API Shield's labeling service helps you organize your endpoints and address vulnerabilities in your API. The labeling service includes managed and user-defined labels.
Managed labels help you organize endpoints by use case. Cloudflare automatically applies selected managed labels based on observed endpoint use cases and risks that may need attention.
You can also create user-defined labels and add them to individual or multiple endpoints. User-defined labels are useful for organizing your endpoints by owner, version, or type.
You can filter your endpoints based on the labels.
Use managed labels to identify endpoints by use case. Cloudflare automatically applies selected managed labels, and you can also apply managed labels manually.
cf-api-endpoint: Add this label to endpoints that serve machine-readable data or facilitate programmatic interaction.
cf-log-in: Add this label to endpoints that accept user credentials. You may have multiple endpoints if you accept username, password, and multi-factor authentication (MFA) across multiple endpoints or requests.
cf-sign-up: Add this label to endpoints that are the final step in creating user accounts for your site or application.
cf-content: Add this label to endpoints that provide unique content, such as product details, user reviews, pricing, or other unique information.
cf-purchase: Add this label to endpoints that are the final step in purchasing goods or services online.
cf-password-reset: Add this label to endpoints that participate in the user password reset process. This includes initial password reset requests and final password reset submissions.
cf-add-cart: Add this label to endpoints that add items to a user's shopping cart or verify item availability.
cf-add-payment: Add this label to endpoints that accept credit card or bank account details where fraudsters may iterate through account numbers to guess valid combinations of payment information.
cf-check-value: Add this label to endpoints that check the balance of rewards points, in-game currency, or other stored value products that can be earned, transferred, and redeemed for cash or physical goods.
cf-add-post: Add this label to endpoints that post messages in a communication forum, or product or merchant reviews.
cf-account-update: Add this label to endpoints that participate in user account or profile updates.
cf-llm: Services that are (partially) powered by Large Language Model (LLM).
cf-mcp: Add this label to endpoints that implement the Model Context Protocol (MCP) for AI tool and data access.
cf-rss-feed: Add this label to endpoints that expect traffic from RSS clients.
cf-web-page: Add this label to endpoints that serve HTML pages.
cf-contains-ads: Add this label to endpoints that serve web pages containing advertisements.
Cloudflare automatically scans your saved endpoints for risks approximately once a day. API Shield applies these labels when a scan finds security risks on your endpoints. A corresponding Security Center Insight is also raised when risks are found.
cf-risk-missing-auth: Automatically added when all successful requests lack a configured session identifier. Refer to Authentication Posture for more information.
cf-risk-mixed-auth: Automatically added when some successful requests contain a configured session identifier and some successful requests lack one. Refer to Authentication Posture for more information.
cf-risk-sensitive: Automatically added to endpoints when HTTP responses match the WAF's Sensitive Data Detection ruleset.
cf-risk-errors-anomaly: Automatically added when an endpoint experiences a recent increase in response errors over the last 24 hours.
cf-risk-latency-anomaly: Automatically added when an endpoint experiences a recent increase in response latency over the last 24 hours.
cf-risk-size-anomaly: Automatically added when an endpoint experiences a spike in response body size over the last 24 hours.
cf-risk-bola-enumeration: Automatically added when some sessions request unusually many distinct combinations of path parameter values for an endpoint compared with other sessions.
cf-risk-bola-pollution: Automatically added when Cloudflare detects an unusual pattern of requests that send different values for the same parameter in its schema-defined location and an unexpected request location. Only requests whose responses have status codes below 400 contribute.
cf-risk-zombie: Automatically added when a saved endpoint has not received traffic in 32 days.
How you address risks to your endpoints will depend on its label(s). The following steps provide you with general guidelines on how to take action on them.
-
Review risks to endpoints.
View the endpoints labeled as risks and identify if they have been labeled for other risks.
For example, endpoints labeled
Go to Web assets ↗cf-risk-sensitiveandcf-risk-missing-authorcf-risk-mixed-authmay return sensitive data in successful responses that lack a configured session identifier.Go to the details pages for endpoints labeled as
cf-risk-missing-authorcf-risk-mixed-auth, and check for recent changes in configured session identifier presence in the last 24 hours and seven days. -
Review traffic to these labeled endpoints in Security Analytics.
Check for unexpected traffic sources and note any irregular traffic patterns.
Go to Analytics ↗ -
Review your origin's authorization and authentication policies with your development team.
Speak with your developers or application owners in your organization to understand whether or not all requests to these endpoints should be authenticated. Modify your application to consistently enforce the authentication requirement for all traffic accessing these endpoints.
Refer to Authentication Posture for more information.
You can query the matched operation and managed labels for individual requests using the GraphQL Analytics API. The webAssetsOperationId and webAssetsLabelsManaged fields are available in the httpRequestsAdaptive and httpRequestsAdaptiveGroups datasets. Use introspection to explore the full schema and available filter operators.
webAssetsLabelsManaged returns at most 10 labels per request.
The following query returns the count of requests per operation ID and managed label set, filtered to requests where the matched operation carries the cf-log-in managed label.
query GetAdaptiveGroups($start: DateTime!, $end: DateTime!) {
viewer {
zones(filter: { zoneTag: $zoneTag }) {
httpRequestsAdaptiveGroups(
filter: {
datetime_geq: $start
datetime_leq: $end
requestSource: "eyeball"
webAssetsLabelsManaged_hasany: ["cf-log-in"]
}
limit: 25
orderBy: [count_DESC]
) {
count
dimensions {
webAssetsOperationId
webAssetsLabelsManaged
}
}
}
}
}Replace cf-log-in with any managed label or risk label. You can also omit the webAssetsLabelsManaged_hasany filter and use webAssetsOperationId as the sole dimension to group traffic by matched operation regardless of label.
You can export per-request Web Assets data to your storage or SIEM system of choice using Logpush. The WebAssetsOperationID and WebAssetsLabelsManaged fields are available in the HTTP requests dataset.
-
In the Cloudflare dashboard, go to the Security Settings page.
Go to Settings ↗ -
Filter by API abuse.
-
Under Endpoint labels, select Manage labels.
-
Name the label and add an optional label description.
-
Apply the label to your selected endpoints.
-
Select Create label.
Alternatively, you can create a user-defined label via Security > Web Assets.
-
In the Cloudflare dashboard, go to the Web Assets page.
Go to Web assets ↗ -
Go to the Operations tab.
-
Choose the endpoint that you want to label.
-
Select Edit endpoint labels.
-
Under User, select Create user label.
-
Enter the label name.
-
Select Create.
-
In the Cloudflare dashboard, go to the Web Assets page.
Go to Web assets ↗ -
In the Operations tab, choose the endpoint that you want to label.
-
Select Edit endpoint labels.
-
Add the label(s) that you want to use for the endpoint from the list of managed and user-defined labels.
-
Select Save labels.
-
In the Cloudflare dashboard, go to the Security Settings page.
Go to Settings ↗ -
Filter by API abuse.
-
On Endpoint labels, select Manage labels.
-
On the existing label that you want to apply to multiple endpoints, select Bulk apply.
-
Choose the endpoints that you want to label by selecting its checkbox.
-
Select Apply label.
User-defined endpoint labels are available to all customers. Managed endpoint labels require an API Shield subscription.