ST-2026-053 · Authentication & identity
Cloudflare Access moves plaintext private HTTP apps to browser login
Private HTTP applications on port 80 now use the standard Access browser login and application token instead of the One Client pop-up session flow.
Previous state
Private port-80 HTTP applications used the One Client notification and session login flow.
Current state
Users authenticate in the browser and receive the standard Access application token.
Affected users
Who needs to care
Cloudflare Zero Trust private HTTP applications routed on port 80.
Required response
What to do
Test browser redirection and token handling while retaining One Client for private-network routing.
Evidence boundary
What the source does not prove
One Client remains required for routing and no configuration change is required; non-HTTP protocols retain their own flow.
Lifecycle history
Dated event sequence
- Login flow changed
Browser-based Access login became the standard for plaintext private HTTP applications.
Evidence ledger
First-party sources
- 01Cloudflare Developers — Cloudflare Access changelog
Official product changelog · 2026-07-20
Open official source ↗