DOCUMENTATION · OPERATOR REFERENCE
Cloudflare Access reference
Reference for managing Cloudflare Access credentials on ERPipe connections: supported fields, permissions, verification behavior, API operations and self-host settings.
Published: September 18, 2026 · Last updated: September 29, 2026
Answer first
ERPipe's Cloudflare Access configuration is an optional credential pair on an Odoo connection. It adds CF-Access-Client-Id and CF-Access-Client-Secret to Odoo requests. It does not replace Odoo authentication or grant additional Odoo permissions. For the sequence of dashboard steps, use the Odoo Cloudflare Access setup guide.
This reference applies to releases exposing the Cloudflare Access card and the operations below. Check the connection's Configure page before following a workflow on an older deployment. Generic custom headers and browser-based Access login are not configuration options in this feature.
Credentials and request boundaries
| Credential | Where it belongs | Purpose |
|---|---|---|
| Access Client ID and Client Secret | Cloudflare Access card on the Odoo connection | Admit ERPipe's requests through the Access policy. |
| Odoo API key or password | Odoo credential field on the connection | Authenticate the dedicated Odoo user. |
| Cloudflare Tunnel token | Your cloudflared connector | Connect your origin to Cloudflare; never enter it as Client Secret. |
| Cloudflare account API token | Your Cloudflare administration tools | Manage Cloudflare resources; ERPipe does not need it for this connection. |
| ERPipe MCP OAuth grant | Your MCP client's native authorization flow | Authorize access to the ERPipe workspace. |
Cloudflare documents the two service-token headers in its service-token reference. Odoo 19 JSON-2 uses a separate bearer credential, described in the official Odoo API reference.
For hosted ERPipe, the destination must pass public HTTPS and DNS validation. A service token does not make a private-only origin routable. JSON-2 authentication, its version probe and XML-RPC calls all receive the configured pair. Redirects are not followed. Odoo ACLs, field policies, write settings and approvals continue to apply.
Fields and validation
| Field | Input contract |
|---|---|
access_client_id | Complete Client ID as supplied by Cloudflare, including any suffix. |
access_client_secret | Matching opaque Client Secret. Both legacy hexadecimal and newer cfast_ formats are accepted. |
password on set | Optional replacement Odoo password/API key. A supplied value must be a nonempty string. Omit it to use the stored Odoo credential. |
cloudflare_access_configured | Read-only boolean in public connection results; not a credential and not a live health result. |
Both input values must be strings containing 1–512 visible ASCII characters after surrounding spaces are removed. Control characters, newlines, non-ASCII characters and internal whitespace are rejected. Supply both or omit both during creation. The wizard omits its unused blank fields; explicitly sending empty or partial values to the API is invalid. Set/replace always requires a complete pair.
The Access secret is encrypted with a connection-specific context separate from the Odoo credential. Saved Client IDs, secrets and encrypted values are not returned in public connection responses. Logs and audit handling redact Access credential fields. A configured flag reports stored configuration, not proof that the token remains valid after expiry or policy changes.
Owner permissions and connection states
Only a current owner of the connection's workspace can configure Access. Dashboard/API operations require the authenticated owner session. MCP Access configuration additionally requires erpipe:write; creating an instance with an Access pair also requires owner access. Odoo writes can stay disabled throughout token setup.
A paused connection can have its token replaced. The operation preserves its paused status. A revoked connection rejects configuration changes. Verification that overlaps another credential update, revocation or loss of ownership can return 409; reload before deciding whether to retry.
API operations
Use the authenticated ERPipe application API. Browser integrations must preserve the existing same-origin/session protections. Never place a session cookie or credential in a public example, query string or analytics event.
| Method and path | Request | Successful behavior |
|---|---|---|
POST /api/app/connections | Existing Odoo setup fields plus an optional complete Access pair | Verify before creating the connection. |
PUT /api/app/connections/:id/cloudflare-access | access_client_id, access_client_secret, optional password | Verify with the supplied new Odoo credential or the saved one, then save the verified credentials together. |
DELETE /api/app/connections/:id/cloudflare-access | Empty request body | Verify without Access headers, then remove the pair. |
Here is the response shape for a successful set operation; the identifiers are illustrative:
{
"ok": true,
"connection": {
"id": "connection-id",
"instance": "your-instance-key",
"cloudflare_access_configured": true
}
}A successful clear returns the same shape with cloudflare_access_configured: false. Connection lists and details expose the flag as well. Replacing the Access pair does not require sending another Odoo password.
