Skip to main content

Cloudflare

Cloudflare

The recommended way to integrate CrowdSec Blocklists with Cloudflare is the Self-Hosted Cloudflare Bouncer, connected to a Blocklist Integration Endpoint. You don't need to deploy anything on your servers and you are able to choose the type of remediation for each blocklist: Ban or Captcha, resulting in a Block or Turnstile challenge for the end-user.

info

For other integration methods (Security Engine LAPI, CLI Bouncer Daemon, advanced config), see the full Cloudflare Bouncer documentation.


Create a Blocklist Integration Endpoint

Step 1 - Create an integration in the CrowdSec Console

In your CrowdSec Console account, navigate to the Blocklist tab in the top menu bar, then select the Integrations sub-menu. Choose the integration type you need, then click Connect.

info

If you don't have a CrowdSec Console account, sign up here. On mobile, use the menu icon in the top-right corner, tap Blocklist, then Integrations.

CrowdSec Integrations ScreenCrowdSec Integrations Screen

Deploy and Configure the Cloudflare Bouncer

For Cloudflare, the Cloudflare Bouncer acts as the intermediary: it pulls decisions from the Blocklist Integration Endpoint and enforces remediations directly inside your Cloudflare account via Workers and a KV store — no server required on your side.

Follow the Self-Hosted Setup instructions to deploy the installer and configure it. When prompted for a CrowdSec Integration Endpoint, paste the URL from Step 1.

Once your zones are protected, the installer UI will show them as installed:

Zone Install


Go further

CrowdSec Docs
We use cookies

This site uses cookies to help us improve your experience. You can accept or decline below.