ZTNA Kit Cloudflare One config generator

Token-free • runs in your browser

Fill in your profile once. It is saved locally, sharable by link, and turned into ready-to-run Terraform and API scaffolding for a Tunnel + Access + Gateway deployment.

How this works (3 steps, no token required)
  1. Describe the app you want to protect. Enter your account and zone IDs, the public hostname, and the local service the tunnel should reach (for example http://localhost:3000).
  2. Choose what to deploy. Turn on Gateway DNS filtering, a private network route, or paranoid ordering. The summary on the right lists every resource before you create anything.
  3. Take the output. Copy or download any file, or grab setup.sh to write the whole folder at once. Then run terraform apply or ./deploy.sh.

Your API token is never entered here and never leaves your machine. Terraform reads it from TF_VAR_cloudflare_api_token and the script reads CLOUDFLARE_API_TOKEN, both from your shell. The profile is stored in your browser and encoded into the share link, so no server sees it.

Work top to bottom. Empty required fields show a warning and invalid values show an error, inline and in the summary. Nothing is sent anywhere.

Identifiers

Application

Identity

Gateway (DNS filtering)

Options

main.tf