Cloudflare is introducing scannable API tokens, enhanced OAuth visibility, and GA for resource-scoped permissions. These tools help developers implement a true least-privilege architecture while prote
AI Summary
Here's a 2-3 sentence summary of the blog post on securing non-human identities: To secure non-human identities, such as agents and scripts, Cloudflare has introduced updates to manage their entire lifecycle, including scannable tokens, OAuth visibility, and resource-scoped RBAC to fine-tune policies. The company's new token formats, with a scannable "cf" prefix and checksum, enable automated security tools to easily identify and revoke leaked API tokens, and its partnership with GitHub detects and revokes leaked tokens in public and private repositories. Cloudflare One customers also benefit from these features, as DLP profiles can detect and block credential leaks across network traffic, email, and SaaS applications, and the company's AI Gateway scans and blocks AI traffic in real-time.
Get the top 10 engineering articles delivered every Monday.