ST-2026-202 · Authentication & identity
Cloudflare Access adds FIDO2 independent MFA for infrastructure applications
Cloudflare added FIDO2 keys to independent MFA for Access infrastructure applications on 12 August 2026, allowing ssh_fido2_key, piv_key, or both in application-level and policy-level MFA settings.
Previous state
The documented independent-MFA controls for Access infrastructure applications did not include the announced FIDO2 SSH-key option.
Current state
Access infrastructure applications can enforce independent MFA using FIDO2 SSH keys, PIV keys, or both through application-level and policy-level MFA settings.
Affected users
Who needs to care
Cloudflare Access administrators and users of supported infrastructure applications, including SSH workflows configured for independent MFA.
Required response
What to do
Review supported key types, enrollment flow, and application or policy MFA settings before enabling FIDO2 for infrastructure access.
Evidence boundary
What the source does not prove
The source proves FIDO2 support for independent MFA on the documented Access infrastructure-application surface. It does not generalize FIDO2 enforcement to every Access authentication flow or equate SSH FIDO2 keys with browser WebAuthn security keys.
Lifecycle history
Dated event sequence
- FIDO2 independent MFA becomes available for infrastructure applications
Cloudflare announced support for ssh_fido2_key alongside PIV keys in infrastructure-application MFA settings.
Evidence ledger
First-party sources
- 01Cloudflare — Independent MFA supports FIDO2 for infrastructure applications
Official Cloudflare changelog · 2026-08-12
Open official source ↗