Grace periods for service token rotation
Cloudflare Access now supports grace periods during service token secret rotation, allowing both old and new secrets to remain valid for 1 hour to 30 days while administrators update services. The dashboard and API both support custom rotation schedules without interrupting authentication.
Cloudflare Access administrators can now choose a grace period when rotating a service token secret. Both secrets remain valid during the grace period, giving administrators time to update services without interrupting authentication.
The dashboard offers grace periods from one hour to 30 days. Administrators can also revoke the previous secret immediately. The API accepts an RFC 3339 expiration time for custom rotation schedules.
For configuration instructions, refer to Rotate service token secrets.
Source: original entry ↗