MCP operations
create_instance accepts the optional pair alongside its normal connection inputs. update_instance_cloudflare_access manages an existing connection:
| Action | Required arguments | Conditions |
|---|---|---|
set | instance, action: "set", access_client_id, access_client_secret | Optional password replaces the Odoo credential in the same operation. Owner and write scope; successful preflight before persistence. |
clear | instance, action: "clear", confirm: true | Omit Access fields and password. Odoo must verify without Access headers. |
Credential-bearing setup is best completed in the dashboard. Automated integrations must obtain secrets through their own protected runtime inputs; do not paste them into an agent conversation. MCP success reports success: true, connection identifiers and configured status. The public tool catalog describes the rest of the surface.
Errors and recovery
API errors use the existing error and message envelope. The user-facing message omits saved secrets. A failed set or clear leaves the saved credential pair unchanged.
| HTTP status | Meaning for this operation | Recovery |
|---|---|---|
| 400 | Invalid body, missing value or invalid pair | Supply two valid values; omit credentials for clear. |
| 403 | Workspace ownership/authorization denied | Use the appropriate workspace owner. This is separate from an upstream Odoo/proxy 403. |
| 404 | Connection not found in the caller's tenant | Check the instance identifier and current workspace. |
| 409 | Revoked connection or state changed during verification | Reload the connection. Do not overwrite a newer change blindly. |
| 422 | Odoo verification failed with the proposed configuration | Check Access policy/token, Odoo credential, DNS and origin reachability as indicated. The old pair remains saved. |
Missing authentication is handled by the application's normal session gate. For upstream redirects and proxy 403 responses, follow setup troubleshooting. More-specific Cloudflare application-path policies can explain why an ORM call works while version discovery is denied.
Replacement and removal
Set/replace checks the new pair with the existing Odoo credential before saving it. A failed check, concurrent change or permission loss does not authorize replacing the previous verified state. After a successful replacement, perform a small Odoo read before revoking an old token during planned rotation.
If both credentials have changed or expired, expand Odoo credential also changed? on Configure and supply the new Odoo password/API key with the new Access pair. The API and MCP set operation accepts the same optional password field. Both credentials are verified together and saved in one conditional update; an invalid replacement, failed check or concurrent update preserves the previous stored bytes. This recovery does not require decrypting obsolete credentials when both are replaced. It preserves the connection identity, paused state and write controls.
Clear checks the same Odoo credential without Access headers. When Cloudflare still blocks that request, the operation returns 422 and retains the saved token. Clearing ERPipe's copy does not change the Cloudflare policy or revoke the token in Cloudflare. Manage Cloudflare's token lifecycle in Cloudflare and keep the integration's saved pair current.
Self-host configuration
The TypeScript self-host Worker accepts CF_ACCESS_CLIENT_ID and CF_ACCESS_CLIENT_SECRET together. Leave both unset for a connection that does not use Access. Use interactive secret prompts in the self-host package:
npx wrangler secret put CF_ACCESS_CLIENT_ID
npx wrangler secret put CF_ACCESS_CLIENT_SECRETCore consumers can supply the typed cfAccess object with clientId and clientSecret loaded from their own secret store. Access-capable packages in this implementation are core 0.1.3 and XML-RPC 0.1.2; verify the installed build supports them rather than assuming registry publication. Partial or empty self-host environment configuration fails before a request is sent.
Sources and related documentation
This contract was updated against the ERPipe implementation on September 29, 2026. External configuration references are linked above. No customer hostname, credential or live-policy test result is included here.
Continue with the setup walkthrough, connector documentation, security boundaries and compatibility matrix.