Securing non-human identities: automated revocation, OAuth, and scoped permissions
2026-04-24T19:24:10Z•3ba82d4e58606cfbe5c4a09cd88725a200d04335510f79f0dfd01484c8528c22
ACMEACME validation vulnerabilityAI Security for Apps','AI discovery','account abuse protection'AI detectionAPI tokensCloudflareCloudflare GatewayCode ModeMCPManaged OAuthOAuthPingoraPingora 0.8.0RFC 9728Shadow MCPWeb & API Vulnerability Scannercertificate validationclient‑side securitydeveloper securityleast privilegenon‑human identitiesrequest smugglingresource‑scoped permissionsscannable tokensvulnerability disclosure
What happened
Cloudflare published a broad set of security-focused updates: new developer security features for non-human identities (scannable API tokens, enhanced OAuth visibility, GA resource‑scoped permissions, Managed OAuth adopting RFC 9728), guidance and tooling for MCP adoption (including Code Mode and Shadow MCP detection), and expanded visibility and protection products (AI Security for Apps GA, Client‑Side Security opened to all, Account Abuse Protection EA, Log Explorer multi‑dataset support, and a new Web & API Vulnerability Scanner). They disclosed and fixed specific vulnerabilities — notably,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- 3ba82d4e58606cfbe5c4a09cd88725a200d04335510f79f0dfd01484c8528c22
- Enrichment time
- 2026-04-24T19:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.