Hacker News new | ask | show | jobs
by jgrahamc 2484 days ago
Good news is these tools can stop using the global API token on Cloudflare and use a scoped token just for this purpose: https://blog.cloudflare.com/api-tokens-general-availability/
2 comments

Indeed, "but" the minimum token you can create is one that allows its wielder to edit a whole zone's DNS, not just (say) one specific record.
This is great news! I've always wanted to use the API with fail2ban but didn't want to run the risk of using the global API key.