Website Security & Threat Management
Securing non-human identities: automated revocation, OAuth, and scoped permissions

Securing non-human identities: automated revocation, OAuth, and scoped permissions

4/14/2026 · Justin Hutchings, Adam Bouhmad, Rebecca Varley

What this post added

Introduced scannable API token formats (cfk_, cfut_, cfat_) with checksums for better detection by credential scanning tools. Integrated with GitHub's Secret Scanning program for automated revocation of leaked tokens in public repositories. Extended credential leak protection to Cloudflare One customers via Credentials and Secrets DLP profile across network traffic, outbound email, and data at rest. Integrated AI Gateway with DLP profiles for scanning prompts and responses. Improved OAuth consent experience by providing visibility into requesting third-party applications, scopes, and accounts, with a new 'Connected Applications' experience for management and revocation. Expanded resource-scoped RBAC to new resources, including Access Applications, to enable fine-grained permissioning for users and agents.

Read the original post ↗