DIsable Cloudflare cookie check for API URL


I have an external provier (WATI) calling my site through an API. It is not in a browser so cookie check fails.

I tried creating a Page Rule and setting Disable Security for the URL, but this is not working - WATI is still getting 403.

What can I do? I am on the free plan.

Thank you

This is what it looks like, and URL is still getting cookie check and 403

Assuming the 403 is a Cloudflare challenge, or page, you can look in the security events here to find the rejected/challenged request and the reason for it…

Then use a WAF rule to skip the problem for the provider as specifically as you can (not just URL, but also IP address if you know them).

First of all thank you for your reply.

Secondly - I added this and nothing changed:

This is the response from Cloudflare:

Ahhh nevermind! I was a long shot change that this API is called from a country we blocked. Thank you for your time!

