API · SDK · runtime · authentication lifecycle intelligence

Last updated · 3 October 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-273 · Authentication & identity

Cloudflare Access introduces strict service-token authentication

Cloudflare Access makes strict service-token authentication the default for new organizations from 5 October 2026, where it cannot be disabled; older organizations retain a toggle.

Cloudflare Accessservice tokensstrict authentication

Previous state

Service-token handling could accept the prior authentication behavior and organizations controlled existing settings.

Current state

New organizations default to strict service-token authentication from 5 October 2026 and cannot disable it; existing organizations retain the documented toggle.

Who needs to care

Cloudflare Access organizations and service-token clients.

What to do

Test service-token clients against strict authentication and review the organization setting before creating new organizations.

What the source does not prove

The non-disableable boundary applies to new organizations; the source preserves a toggle for older organizations.

Lifecycle history

Dated event sequence

  1. Change announced

    Cloudflare documented strict service-token authentication.

  2. New-organization default

    Strict authentication becomes the default and fixed behavior for new organizations.

Evidence ledger

First-party sources

  1. 01
    Cloudflare Developers — Strict service token authentication

    Official Cloudflare authentication authority · 2026-10-02

    Open official source ↗