Manage Cloudflare from your phone.
DNS, firewall, analytics, Workers and an AI assistant in one clean Android app.
Important
This is the foss branch. It builds the same app without ads, without Google Play billing and without any Google Play services library. Every feature is unlocked, and usage signals are off unless you turn them on. It is the branch used for GitHub Releases and F-Droid; the Play Store build comes from main.
Note
CloudFlare Mobile is an independent, unofficial client. It is not affiliated with, endorsed by or sponsored by Cloudflare, Inc. It talks to the official Cloudflare API with your own API token.
Screenshots use demo data.
|
|
|
|
|
|
Also in the app: Email Routing, cache purge, page rules, account audit logs, and screens for many more Cloudflare products. docs/ROADMAP.md tracks what is finished and what is still read-only.
1. Create a Cloudflare API token
API Token (recommended)
-
Sign in at dash.cloudflare.com
-
Open My Profile → API Tokens → Create Token
-
Start from the Edit zone DNS template, or build a custom token with only what you need:
Permission Used for Zone:ReadListing zones Zone Settings:Read/EditSSL, cache and zone switches DNS:Read/EditDNS records Firewall Services:Read/EditFirewall rules Analytics:ReadAnalytics Workers Scripts:Read/EditWorkers Account Settings:ReadAccount info -
Create the token and copy it. Cloudflare shows it only once.
Global API Key (not recommended)
My Profile → API Tokens → Global API Key → View. You also need your Cloudflare email. This key has full access to the whole account, so prefer a scoped token.
2. Sign in
Open the app, pick API Token or Global Key, paste your credentials and tap Sign In. A token that lacks a permission only hides the section that needs it; the rest of the app keeps working.
3. Find your way around
| Tab | What it does |
|---|---|
| Dashboard | Zone counts, quick actions, shortcuts |
| Zones | Every zone, with search. Tap one to manage it |
| AI Chat | Ask the assistant to inspect or change a zone |
| Services | Workers, KV, R2, Pages, D1 and other account products |
| Settings | Theme, language, accounts, app lock |
| Credentials | Stored on your device with hardware-backed encryption. Sent only to api.cloudflare.com. |
| AI features | Send the zone configuration needed to answer to a hosted backend. Your API token is never sent to it. That backend is not part of this repository. |
| Ads | The free version shows ads. A one-time purchase removes them. |
| Policy | Privacy policy |
| Auth method | Header | Scope |
|---|---|---|
| API Token | Authorization: Bearer <token> |
Scoped. Recommended. |
| Global API Key | X-Auth-Email + X-Auth-Key |
Full account access. |
Requirements: Node.js 18+, JDK 17+, Android Studio with the Android SDK.
git clone https://github.com/imtaqin/CFMobile.git
cd CFMobile
npm install
npx expo run:android| Command | What it does |
|---|---|
npx expo start |
Start the dev server |
npx expo run:android |
Build and run on a device or emulator |
npx tsc --noEmit |
Typecheck. Must be clean |
npm test |
Run the Jest tests |
npm run cf:schema then npm run cf:docs |
Regenerate the API reference in docs/cf-api/ |
node scripts/i18n-translate.js <namespace> <source.json> |
Translate new strings into all 12 locales |
Release build
npx expo prebuild --platform android
cd android && ./gradlew bundleRelease
# android/app/build/outputs/bundle/release/app-release.aabRelease signing reads its keystore settings from your own Gradle properties. Updates ship through Google Play.
app/ Expo Router screens
(tabs)/ dashboard, zones, ai-chat, services, settings
zone/[id]/ zone-scoped screens (dns, ssl, firewall, analytics, ...)
d1/ kv/ r2/ storage browsers
worker-tail/ live Worker logs
components/ui/ shared UI kit (see docs/UI_STYLE.md)
services/ cloudflare.ts (all API calls), ai.ts, premium.ts, ...
contexts/ auth (multi-profile), theme
locales/ 12 languages, identical key sets
docs/cf-api/ generated Cloudflare API reference
store/ Play Store screenshots, icon and listing sources
React Native 0.81 · Expo SDK 54 · Expo Router · TypeScript · Axios · i18next · react-native-svg · Expo Secure Store · react-native-iap · Google Mobile Ads
- Rate limits. Cloudflare allows 1,200 API requests per five minutes. Requests are not batched, so heavy use can hit the limit.
- No offline mode. Everything is fetched live.
- Android first. iOS is untested.
- Two-factor auth. The app signs in with API tokens, not your dashboard password.
MIT







