Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-15T07:24:08Z4e4ed4d386fdf8c34c06c587a82aa48038e7750672c0d80ddacfb11c6673381f
ACME validation vulnerabilityAI Security for AppsAI discoveryAPI tokensAccount abuse protectionCloudflareDDoSGNNLLMLog ExplorerManaged OAuthOAuthPingoraPingora 0.8.0RFC 9728Web and API vulnerability scannerWorkers VPC Services','CGNAT','Matrix homeserver','ASPA','Key-透明client-side securityleast privilegepost-quantum 2029post-quantum roadmaprequest smugglingresource-scoped permissionstoken revocationvulnerability disclosure

What happened

Cloudflare published a batch of security-focused announcements and disclosures. Key themes: improved developer credential hygiene (scannable API tokens, automated revocation, resource-scoped permissions GA, recommendations for least-privilege and token cost reduction), Managed OAuth for Access (RFC 9728 support to enable agent-safe auth), expanded AI security and discovery (AI Security for Apps GA, Client-Side Security public, Cloudy LLM explanations, free AI discovery for shadow AI), new detection and defender tooling (Web & API vulnerability scanner, Log Explorer multi-dataset investigations

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
4e4ed4d386fdf8c34c06c587a82aa48038e7750672c0d80ddacfb11c6673381f
Enrichment time
2026-04-15T07:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.