LuriaDocs
Install

Install on Cloudflare

If your site runs through Cloudflare, paste one API token and Luria installs itself at the edge, with no tag to paste and no flicker. Takes under 10 minutes and removes itself cleanly.

plain textupdated 2026-09-30

About 8 minutes

What you'll need

  • A site whose domain uses Cloudflare, with the hostname proxied (the orange cloud in Cloudflare's DNS page).
  • Permission to create API tokens in that Cloudflare account.
  • Your Luria dashboard open on Connections.

Luria deploys a small Cloudflare Worker named luria-edge-<your site id> on your hostname. It adds the Luria tag to the top of each page, serves Luria's scripts from your own domain, and shows each visitor their version before the page paints. If anything in it fails, Cloudflare serves your page exactly as your server sent it.

In Luria, open Connections, choose Cloudflare, and press Create token. It opens Cloudflare with the token already filled in: name "Luria edge" and four permissions.

PermissionWhat Luria uses it for
Account: Workers Scripts EditUpload the Luria Worker, and remove it when you disconnect
Zone: Zone ReadFind the zone your site lives in
Zone: DNS ReadCheck that your hostname is proxied
Zone: Workers Routes EditAdd the route that runs the Worker on your hostname, and remove it later

Luria never asks for DNS edit, cache, firewall or billing permissions.

Step 2: Limit it to your site's zone

Under Zone Resources, choose Include, Specific zone, and pick the zone your site uses. Leave Account Resources on your account. Press Continue to summary, then Create Token.

Copy it now

Cloudflare shows the token once. Copy the whole value before you leave the page.

Step 3: Paste the token in Luria

Paste it into the Cloudflare token box and press Connect. Luria reads your zone, DNS record and existing Worker routes (read only) and tells you exactly which permission is missing if any is. Your account and zone IDs are found for you. Luria stores the token encrypted and shows only its last four characters.

Step 4: Let Luria install

Press Install. Luria uploads the Worker and adds a route for yourdomain.com/*, plus script-free routes for static files (/assets/*, /static/*, /_next/static/*, /wp-content/uploads/*) so images and bundles never count against your Workers requests. The route is set to fail open: if your Workers plan runs out of daily requests, Cloudflare skips the Worker and your site keeps loading.

Luria installs the plain tag instead, and says why, when:

  • the hostname is DNS-only (grey cloud): Workers never see its traffic. Turning the proxy on is your call; it changes how your traffic flows, so weigh it with whoever runs your DNS.
  • another Worker already runs on your whole hostname: Luria never replaces your Worker.
  • your Content-Security-Policy would block the tag: add 'self' to script-src to use the edge install.
  • your framework hydrates the whole document (Next.js App Router, Remix, React Router, SolidStart): edge injection into the page head is not yet proven safe there, so the plain tag is used.

Step 5: Verify

Press Verify. Luria checks that the token is valid, the Worker and route are in place and fail open, yourdomain.com/_luria/health answers with this Worker's signature, the Luria tag is in the head of your live homepage, the page sets the luria_sid visitor cookie, and a test event sent through your own domain reaches Luria. Each failed check comes with its fix.

Plans and limits

Workers Free allows 100,000 requests a day. Every HTML page view is one request; static files are excluded by the bypass routes. Above that, the route fails open (your site loads without Luria until the next UTC day). Workers Paid has no daily cap. Very large pages (over 256 KB of HTML) still get their tag and flicker guard; the version is applied by the tag instead of at the edge.

Disconnect

In Connections, press Disconnect on Cloudflare. Luria deletes the routes it created and the luria-edge-<site id> Worker, re-reads your account to confirm they are gone, and deletes its copy of the token. Nothing else in your Cloudflare account is touched, and your pages are served exactly as before. You can then delete the token in Cloudflare under My Profile, API Tokens.

Common failures

Next steps

On this page