CDN integrations
Connect Cloudflare, Akamai, and Fastly accounts to manage zones, apply WAF rules and SSL settings in bulk, and feed AI crawler analytics into the AI Visibility Technical Health dashboard.
Overview
CDN Integrations is a control plane for the three major edge providers. Connect a CDN account once and WebGPT can list every zone or property under it, apply settings in bulk across dozens or hundreds of domains, and stream traffic + AI-crawler data into the brand-scoped Technical Health surface on AI Visibility. The page is structured as a tab per provider; each tab handles account-level connections for its CDN.
Cloudflare
The Cloudflare tab is the most feature-rich of the three because it shipped first and accumulated the full WAF + SSL + bulk-operations + analytics surface. Two inner sub-tabs: Accounts (default) and Analytics.
Connecting Cloudflare
Authentication uses a scoped Cloudflare API token. Create it in Cloudflare → My Profile → API Tokens → Create Token → Create Custom Token, with these permissions on all zones of the account:
- Zone → Zone → Read — look up zones by domain name
- Zone → Zone WAF → Edit — create and manage WAF rules
- Zone → Zone Settings → Edit — read and change SSL/TLS mode
- Zone → DNS → Edit and Zone → Page Rules → Read — domain redirects
- Zone → Analytics → Read — the analytics sub-tab
- Open the Cloudflare tab and click Connect.
- Enter the Cloudflare account email and the API token.
- Click Verify. The token is checked live — both that it is active and that it can actually list zones — and the zones found are listed.
- Click Save. Credentials are stored encrypted, and all zones in the account are synced automatically.
- Optionally add the Global API key afterwards by editing the account — find it in Cloudflare → My Profile → API Tokens → Global API Key.
Changing the token later requires clicking Verify again before saving. The same applies to the Global API key, and to the account email while a key is stored — the email + key pair is always re-validated as a unit.
WAF rules
Create, edit, and delete custom WAF rules for any zone. Rules use Cloudflare's expression syntax (e.g., block requests from specific countries, challenge suspicious user agents, allow known bots). Expressions are validated before they're applied, catching syntax errors early.
Actions are block, managed challenge, interactive challenge, JS challenge, log, and skip. A skip rule lets matching traffic bypass the protection layers you choose — remaining custom rules, WAF managed rules, rate limiting, Bot Fight Mode, and Browser Integrity Check — which is how you allowlist a monitoring service, webhook, or crawler that a broader rule would otherwise challenge.
Rules WebGPT manages for you (such as the AI-crawler allowlist deployed from AI Visibility) appear in the list marked as managed and are read-only here, so removing one from the wrong place can't silently break the feature that deployed it. Manage those from the feature that owns them.
SSL/TLS mode
Cloudflare's four SSL/TLS modes:
- Off — No encryption (not recommended).
- Flexible — Encrypts visitor-to-Cloudflare, but not Cloudflare-to-origin.
- Full — End-to-end encryption without origin certificate validation.
- Full (Strict) — End-to-end with origin certificate validation. Recommended when the origin has a valid certificate.
Bulk operations
Apply the same WAF rule or SSL mode across dozens or hundreds of zones in a single pass. Select the target domains, define the change, and the background job system processes every zone, tracks per-domain success or failure, and returns a results summary at the end.
Redirect a domain
Send every request for one domain to another with a permanent (301) redirect, created on the source domain's Cloudflare zone. The path and query string are preserved, so domain-a.com/some-page/?ref=x lands on domain-b.com/some-page/?ref=x — not on the target's homepage. Open a domain's rules, switch to the Redirects tab, enter the target domain, and create the redirect. The target can live on a different Cloudflare account; only the source zone is changed.
Before creating the redirect, the tab checks the zone and reports anything in the way — a missing API token, an inactive zone, DNS records that are not proxied, or an existing redirect. Fixable items (SSL off, DNS not proxied) are handled automatically when the redirect is created, and reversed if the redirect is later removed.
/.well-known/ are never redirected, so a source domain that renews its SSL certificate over HTTP continues to do so.
Analytics sub-tab
Cloudflare traffic and security data, sourced directly from Cloudflare's analytics — a complementary view to Google Analytics.
- KPI cards — Active domains, unique visitors, average visitors per domain, average visitors per day.
- Trend chart — Visitors over time, with an optional toggle to overlay total requests.
- Top domains — Horizontal bar chart ranking zones by visitors or total requests.
- Category breakdown — Per-category table aggregating active domains, unique visitors, averages, and total requests.
Akamai
The Akamai tab covers account-level connection and credential management. Once connected, Akamai analytics flow into the brand-scoped Technical Health dashboard on AI Visibility — the WAF/SSL/bulk-operations surface that Cloudflare exposes here isn't replicated in this tab (use Akamai's own Control Center for those changes).
Connecting Akamai
- Open the Akamai tab and click Connect.
- Enter your Akamai API credentials. Akamai uses EdgeGrid authentication — you'll need the client token, client secret, access token, and host from an API client provisioned in Akamai Control Center → Identity & Access → API Clients.
- Click Verify — the credentials are validated with a live API call — then Save. When editing later, only the changed fields need re-entry; verification always tests the full credential set.
Fastly
The Fastly tab covers account-level connection and credential management, mirroring the Akamai tab. Fastly analytics flow into the AI Visibility Technical Health dashboard.
Connecting Fastly
- Open the Fastly tab and click Connect.
- Enter a Fastly API token from Fastly account → Account → API tokens. Choose a token scoped to read-only on services unless you need write access.
- Click Verify — the token is validated against the Fastly API — then Save.
How CDN data reaches the Technical Health dashboard
Each connected CDN runs background sync jobs that pull traffic, request, and AI crawler data. The aggregated data is keyed by brand domain and surfaces in the Technical Health tab on AI Visibility — per-domain AI bot access matrix, crawler request volumes, and (when available) reasons crawlers were blocked. Connect at least one CDN that fronts the brand's domains to populate that dashboard.
Troubleshooting
- Cloudflare invalid credentials — Check the token was created as a User API Token rather than an Account API Token. Global API keys require clicking "View" and entering the password in the Cloudflare dashboard before copying.
- Cloudflare missing zones — The zone must be active in Cloudflare (not paused or deleted), and the token's resources must include it — scope the token to all zones of the account rather than a single zone. Try re-syncing the account.
- Cloudflare WAF rule errors — Expression syntax issues are highlighted before applying. If a rule still fails, check for zone-specific conflicts.
- Cloudflare API token permissions — For full functionality the token needs Zone:Read, Zone WAF:Edit, Zone Settings:Edit, DNS:Edit, Page Rules:Read, and Analytics:Read. A token that verifies successfully but fails when saving a rule is usually missing Zone WAF:Edit.
- Cloudflare "API token required" — Shown on an account that holds only a Global API key. Rules, redirects, and allowlists run through Cloudflare's rules engine, which accepts token authentication only; add a token to the account to enable them.
- Akamai authentication — EdgeGrid requires all four fields (client token, client secret, access token, host). Missing or mismatched fields produce a 401.
- Fastly token scope — Read-only tokens are sufficient for analytics ingestion. Service-write tokens are only needed if you plan to add zone-management features in the future.
- Bulk operation failures — Individual domain failures during Cloudflare bulk jobs usually reflect zone-specific issues (e.g., a zone in a pending state). Details are in the job results summary.