How to prevent abuse from bots?

Sadly, Bubble does not support using your own Cloudflare account in Proxy mode, so all of the protections that a Cloudflare WAF, cache, bot fight mode, etc can offer you are not available to Bubble customers.

Bubble should offer customers a choice:

  1. Use Bubble’s Enterprise Cloudflare account, or
  2. BYOC - Bring your own Cloudflare

There’s also this feature called Orange to Orange for SaaS providers:

According to ChatGPT:

If Bubble were to integrate Cloudflare for SaaS on their backend—onboarding each customer’s custom hostname into Bubble’s Cloudflare zone via the Cloudflare for Platforms APIs—then their customers could simply create a CNAME record in their Cloudflare DNS, turn on the orange‑cloud proxy for that CNAME, and automatically get an Orange‑to‑Orange (O2O) setup. Traffic would first hit the customer’s zone (applying their Cloudflare rules) and then pass through Bubble’s zone (applying Bubble’s rules) before reaching Bubble’s origin.