ST-2026-273 · Authentication & identity
Cloudflare Access introduces strict service-token authentication
Cloudflare Access makes strict service-token authentication the default for new organizations from 5 October 2026, where it cannot be disabled; older organizations retain a toggle.
Previous state
Service-token handling could accept the prior authentication behavior and organizations controlled existing settings.
Current state
New organizations default to strict service-token authentication from 5 October 2026 and cannot disable it; existing organizations retain the documented toggle.
Affected users
Who needs to care
Cloudflare Access organizations and service-token clients.
Required response
What to do
Test service-token clients against strict authentication and review the organization setting before creating new organizations.
Evidence boundary
What the source does not prove
The non-disableable boundary applies to new organizations; the source preserves a toggle for older organizations.
Lifecycle history
Dated event sequence
- Change announced
Cloudflare documented strict service-token authentication.
- New-organization default
Strict authentication becomes the default and fixed behavior for new organizations.
Evidence ledger
First-party sources
- 01Cloudflare Developers — Strict service token authentication
Official Cloudflare authentication authority · 2026-10-02
Open official source ↗