Monitor Cloudflare.Hear only when it matters.

Watch Workers, Pages, and zones from a single sign-in.

What Beaam does with Cloudflare

One read-only API token imports every Cloudflare resource across every account it reaches. Beaam reads the GraphQL Analytics API each minute and alerts when something is actually failing — not when traffic merely changes.

What raises an incident

Curated deliberately: a short list worth your attention, not every metric that exists. Signals that can blip need repeated evidence before Beaam calls them; a reading that is definitive by nature — the provider reporting a failure outright — alerts on the first observation.

SignalWhen Beaam speaks up
Worker error rateErrors as a share of invocations, once at least 20 requests were observed. A quiet or tiny window never pages overnight.
Pages deployment failuresThe latest production deployment failing, which leaves the previous build serving.
Durable Object error rateErrors as a share of DO invocations, after at least 20 requests.
Zone 5xx ratioShare of edge responses that were 5xx after at least 20 requests, weighted so a busy bucket is not averaged against an idle one.
Queue delivery failuresFailed and dead-lettered messages alert after 2 of 3 checks.

Also collected, but quiet

Charted on the service page and there for context when something does break — but it will not wake you unless you ask it to.

  • Worker requests, subrequests, CPU time p99
  • Zone requests, bytes, 4xx ratio
  • R2 and KV operations
  • D1 queries, latency and storage
  • Queue flow and backlog

What connecting needs

  • Sign in with Cloudflare: Beaam requests read scopes only — account-settings.read, workers-scripts.read, page.read, workers-r2.read, workers-kv-storage.read, d1.read, queues.read, zone.read, analytics.read, account-analytics.read — plus offline_access so the connection can renew itself.
  • API token instead: start from Cloudflare's Read all resources template, or grant Account Analytics Read plus a read permission for each product you want discovered.
  • A product the credential cannot read is skipped and named on the integration page, not treated as a failed connection.
  • Analytics dataset availability and retention vary by Cloudflare plan. A dataset your plan does not include is reported as unavailable.

What Beaam will not tell you

Stated rather than discovered later. Some of these are deliberate — an alert that is not about your system is noise — and some are simply where this integration's view ends.

  • Pages Functions errors cannot be attributed to a project through Cloudflare's analytics, so Pages alerts on failed production deployments only. Beaam offers a one-click HTTP check of each project's pages.dev address to cover whether it answers.
  • R2 and KV report a daily cumulative count with no error signal: charted, with no default alert. D1 has no default alert either, because the right threshold depends on a plan Beaam is not told.
  • Error-rate alerts wait for at least 20 requests in the window (3 for a near-total failure), so a quiet Worker cannot page you at 3am over two bad requests.
  • Metrics are always about a minute behind, the time Cloudflare takes to publish them.
  • Queue backlog age, CPU and traffic volume are collected but off by default.

setup

Designed to stay small

Sign in with Cloudflare and approve read-only access — no token to create. Beaam imports every resource it can reach; an API token still works if your organisation blocks third-party apps.

Beaam applies sensible defaults. Threshold configuration is optional, not onboarding.

access

Never writes, and revocable

Beaam never writes to Cloudflare. Credentials are encrypted with AES-256-GCM using a key held as a deploy secret, and are deleted immediately when you disconnect.

How Beaam handles credentials →

Questions

What does Beaam alert on for Cloudflare?

5 signals can raise an incident: Worker error rate, Pages deployment failures, Durable Object error rate, Zone 5xx ratio, Queue delivery failures. Everything else is collected for context but stays quiet until you opt in.

How long does it take to connect Cloudflare?

Sign in with Cloudflare and approve read-only access — no token to create. Beaam imports every resource it can reach; an API token still works if your organisation blocks third-party apps. Most connections are watching within a few minutes, and you can send a test alert immediately to prove the path works end to end.

Does Beaam need write access to Cloudflare?

No. Beaam only ever performs read operations — there is no code path that writes to a connected provider. Worth separating from that: what Beaam *does* and what a token *permits* are different things. Where Cloudflare offers a read-scoped credential, use it; some providers only issue tokens carrying broader rights than Beaam uses, which is a property of their API rather than of Beaam's behaviour. Scope it as narrowly as the provider allows. Credentials are encrypted with AES-256-GCM before storage and deleted the moment you disconnect.

What does Cloudflare monitoring cost?

The free plan covers two integrations and five watched services, with email, Slack and webhook alerts. Solo is $19/month flat for unlimited integrations, services and organizations, with collaborators included — there is no per-host, per-check or per-alert metering.

Watching more than Cloudflare?

Most stacks are several services with seams between them, and the seams are where the damaging failures hide. Beaam correlates across every connected integration, so a database problem reads as one incident rather than five alarms from five tools.