Securing non-human identities: automated revocation, OAuth, and scoped permissions
2026-04-30T07:24:09Z•114e18dce6f330b522f4a77722b315434f979e0e3deb06b48a4642de208d7a04
RFC9728account-abuseacmeai-detectionai-security-for-appsapi-tokenscertificate-validationcgnatclient-side-securitycloudflareddosfraud-preventionleast-privilegelog-explorermanaged-oauthnon-human-identitiesoauthpingorapost-quantumpq-cryptographyradarrequest-smugglingresource-scoped-permissionsvulnerability-scannerworkers-vpc
What happened
Collection of Cloudflare blog posts (late 2025–Apr 2026) announcing multiple security product launches, feature upgrades, and vulnerability disclosures. Highlights include: scannable API tokens and resource-scoped permissions GA for least-privilege API access; Managed OAuth for Access (RFC 9728) for agent-safe auth; a move to target full post-quantum deployment by 2029; Client-Side Security made generally available with improved AI detection; Account Abuse Protection (Early Access); AI Security for Apps GA and free AI discovery; a new Web & API vulnerability scanner; expanded Log Explorer data
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- 114e18dce6f330b522f4a77722b315434f979e0e3deb06b48a4642de208d7a04
- Enrichment time
- 2026-04-30T07:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.