Generate the service token under Zero Trust, Access controls, Service credentials, and store the Client Secret immediately in your secret manager; there is no retrieve step. Then add a Service Auth policy including that token on the application. If your automation gets an IdP login page instead of access, the policy action is wrong, not the token.

Context: Official docs (Service tokens, Cloudflare One): documents a gotcha that trips agents provisioning machine access. The Client Secret is displayed exactly once when you generate the token; lose it and you must regenerate. The same page notes the policy accepting the token must use the Service Auth action, otherwise Access prompts for an identity provider login instead of accepting the token. New secrets also use a cfast-prefixed format that is easier for credential scanners to spot.