ST-2026-041 · Authentication & identity
Cloudflare API tokens gain secret-scannable format and exposure deactivation
Newly generated Cloudflare API tokens use a recognisable format that supported secret scanners can detect and report for immediate deactivation.
Previous state
API-token strings were harder for supported scanners to identify reliably and exposure handling depended more heavily on manual discovery.
Current state
New tokens are scanner-recognisable and can be deactivated immediately when a supported scanner reports exposure.
Affected users
Who needs to care
Cloudflare administrators, security teams and developers storing API tokens in source or CI systems.
Required response
What to do
Rotate to newly generated token formats where appropriate, enable supported secret scanning and test revocation and replacement runbooks.
Evidence boundary
What the source does not prove
The source does not prove that every historical token has the new detectable format or that every repository host and scanner participates.
Lifecycle history
Dated event sequence
- Change documented
Newly generated Cloudflare API tokens use a recognisable format that supported secret scanners can detect and report for immediate deactivation.
Evidence ledger
First-party sources
- 01Cloudflare Developers — Secret scanning support for Cloudflare API tokens
Official product documentation or changelog · 2026-04-10
Open official source ↗