Securing non-human identities: automated revocation, OAuth, and scoped permissions
2026-04-25T19:24:14Z•d2d5783ec4f67dd1ad9dceae99265bb40289f226e9711ccec0e46171cfc7d4a8
accessacmeai-securityapi-tokenscertificate-validationcgnatclient-side-securitycloudflareddoslog-explorermanaged-oauthmcpoauthpingorapost-quantumrequest-smugglingscoped-permissionssecurity-blogvulnerability-disclosurevulnerability-scannerworkers-vpc
What happened
Cloudflare published a batch of security-focused announcements: new scannable API tokens, enhanced OAuth visibility and Managed OAuth (RFC 9728) for agent-friendly authentication, and GA of resource-scoped permissions to enable least-privilege architectures. They advanced post-quantum planning (targeting full PQ security by 2029), opened advanced client-side security powered by graph neural nets + LLMs, and launched multiple AI security and discovery features. Operations and observability improvements include Log Explorer multi-dataset support, a Web/API vulnerability scanner, and Radar PQ/KT/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- d2d5783ec4f67dd1ad9dceae99265bb40289f226e9711ccec0e46171cfc7d4a8
- Enrichment time
- 2026-04-25T19:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.