Securing non-human identities: automated revocation, OAuth, and scoped permissions
2026-04-29T07:24:18Z•7727b49a472fa067831104f34259bbab7da62a0e0305016f51f40bd97c38afa5
ACME validationAI Security for AppsAI discoveryAPI tokensCloudflareLLMLog ExplorerManaged OAuthOAuthPQ roadmapPingoraPingora 0.8.0RFC 9728Web and API Vulnerability Scanner','API call graphs' ,"DDoS","31account-abuse protectionclient-side securityfraud preventiongraph neural networksleast-privilegemulti-vector attackspost-quantumrequest smugglingresource-scoped permissionsscannable tokensvulnerability disclosure
What happened
Cloudflare published a broad set of security updates and product launches covering developer credentials, OAuth, post-quantum planning, client-side protections, AI/agent security, observability, and several vulnerability disclosures and fixes. Key items include scannable API tokens, enhanced OAuth visibility and GA resource-scoped permissions to enable least-privilege access, Managed OAuth for Access (RFC 9728) for agent-safe authentication, a move to target full post-quantum deployment by 2029, and opening advanced client-side security (GNN + LLM) and AI Security for Apps to more users. They:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- 7727b49a472fa067831104f34259bbab7da62a0e0305016f51f40bd97c38afa5
- Enrichment time
- 2026-04-29T07:24:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.