Cloudflare deprecated the Origin CA Key at the end of September 2026 and replaced it with API tokens for specific actions.
There are a number of great caching plugins but I am using Super Page Cache that connects to Cloudflare caching performance.
Here here is a step by step guide to connecting Super Page Cache to your website in Cloudflare.
1. Log into Cloudflare
Go to your Cloudflare dashboard.
Then go to:
My Profile → API Tokens → Create Token.
From here you can select a custom token or use one of the templates. The API token is not generic key, it is a token assigned to a specific project.
2. Click Create Token
You’ll see a list of templates.
Look for:
WordPress
and click:
Use template
This will take your through to further options.
3. Add and edit permissions
This is the most important part so must be completed correctly.
Scroll down to the Permissions section.
You should already have a number of permissions populated by the WordPress template.
Click + Add more / Add permission.
Add:
Zone → Cache Rules → Edit
Then add:
Zone → Transform Rules → Edit
Your final permission list should therefore contain the permissions from the WordPress template plus those two.
4. Restrict the token to your website
This is and import security setting.
Find:
Zone Resources
Instead of:
All zones
choose:
Include → Specific zone
Then select the domain you’re setting up.
For example:
website.com
This means the token can only control Cloudflare settings for that particular website.
Previously, every website had the same API token, now every website should have its own API token so all your websites will need updating.
5. Set an expiration
If Cloudflare gives you the option, you can set an expiration date.
It is not necessary to have an experation date for connecting Cloudflare to a caching plugin as the project is continuous.
6. Click Continue to summary
These are the setting for the zones, edit them as they are below.
Zone – Zone – Read Zone – Zone Settings – Edit Zone – DNS – Read Zone – Cache Purge Zone – Analytics – Read Account – Account Settings – Read Zone – Cache Rules – Edit Zone – Transform – Edit
The exact list displayed can vary slightly with Cloudflare’s current interface/template, but the two bold permissions are the ones that Super Page Cache specifically must be included.
7. Click Create Token
Cloudflare will only show you the token once. So copy it then take a screen shot in case you need to use it.
Copy it immediately.
Paste it into the section required in Super Page Cache.
8. Put it into Super Page Cache
Go to Super Page Cache and input the API directly into the Cloudflare connection box.
WordPress Admin → Super Page Cache → Settings → Cloudflare
Connect to Cloudflare.
9. Select your domain
After the token has been successfully authenticated, Super Page Cache should ask you to select the domain.
Add domain relating to the connection.
Choose the Cloudflare zone corresponding to your WordPress site.
Then save the domain.
10. Enable Cloudflare CDN & Caching
Enable Cloudflare CDN & Caching in Super Page Cache
Update Settings
An important point here: you don’t normally need to manually create the Cloudflare Cache Rule yourself.
Super Page Cache is designed to create and manage its own Cloudflare cache rule after you connect the account and select the correct zone.
Cloudflare has deprecated Service Key authentication
Cloudflare has deprecated Service Key authentication, as of September 30, 2026, replaced with API tokens.
So if Super Page Cache is currently showing Origin API deprecated, you want a new Cloudflare API Token with the permissions above.