Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-28T19:24:21Z275973bfe8d22015f2645897e66a25087dcdc1702b7162dc7e590dfd66cea5d3
OAuthRFC-9728account-abuse-protectionacmeacme-validationai-security-for-appsapi-tokensautomated-revocationclient-side-securitycloudflareddosdeveloper-securitykt-logs-key-transparency','aspa'least-privilegemanaged-oauthpingorapingora-0.8.0post-quantumpost-quantum-cryptographyradarrequest-smugglingresource-scoped-permissionsscoped-permissionsvulnerability-mitigationweb-api-scanner

What happened

Collection of Cloudflare security announcements (Mar–Apr 2026) covering developer and platform protections: scannable API tokens, automated token revocation, GA resource-scoped permissions and least-privilege tooling, Managed OAuth for Access (RFC 9728) for agent-safe auth, and expanded OAuth visibility. Product/security launches include AI Security for Apps GA, Client-Side Security opened to all with cascade AI detectors, Account Abuse Protection (Early Access), a new Web/API vulnerability scanner, expanded Log Explorer datasets, and Cloudy (LLM explanation layer). Operational/security posts:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
275973bfe8d22015f2645897e66a25087dcdc1702b7162dc7e590dfd66cea5d3
Enrichment time
2026-04-28T19:24:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.