ST-2026-197 · Authentication & identity
Cloudflare Access adds configurable eager redirects for multi-domain authorization cookies
Cloudflare added an Eager redirect setting for multi-domain Access self-hosted applications on 3 August 2026, letting administrators choose whether CF_Authorization cookies are pre-issued across public hostnames or issued when each hostname is visited; new applications default the setting on.
Previous state
Multi-domain Access applications did not expose the announced administrator setting for choosing eager cross-hostname authorization-cookie issuance behaviour.
Current state
Administrators can configure eager redirects that pre-issue CF_Authorization cookies across public hostnames or defer cookie issuance until each hostname is visited; Cloudflare enables eager redirect by default for new applications.
Affected users
Who needs to care
Cloudflare Access administrators operating multi-domain self-hosted applications whose public hostnames rely on CF_Authorization cookies.
Required response
What to do
Review the Eager redirect setting for new or existing multi-domain Access applications and validate redirect and cookie behaviour against the intended user flow before changing an established configuration.
Evidence boundary
What the source does not prove
The source proves the configurable authorization-cookie issuance and redirect behaviour. It does not change the configured identity provider, underlying allow/deny policy evaluation, or establish a mandatory migration for existing applications.
Lifecycle history
Dated event sequence
- Eager redirect setting becomes available
Cloudflare announced configurable eager-redirect authorization-cookie issuance for multi-domain Access applications and stated that new applications default the setting on.
Evidence ledger
First-party sources
- 01Cloudflare — Eager redirect setting for Access applications
Official Cloudflare changelog · 2026-08-03
Open official source ↗