
  • Zone: Read
  • Analytics: Read (zone)
  • Workers Scripts: Edit
  • Workers Routes: Edit
  • Bot Management: Read

Path 2: Client-created scoped token fallback

Use this fallback only when member invitations are prohibited by your security policy. Create a custom Cloudflare API token with the six permissions above, restricted to the account and website zone New Reward will manage.

Reply to your onboarding email with the Cloudflare account ID, public delivery hostname, and dedicated origin/bypass hostname. New Reward will provide an approved secure credential channel for the token. Do not paste the token into email, chat, or this page.

If you do not use Cloudflare yet

  1. 1. Create or sign in to a Cloudflare account. Start at Cloudflare sign up.
  2. 2. Add your website to Cloudflare. Follow Cloudflare’s zone onboarding steps. If your website will use Cloudflare as the main DNS provider, Cloudflare’s guide for the nameserver change is here: Change your nameservers.
  3. 3. Wait for the zone to become active. Your domain should show as active in Cloudflare before you send us access.
  4. 4. Make sure the hostname we will publish is proxied. In the Cloudflare DNS screen, the hostname should show the orange cloud proxy status.
  5. 5. Choose an access path above. Once your website is active on Cloudflare, use the member-invite path or, when invitations are prohibited, the client-token fallback.

Need the official integration screen after you log in?

Once your workspace account is active, your team can manage other integrations from the client workspace. If you are not sure where to start, reply to your onboarding email and we will point you to the correct client record before deployment begins.