Skip to content

Session identifiers

Last updated View as MarkdownAgent setup

While not strictly required, it is recommended that you configure your session identifiers when getting started with API Shield. When Cloudflare inspects your API traffic for individual sessions, we can offer more tools for visibility, management, and control.

If you are unsure of the session identifiers that your API uses, consult with your development team.

Session identifiers should uniquely identify API clients. A common session identifier for API traffic is the Authorization header. When a JSON Web Token (JWT) is used by the API for client authentication, its value may change over time. You can use a claim value inside the JWT such as sub or email as a session identifier to uniquely identify the session over time.

If no session identifiers are configured and the Authorization header appears on more than 1% of eligible sampled client requests with 2xx responses, Cloudflare automatically configures that header as the API Shield session identifier. Cloudflare does not overwrite an existing session identifier configuration.

To set up session identifiers

You can configure up to 10 session identifiers.

  1. In the Cloudflare dashboard, go to the Security Settings page.

    Go to Settings ↗
  2. Filter by API abuse.

  3. On Session identifiers, select Configure session identifiers.

  4. Select Manage identifiers.

  5. Choose the type of session identifier (cookie, HTTP header, or JWT claim).

  6. Enter the name of the session identifier.

  7. Select Save.

API Shield generates rate limiting recommendations for eligible saved operations. Recommendations require API Shield access, a configured session identifier that matches operation traffic, sufficient data, and completed processing. After these requirements are met, you can view per-operation and per-session recommendations and create rate limiting rules.

Discovery can use configured session identifiers as one signal when identifying API traffic. Session identifiers also support session traffic analysis in Sequence Analytics.

Was this helpful?