Securing non-human identities: automated revocation, OAuth, and scoped permissions
2026-04-20T19:24:12Z•a2d335e47fa70bbd00f6c14e803eb78b7c0f51232ad47eeda168f80995f758a5
account-abuseacme-validationaiai-security-for-appsapi-tokensclient-side-securitycloudflarecloudyddosgnnleast-privilegellmlog-explorermanaged-oauthmcpoauthphishingpingorapost-quantumpq-cryptographyrequest-smugglingresource-scoped-permissionsshadow-mcpvulnerability-scannerworkers-vpc
What happened
Collection of Cloudflare security announcements (Mar–Apr 2026) covering developer and platform hardening: scannable API tokens, enhanced OAuth visibility and Managed OAuth (RFC 9728), and GA of resource-scoped permissions to enable least-privilege non-human identities. Additional highlights include a 2029 target for full post‑quantum migration, Client‑Side Security opened to all with GNN+LLM detections, Account Abuse Protection (Early Access), AI Security for Apps (GA) with free discovery, Log Explorer enhancements, a new Web/API vulnerability scanner, and mitigations for disclosed issues (not
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- a2d335e47fa70bbd00f6c14e803eb78b7c0f51232ad47eeda168f80995f758a5
- Enrichment time
- 2026-04-20T19:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.