Onboard the privacy tunnel
Walk the same path as deploy-vpn.ps1 / --team and
warp-setup.md steps 7–8. Consumer WARP needs no org.
Cloudflare One adds Gateway and (optionally) device posture.
This page never stores an IP and never claims Access.
Choose a track
Installs WARP, connects a free consumer device, verifies egress. Gateway policies do not apply.
Checklist
Owner tells you who can finish the step. Dashboard items cannot be set from this CLI.
Live probes (stay in this browser)
Same-origin /cdn-cgi/trace and GET /api/enterprise/onboard. IPs are not shown.
Your audit Worker (optional)
This site does not proxy the request. A successful probe lists field names only.
Security audit (local, read-only)
Device + public site need no token. Zero Trust listings (Access apps, Gateway rules, posture, TLS decrypt) need CF_API_TOKEN and CF_ACCOUNT_ID. GET only. The token is never printed.
py -3 scripts/cf-one-audit.py py -3 scripts/cf-one-audit.py --json # optional Zero Trust plane: # set CF_API_TOKEN and CF_ACCOUNT_ID, then re-runVPN enroll scripts deploy-vpn.ps1 deploy-vpn.sh
Dashboard (steps the CLI cannot set)
| Surface | Where |
|---|---|
| Cloudflare One / Zero Trust | dash.cloudflare.com/one |
| Enrollment rules | Settings → WARP Client → Device enrollment |
| Gateway DNS (step 7) | Gateway → Firewall policies → DNS |
| Gateway HTTP / TLS inspect (step 7–8) | Gateway → Firewall policies → HTTP. Needs the CF root cert. |
| Device posture (step 8) | Settings → WARP Client → Device posture. Not Access. Not HMAC lock. |