You do not have to move a domain's DNS to us to manage it from the toolbox. If the zone is already on Cloudflare, connecting it means the record editor works on the records where they actually live, and nothing about the domain's nameservers changes.
That is the whole point of connecting rather than transferring. The domain stays registered here, the zone stays on Cloudflare, and the toolbox gets a way to read and write it.
What connecting needs
A Cloudflare API token, created in your own Cloudflare account, scoped to what this actually needs. Two permissions are required:
Zone · DNS · Edit so the toolbox can change records, and Zone · Zone · Read so it can list them and know which zone it is working with.
A token with only those two works fully. Everything else is optional, and the Cloudflare token screen marks the optional rows as such, so it is clear which ones you can skip.
The optional one worth knowing about
There is a third permission you may want: Registrar · Read.
Grant it and the Domains list can show each domain's transfer lock and auto-renew state, which is otherwise only visible inside your Cloudflare dashboard. It is an account-level permission, so it covers every domain in the account rather than just the one you are connecting.
That is a real trade and worth thinking about rather than accepting by default. It is read-only and cannot change anything, but it does widen what one token can see. If you only want the toolbox managing records, leave it off.
Anything to do with zone settings, configuration rules or cache rules is for hosting features that may come later. None of it is needed now.
How the token is handled
It is encrypted before it is stored, it does not appear on any page again after you save it, and it is used only to make the DNS changes you ask for.
Disconnecting removes it from here immediately. That is not the same as revoking it, though, and the difference is worth knowing. The token still exists in your Cloudflare account until you delete it there. If you want it gone for good rather than merely unused, revoke it in Cloudflare as well.
What changes, and what does not
The nameservers do not move. The zone stays on Cloudflare and keeps answering for the domain exactly as it did, so there is no propagation wait and no window where the domain resolves to nothing. This is the reason to connect rather than to change nameservers when the DNS is already somewhere you are happy with.
What changes is that managing DNS records now works from the toolbox for that domain. The Domains list names the DNS provider per domain, so it is checkable at a glance which ones you are managing here and which you are not.
If you would rather the DNS lived with us instead, that is a different job and it does move the nameservers. Changing nameservers covers that side, including why the records should exist at the destination before the move rather than after.
If a token does not work
A token that is refused is almost always scope rather than typing. A token created for a different zone, or one missing Zone · DNS · Edit, connects but cannot change anything, and the failure appears when you try to save a record rather than when you connect.
Create the token with the zone selected explicitly rather than account-wide. An account-wide token is more powerful than this needs, and it is the sort of thing that outlives the reason it was created.
EnterraHost