Cloudflare Gateway PAC builder

Builds a PAC file for a Cloudflare Gateway proxy endpoint with the required HTTPS directive and port 443, the identity-provider bypass Cloudflare marks as critical, and the private-network and plain-hostname bypasses of Cloudflare's template without a DNS lookup per request.

Cloudflare’s templates are a good base: correct RFC 1918 masks, loopback as a /8, lower-cased host, IdP bypass first. Two things are changed here. The private-network test is guarded by an IP-literal check instead of calling dnsResolve(host) for every request (one DNS dependency is qualitatively different from none), and the *.local bypass is optional because some networks still use .local as an internal DNS suffix.

Not using a security service edge? The PAC file generator builds a file for your own proxies.

From the proxy endpoint you created in Cloudflare One (Networks > Resolvers and proxies > Proxy endpoints).

    Cloudflare's template marks the IdP bypass as critical for authorization endpoints.

      One per line; the domain and all its subdomains are matched.

        One per line, without a leading dot; the domain and all its subdomains are matched.

          Uses an IP-literal test in front of isInNet, so host names never trigger a DNS lookup. See isinnet-on-hostname.

            Cloudflare's template includes this. Leave it off if .local is an internal DNS suffix in your network; the checker notes it either way. See dot-local-direct.

              Generated proxy.pac

              Deploying it

              Host the file as a Cloudflare-hosted PAC (https://pac.cloudflare-gateway.com/<account-id>/<slug>, 256 KB limit) or on your own server with Cache-Control: max-age set, so that browsers pick up changes without clearing their cache. Safari and iOS/iPadOS cannot use an HTTPS proxy endpoint.

              What the Cloudflare pack checks

              A Gateway proxy endpoint is a TLS-terminating proxy, so the PAC must return HTTPS <subdomain>.proxy.cloudflare-gateway.com:443; a PROXY directive to the same host fails. Chromium browsers and Firefox support HTTPS proxies through a PAC file; Safari and iOS/iPadOS do not. Cloudflare’s templates place identity-provider, private-network and streaming bypasses in the PAC because Gateway has no other place for them in this deployment model. Two refinements this site applies on top of the published templates: resolve private ranges without a DNS lookup on every request (guard isInNet with an IP-literal test instead of dnsResolve(host)), and set Cache-Control: max-age on the hosted file instead of asking users to clear their browser cache.
              • Directive: HTTPS, not PROXY; port 443. Authorization endpoints require TLS inspection and a browser that can complete the Access login.
              • Safari and iOS/iPadOS do not support the HTTPS proxy type; WinHTTP support is not yet verified in a lab run.
              • Hosted PAC files: https://pac.cloudflare-gateway.com/<account-id>/<slug>, 256 KB per file.
              • The published templates call dnsResolve(host) for every request; the generator here keeps the same bypasses with an IP-literal guard, so hostnames never trigger a lookup.

              Sources

              Vendor documentation the pack rests on, fetched on the date shown.