# Install on Cloudflare Source: https://www.luriart.com/docs/install/cloudflare Plain text: https://www.luriart.com/docs/install/cloudflare.txt If your site runs through Cloudflare, paste one API token and Luria installs itself at the edge, with no tag to paste and no flicker. Takes under 10 minutes and removes itself cleanly. Time needed: about 8 minutes. ## What you'll need * A site whose domain uses Cloudflare, with the hostname proxied (the orange cloud in Cloudflare's DNS page). * Permission to create API tokens in that Cloudflare account. * Your Luria dashboard open on Connections. Luria deploys a small Cloudflare Worker named `luria-edge-` on your hostname. It adds the Luria tag to the top of each page, serves Luria's scripts from your own domain, and shows each visitor their version before the page paints. If anything in it fails, Cloudflare serves your page exactly as your server sent it. ### Step 1: Open the token link In Luria, open Connections, choose Cloudflare, and press Create token. It opens Cloudflare with the token already filled in: name "Luria edge" and four permissions. | Permission | What Luria uses it for | | ----------------------------- | ------------------------------------------------------------------------ | | Account: Workers Scripts Edit | Upload the Luria Worker, and remove it when you disconnect | | Zone: Zone Read | Find the zone your site lives in | | Zone: DNS Read | Check that your hostname is proxied | | Zone: Workers Routes Edit | Add the route that runs the Worker on your hostname, and remove it later | Luria never asks for DNS edit, cache, firewall or billing permissions. ### Step 2: Limit it to your site's zone Under Zone Resources, choose Include, Specific zone, and pick the zone your site uses. Leave Account Resources on your account. Press Continue to summary, then Create Token. **Warning:** Cloudflare shows the token once. Copy the whole value before you leave the page. ### Step 3: Paste the token in Luria Paste it into the Cloudflare token box and press Connect. Luria reads your zone, DNS record and existing Worker routes (read only) and tells you exactly which permission is missing if any is. Your account and zone IDs are found for you. Luria stores the token encrypted and shows only its last four characters. ### Step 4: Let Luria install Press Install. Luria uploads the Worker and adds a route for `yourdomain.com/*`, plus script-free routes for static files (`/assets/*`, `/static/*`, `/_next/static/*`, `/wp-content/uploads/*`) so images and bundles never count against your Workers requests. The route is set to fail open: if your Workers plan runs out of daily requests, Cloudflare skips the Worker and your site keeps loading. Luria installs the plain tag instead, and says why, when: * the hostname is DNS-only (grey cloud): Workers never see its traffic. Turning the proxy on is your call; it changes how your traffic flows, so weigh it with whoever runs your DNS. * another Worker already runs on your whole hostname: Luria never replaces your Worker. * your Content-Security-Policy would block the tag: add `'self'` to `script-src` to use the edge install. * your framework hydrates the whole document (Next.js App Router, Remix, React Router, SolidStart): edge injection into the page head is not yet proven safe there, so the plain tag is used. ### Step 5: Verify Press Verify. Luria checks that the token is valid, the Worker and route are in place and fail open, `yourdomain.com/_luria/health` answers with this Worker's signature, the Luria tag is in the head of your live homepage, the page sets the `luria_sid` visitor cookie, and a test event sent through your own domain reaches Luria. Each failed check comes with its fix. ## Plans and limits Workers Free allows 100,000 requests a day. Every HTML page view is one request; static files are excluded by the bypass routes. Above that, the route fails open (your site loads without Luria until the next UTC day). Workers Paid has no daily cap. Very large pages (over 256 KB of HTML) still get their tag and flicker guard; the version is applied by the tag instead of at the edge. ## Disconnect In Connections, press Disconnect on Cloudflare. Luria deletes the routes it created and the `luria-edge-` Worker, re-reads your account to confirm they are gone, and deletes its copy of the token. Nothing else in your Cloudflare account is touched, and your pages are served exactly as before. You can then delete the token in Cloudflare under My Profile, API Tokens. ## Common failures **Connect says a permission is missing** The token was created without one of the four permissions, or for a different zone. Create a new one from the link in Luria and paste it. **Verify says the tag is not in the head** A cached copy of the page is being served. Purge the Cloudflare cache for your homepage, then verify again. **Verify says the health check does not answer** The route is missing or points elsewhere. Press Repair: it redeploys the Worker and recreates the route, never over a Worker of yours. **Luria shows the token as disconnected** The token was deleted, rolled or expired in Cloudflare. Create a new one from the link in Luria and paste it; your settings stay. **The route is not fail open** Press Repair. If it stays closed, open Workers Routes in Cloudflare, edit the route for your hostname, and set Request limit failure mode to Fail open. ## Next steps * [Verify your install](/install/verify)