Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-23T19:24:15Zb718ee244921ef12e49d2917df14fd6b8d88ef2949fa3db0e22a4a5a55bf37f3
MCPPingoraRFC-9728account-abuse-protectionacme-validationai-gatewayai-security-for-appsapi-tokensclient-side-securitycloudflareddosleast-privilegelog-explorermanaged-oauthmatrix-homeserver-pq-proof-of-conceptmulti-vector-attacksoauthpost-quantumpq-cryptographyradarrequest-smugglingresource-scoped-permissionstoken-revocationvulnerability-disclosurevulnerability-scanner

What happened

Collection of Cloudflare security blog posts (Apr 2026 and earlier) announcing product security improvements, research, and several vulnerability disclosures. Key highlights: scannable API tokens, automated revocation and resource-scoped permissions (GA) to enable least-privilege; enhanced OAuth visibility and Managed OAuth for Access (RFC 9728) for agent-safe internal app access; MCP governance guidance and token-cost reductions; Cloudflare moving its target for full post-quantum deployment to 2029 and adding PQ transparency tooling in Radar; Client-Side Security made generally available with

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
b718ee244921ef12e49d2917df14fd6b8d88ef2949fa3db0e22a4a5a55bf37f3
Enrichment time
2026-04-23T19:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.