API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-053 · Authentication & identity

Cloudflare Access moves plaintext private HTTP apps to browser login

Private HTTP applications on port 80 now use the standard Access browser login and application token instead of the One Client pop-up session flow.

Cloudflare Accessprivate appsbrowser loginHTTP

Previous state

Private port-80 HTTP applications used the One Client notification and session login flow.

Current state

Users authenticate in the browser and receive the standard Access application token.

Who needs to care

Cloudflare Zero Trust private HTTP applications routed on port 80.

What to do

Test browser redirection and token handling while retaining One Client for private-network routing.

What the source does not prove

One Client remains required for routing and no configuration change is required; non-HTTP protocols retain their own flow.

Lifecycle history

Dated event sequence

  1. Login flow changed

    Browser-based Access login became the standard for plaintext private HTTP applications.

Evidence ledger

First-party sources

  1. 01
    Cloudflare Developers — Cloudflare Access changelog

    Official product changelog · 2026-07-20

    Open official source ↗