I’m planning to enable APO on a subdomain. According to the documentation, this will require using Global API key to authenticate in the plugin (and plugin-less APO is evidently going away). I have reasonable concerns about the security of Wordpress (more specifically – its various plugins), and the website is operated by a somewhat independent entity. Therefore I’d like not to save the Global key in Wordpress unless absolutely necessary. Would I be able to replace this after setup is complete with a regular per-zone API token? Any other hints how to make this setup more secure?
That might be old documentation. As I recall, APO works with Tokens:
I didn’t even think APO would work without a plugin. Do you have a link that explains this? Another user looks to have APO enabled on a subdomain (under a domain with the plugin) and it’s active.
Thank you for your reply. The documentation doesn’t seem too old – Subdomains and subdirectories · Cloudflare Automatic Platform Optimization docs was updated 6 days ago and specifically states “You can only use a Global key for the subdomain”. And I won’t sleep well knowing that the webmaster of this website is in control of all our DNS zones.