Securing non-human identities: automated revocation, OAuth, and scoped permissions
2026-04-19T19:24:05Z•a7af8c2d59e1b156b73d57609534e1645215f0a798ebe9cae83d19b2c28c84f9
AI GatewayAI Security for AppsAPI tokensCloudflare AccessCode ModeLLMsLog ExplorerMCPManaged OAuthOAuthPQC roadmap (2029)RFC 9728Shadow MCPaccount abuse protectionclient-side securityfalse positive reductionfraud preventiongraph neural networksleast privilegemulti-vector attack visibilitynon-human identitiespost-quantum cryptographyrequest smuggling vulnerability (Pingora)resource-scoped permissionsshadow AI discovery
What happened
Cloudflare published a collection of security updates and product launches focused on improving developer and enterprise security posture: scannable API tokens, resource-scoped permissions, and Managed OAuth (RFC 9728) to enable least-privilege non-human identities and agent-ready internal apps; expanded governance and cost controls for MCP and Cloudflare Gateway; and a move to accelerate full post‑quantum adoption to 2029. They also announced broader defensive tooling—client-side security with GNN/LLM detections, AI Security for Apps and shadow‑AI discovery, account‑abuse protections, a Web &
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- a7af8c2d59e1b156b73d57609534e1645215f0a798ebe9cae83d19b2c28c84f9
- Enrichment time
- 2026-04-19T19:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.