Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-30T07:24:09Z114e18dce6f330b522f4a77722b315434f979e0e3deb06b48a4642de208d7a04
RFC9728account-abuseacmeai-detectionai-security-for-appsapi-tokenscertificate-validationcgnatclient-side-securitycloudflareddosfraud-preventionleast-privilegelog-explorermanaged-oauthnon-human-identitiesoauthpingorapost-quantumpq-cryptographyradarrequest-smugglingresource-scoped-permissionsvulnerability-scannerworkers-vpc

What happened

Collection of Cloudflare blog posts (late 2025–Apr 2026) announcing multiple security product launches, feature upgrades, and vulnerability disclosures. Highlights include: scannable API tokens and resource-scoped permissions GA for least-privilege API access; Managed OAuth for Access (RFC 9728) for agent-safe auth; a move to target full post-quantum deployment by 2029; Client-Side Security made generally available with improved AI detection; Account Abuse Protection (Early Access); AI Security for Apps GA and free AI discovery; a new Web & API vulnerability scanner; expanded Log Explorer data

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
114e18dce6f330b522f4a77722b315434f979e0e3deb06b48a4642de208d7a04
Enrichment time
2026-04-30T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Securing non-human identities: automated revocation, OAuth, and scoped permissions · Baitaphish