Securing non-human identities: automated revocation, OAuth, and scoped permissions
2026-04-16T19:24:14Z•0bb47cb4564f8a87d083242da87df984bca297cf5f49edc3c7aa0b2725694bd8
account-abuse-protectionacme-validationai-securityapi-tokenscgnatclient-side-securitycloudflarecloudy-llmddos-reportdetectionleast-privilegelog-explorermanaged-oauthoauthpingorapost-quantumpq-cryptographyradarrequest-smugglingresource-scoped-permissionsscannable-api-tokensvulnerability-scannerworkers-vpc
What happened
Collection of Cloudflare security announcements (Apr 2026): introduces scannable API tokens, enhanced OAuth visibility, and GA of resource-scoped permissions to support least-privilege; Managed OAuth for Access (RFC 9728) for agent-safe internal app access; moves target for full post‑quantum rollout to 2029. Additional items include Client‑Side Security made broadly available, Account Abuse Protection (Early Access), AI Security for Apps GA, Log Explorer enhancements for multi‑vector investigations, and new Web & API Vulnerability Scanner. Cloudflare also discloses and fixes security issues: a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- 0bb47cb4564f8a87d083242da87df984bca297cf5f49edc3c7aa0b2725694bd8
- Enrichment time
- 2026-04-16T19:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.