Maski needs two permissions on the one zone you are setting up: Zone:Read, to
find the zone, and DNS:Edit, to publish the records. Nothing else, and no other
zone.
Create the token
1
Open your API tokens
Go to dash.cloudflare.com/profile/api-tokens,
or from the dashboard select My Profile, then API Tokens. Choose
Create Token.
2
Start a custom token
Cloudflare offers templates first. Scroll past them to Create Custom Token
and choose Get started. The templates do not match what Maski needs closely
enough, so build the token yourself.
3
Set the permissions and the zone
Name the token something you will recognise later, for example
Maski DNS setup.Under Permissions, add two rows. Each row is three dropdowns.Under Zone Resources, choose Include, then Specific zone, then the
domain you are setting up. This is the part that matters most. A token scoped
to one zone cannot touch anything else in your Cloudflare account.Client IP filtering and TTL are optional. Since the token is used once, setting
a short expiry is a reasonable extra precaution.
4
Copy the token
Choose Continue to summary, check the summary reads as expected, then
Create Token. Cloudflare shows the token value once and will not show it
again. Copy it.
5
Paste it into Maski
Open your domain in the Maski dashboard. In Set up automatically, pick
Cloudflare, choose Prefer to paste an API token instead?, paste the token,
and press Review changes.Maski reads your zone and shows you what it would change. Nothing is written
until you press Publish records.