API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-148 · Authentication & identity

Cloudflare Service Key authentication reaches end of life on 30 September 2026

Cloudflare deprecated Service Key authentication and will stop accepting it on 30 September 2026, directing affected API integrations to scoped API Tokens.

CloudflareService KeyAPI Tokenauthenticationend of life

Previous state

Affected Cloudflare API integrations could authenticate with the X-Auth-User-Service-Key header.

Current state

Service Keys stop working after 30 September 2026; scoped API Tokens are the documented replacement.

Who needs to care

Cloudflare API clients, cloudflared versions and origin-ca-issuer deployments that still use Service Key authentication.

What to do

Replace X-Auth-User-Service-Key with a least-privilege API Token and update affected supporting software before the deadline.

What the source does not prove

The notice applies to Service Key authentication and named affected configurations; it does not retire unrelated Cloudflare authentication methods.

Lifecycle history

Dated event sequence

  1. Deprecation announced

    Cloudflare named API Tokens as the replacement.

  2. Service Key end of life

    Service Key authentication stops working.

Evidence ledger

First-party sources

  1. 01
    Cloudflare Developers — Service Key authentication deprecated

    Official authentication-lifecycle notice · 2026-03-19

    Open official source ↗