Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-20T19:24:12Za2d335e47fa70bbd00f6c14e803eb78b7c0f51232ad47eeda168f80995f758a5
account-abuseacme-validationaiai-security-for-appsapi-tokensclient-side-securitycloudflarecloudyddosgnnleast-privilegellmlog-explorermanaged-oauthmcpoauthphishingpingorapost-quantumpq-cryptographyrequest-smugglingresource-scoped-permissionsshadow-mcpvulnerability-scannerworkers-vpc

What happened

Collection of Cloudflare security announcements (Mar–Apr 2026) covering developer and platform hardening: scannable API tokens, enhanced OAuth visibility and Managed OAuth (RFC 9728), and GA of resource-scoped permissions to enable least-privilege non-human identities. Additional highlights include a 2029 target for full post‑quantum migration, Client‑Side Security opened to all with GNN+LLM detections, Account Abuse Protection (Early Access), AI Security for Apps (GA) with free discovery, Log Explorer enhancements, a new Web/API vulnerability scanner, and mitigations for disclosed issues (not

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
a2d335e47fa70bbd00f6c14e803eb78b7c0f51232ad47eeda168f80995f758a5
Enrichment time
2026-04-20T19:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.