Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-19T19:24:05Za7af8c2d59e1b156b73d57609534e1645215f0a798ebe9cae83d19b2c28c84f9
AI GatewayAI Security for AppsAPI tokensCloudflare AccessCode ModeLLMsLog ExplorerMCPManaged OAuthOAuthPQC roadmap (2029)RFC 9728Shadow MCPaccount abuse protectionclient-side securityfalse positive reductionfraud preventiongraph neural networksleast privilegemulti-vector attack visibilitynon-human identitiespost-quantum cryptographyrequest smuggling vulnerability (Pingora)resource-scoped permissionsshadow AI discovery

What happened

Cloudflare published a collection of security updates and product launches focused on improving developer and enterprise security posture: scannable API tokens, resource-scoped permissions, and Managed OAuth (RFC 9728) to enable least-privilege non-human identities and agent-ready internal apps; expanded governance and cost controls for MCP and Cloudflare Gateway; and a move to accelerate full post‑quantum adoption to 2029. They also announced broader defensive tooling—client-side security with GNN/LLM detections, AI Security for Apps and shadow‑AI discovery, account‑abuse protections, a Web &

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
a7af8c2d59e1b156b73d57609534e1645215f0a798ebe9cae83d19b2c28c84f9
Enrichment time
2026-04-19T19:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Securing non-human identities: automated revocation, OAuth, and scoped permissions · Baitaphish