Detection, Mitigation & Response

Detect and mitigate DDoS attacks in under 1 second, respond automatically, and keep your users informed.

All features →
Docs
Documentation Quick Start API Reference Agent Setup Integrations 18
Learn
Free Tools 37 Free Certifications State of DDoS 2026 REPORT DDoS Protection Landscape Buyer's Guide PDF Hackathon Sponsorships DDoS Protection Facts
Company
About Us Partners White Label Contact Us System Status
Open Source
ftagent-lite MIT NetHawk MIT
Legal
Security Trust Center Terms & Privacy
Who Uses Flowtriq

From indie hosts to ISPs, see how teams like yours use Flowtriq to detect and stop DDoS attacks.

All use cases →
Cloudflare API Under Attack Mode Auto-Restore

Flowtriq + Cloudflare

Automatically enable Cloudflare Under Attack Mode when Flowtriq detects a DDoS attack. When the attack ends, Flowtriq restores normal security settings. No manual intervention required.

How It Works

ftagent
Monitors traffic
Flowtriq
Detects DDoS attack
Cloudflare API
security_level = under_attack
Cloudflare Zone
Under Attack Mode active

When the attack ends, Flowtriq calls the API again to restore security_level to "medium".

Setup

Connect in three steps

1. Create a Cloudflare API token
Cloudflare Dashboard > My Profile > API Tokens > Create Token Permission: Zone > Zone Settings > Edit Zone Resources: Include > Specific zone (or All zones)
2. Get your Zone ID
Cloudflare Dashboard > Select your domain > Overview Zone ID is shown in the right sidebar under "API"
3. Configure in Flowtriq
Flowtriq Dashboard > Settings > Integrations > Cloudflare API Token: your-cloudflare-api-token Zone ID: your-zone-id

Flowtriq will automatically toggle Under Attack Mode on your Cloudflare zone when DDoS attacks are detected.

Capabilities

Automated DDoS response for Cloudflare zones

Under Attack Mode Toggle

When Flowtriq detects a DDoS attack, it calls the Cloudflare API to set security_level to "under_attack". This presents JavaScript challenges to all visitors, filtering out attack traffic at Cloudflare's edge before it reaches your origin.

Automatic Restore

When the attack ends, Flowtriq restores the security_level to "medium" automatically. Your site returns to normal operation without anyone needing to log into the Cloudflare dashboard to flip the switch manually.

Full Alert Pipeline

The Cloudflare integration works alongside all Flowtriq alert channels. Get notified via Discord, Slack, PagerDuty, or email when Under Attack Mode is activated and when it is restored.

Zero Manual Intervention

No more waking up at 3am to enable Under Attack Mode. Flowtriq handles the entire lifecycle: detect the attack, enable protection, wait for the attack to end, and restore normal settings.

Automate your Cloudflare DDoS response

Connect Flowtriq to Cloudflare and let Under Attack Mode activate automatically when you need it.

Works with all Cloudflare plans | Back to Integrations

FAQ

Frequently Asked Questions

How does Flowtriq integrate with Cloudflare?

When Flowtriq detects a DDoS attack targeting an IP or zone configured with Cloudflare, it calls the Cloudflare API to set the security_level to "under_attack". This enables Cloudflare's Under Attack Mode, which presents JavaScript challenges to visitors. When the attack ends, Flowtriq restores the security_level to "medium".

What Cloudflare permissions are needed?

You need a Cloudflare API token with Zone Settings:Edit permission for the zones you want Flowtriq to manage. Create the token in your Cloudflare dashboard under My Profile > API Tokens. You also need the Zone ID, found on the zone overview page.

Does this work with the free Cloudflare plan?

Yes. Under Attack Mode and the security_level API are available on all Cloudflare plans, including the free tier. No paid Cloudflare plan is required for this integration.

What happens when the attack ends?

Flowtriq automatically restores the security_level to "medium" when the attack is no longer detected. This removes the JavaScript challenge page and returns your site to normal operation without manual intervention.