Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-24T19:24:10Z3ba82d4e58606cfbe5c4a09cd88725a200d04335510f79f0dfd01484c8528c22
ACMEACME validation vulnerabilityAI Security for Apps','AI discovery','account abuse protection'AI detectionAPI tokensCloudflareCloudflare GatewayCode ModeMCPManaged OAuthOAuthPingoraPingora 0.8.0RFC 9728Shadow MCPWeb & API Vulnerability Scannercertificate validationclient‑side securitydeveloper securityleast privilegenon‑human identitiesrequest smugglingresource‑scoped permissionsscannable tokensvulnerability disclosure

What happened

Cloudflare published a broad set of security-focused updates: new developer security features for non-human identities (scannable API tokens, enhanced OAuth visibility, GA resource‑scoped permissions, Managed OAuth adopting RFC 9728), guidance and tooling for MCP adoption (including Code Mode and Shadow MCP detection), and expanded visibility and protection products (AI Security for Apps GA, Client‑Side Security opened to all, Account Abuse Protection EA, Log Explorer multi‑dataset support, and a new Web & API Vulnerability Scanner). They disclosed and fixed specific vulnerabilities — notably,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
3ba82d4e58606cfbe5c4a09cd88725a200d04335510f79f0dfd01484c8528c22
Enrichment time
2026-04-24T19:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.