Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-16T19:24:14Z0bb47cb4564f8a87d083242da87df984bca297cf5f49edc3c7aa0b2725694bd8
account-abuse-protectionacme-validationai-securityapi-tokenscgnatclient-side-securitycloudflarecloudy-llmddos-reportdetectionleast-privilegelog-explorermanaged-oauthoauthpingorapost-quantumpq-cryptographyradarrequest-smugglingresource-scoped-permissionsscannable-api-tokensvulnerability-scannerworkers-vpc

What happened

Collection of Cloudflare security announcements (Apr 2026): introduces scannable API tokens, enhanced OAuth visibility, and GA of resource-scoped permissions to support least-privilege; Managed OAuth for Access (RFC 9728) for agent-safe internal app access; moves target for full post‑quantum rollout to 2029. Additional items include Client‑Side Security made broadly available, Account Abuse Protection (Early Access), AI Security for Apps GA, Log Explorer enhancements for multi‑vector investigations, and new Web & API Vulnerability Scanner. Cloudflare also discloses and fixes security issues: a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
0bb47cb4564f8a87d083242da87df984bca297cf5f49edc3c7aa0b2725694bd8
Enrichment time
2026-04-16T19:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Securing non-human identities: automated revocation, OAuth, and scoped permissions · Baitaphish