API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-202 · Authentication & identity

Cloudflare Access adds FIDO2 independent MFA for infrastructure applications

Cloudflare added FIDO2 keys to independent MFA for Access infrastructure applications on 12 August 2026, allowing ssh_fido2_key, piv_key, or both in application-level and policy-level MFA settings.

CloudflareAccessFIDO2MFASSH

Previous state

The documented independent-MFA controls for Access infrastructure applications did not include the announced FIDO2 SSH-key option.

Current state

Access infrastructure applications can enforce independent MFA using FIDO2 SSH keys, PIV keys, or both through application-level and policy-level MFA settings.

Who needs to care

Cloudflare Access administrators and users of supported infrastructure applications, including SSH workflows configured for independent MFA.

What to do

Review supported key types, enrollment flow, and application or policy MFA settings before enabling FIDO2 for infrastructure access.

What the source does not prove

The source proves FIDO2 support for independent MFA on the documented Access infrastructure-application surface. It does not generalize FIDO2 enforcement to every Access authentication flow or equate SSH FIDO2 keys with browser WebAuthn security keys.

Lifecycle history

Dated event sequence

  1. FIDO2 independent MFA becomes available for infrastructure applications

    Cloudflare announced support for ssh_fido2_key alongside PIV keys in infrastructure-application MFA settings.

Evidence ledger

First-party sources

  1. 01
    Cloudflare — Independent MFA supports FIDO2 for infrastructure applications

    Official Cloudflare changelog · 2026-08-12

    Open official source ↗