Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-17T07:24:06Z2a7fa550f692628f71202df992a4953c879194a598c8e7377dca3cb3b401d100
acme-validationai-securityapi-securityapi-tokenscgnatclient-side-securitycloudflareddosleast-privilegelog-explorermanaged-oauthmatrixmcpoauthpingorapost-quantumrequest-smugglingscoped-permissionsvulnerability-disclosureworkers-vpc

What happened

Collection of Cloudflare security product updates and vulnerability disclosures (Apr 2026). Key items: new scannable API tokens, enhanced OAuth visibility and Managed OAuth (RFC 9728) for agent-safe auth, GA of resource-scoped permissions to enable least-privilege, and Code Mode/controls for MCP governance. Cloudflare accelerated its post-quantum roadmap target to 2029 and expanded observability (Radar PQ metrics, KT logs, ASPA). Security product launches and enhancements include Client‑Side Security (open to all with AI/graph detection), AI Security for Apps (GA) and free AI discovery, Web &/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
2a7fa550f692628f71202df992a4953c879194a598c8e7377dca3cb3b401d100
Enrichment time
2026-04-17T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.