Cloudflare integration for nginx reverse proxies

ShieldProxy does not run a shared Cloudflare account. Each admin connects their own OAuth or API token so the panel can drive a DMCA-ignore reverse-proxy path: proxied DNS to the nginx shield, Origin CA for Full (Strict), and clean teardown when domains leave.

OAuth or API token

OAuth is convenient when you connect from the browser.

API tokens suit tighter scopes for DNS and certificate work when you prefer token-based access.

Use Disconnect when you want to revoke access cleanly.

What the connection is used for

Looking up zones and pointing proxied records at the shield.

Issuing Origin CA material for the Cloudflare→shield hop when you add domains.

Cleaning up proxy DNS records the panel created when a domain is removed—not rewriting your whole zone.

Keep reading

Explore topics