Can the cloudflare API key transfer out domains?

I want to register domains with Cloudflare but I also have wordpress websites protected by Cloudflare which use the API key to clear the cache etc.
If one of those sites is compromised and someone gets the API key, can they use it to transfer away my domains?

The global API key has full access to your entire Cloudflare account - including transferring domains away from Cloudflare registrar.

An API token, on the other hand, can be scoped to specific actions such as purging zone cache. It is recommended you use properly scoped tokens for any automated tasks or third party integrations.

2 Likes

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.