WARP + Cloudflare One
persist none

Onboard the privacy tunnel

Walk the same path as deploy-vpn.ps1 / --team and warp-setup.md steps 7–8. Consumer WARP needs no org. Cloudflare One adds Gateway and (optionally) device posture. This page never stores an IP and never claims Access.

Honest scope: WARP hides you in Cloudflare’s herd (IP, ASN, DNS-to-ISP). Origin JA3 stays this browser unless Gateway TLS inspection is on. Kill-switch is extension DNR. HMAC apex lock is not Access posture and is not live until an explicit device-lock deploy.

Choose a track

Installs WARP, connects a free consumer device, verifies egress. Gateway policies do not apply.

Checklist

Owner tells you who can finish the step. Dashboard items cannot be set from this CLI.

Loading schema…

Live probes (stay in this browser)

Same-origin /cdn-cgi/trace and GET /api/enterprise/onboard. IPs are not shown.

Open 1.1.1.1/help GET /api/enterprise/onboard
No probe yet.

Your audit Worker (optional)

This site does not proxy the request. A successful probe lists field names only.

Paste none of the values into a receipt.

Security audit (local, read-only)

Device + public site need no token. Zero Trust listings (Access apps, Gateway rules, posture, TLS decrypt) need CF_API_TOKEN and CF_ACCOUNT_ID. GET only. The token is never printed.

py -3 scripts/cf-one-audit.py
py -3 scripts/cf-one-audit.py --json
# optional Zero Trust plane:
#   set CF_API_TOKEN and CF_ACCOUNT_ID, then re-run
VPN enroll scripts deploy-vpn.ps1 deploy-vpn.sh

Dashboard (steps the CLI cannot set)

SurfaceWhere
Cloudflare One / Zero Trustdash.cloudflare.com/one
Enrollment rulesSettings → WARP Client → Device enrollment
Gateway DNS (step 7)Gateway → Firewall policies → DNS
Gateway HTTP / TLS inspect (step 7–8)Gateway → Firewall policies → HTTP. Needs the CF root cert.
Device posture (step 8)Settings → WARP Client → Device posture. Not Access. Not HMAC lock.

layer 2 onboard · persist none · not Access · not device-lock