megachangelog
Cloudflare logo

Cloudflare Changelog

Cloudflare — Cloud, Security product updates and releases, tracked on megachangelog.


Feature

Call Workflows declared in exports through ctx.exports

Workers can now call Workflows declared in their Wrangler configuration exports field through ctx.exports, eliminating the need for a separate workflows binding. Workflows are keyed by class name and share the same API as bindings, with local development support via Wrangler, Vite, and Vitest plugins.

workersworkflowsapidevelopment
Feature

Network Firewall Managed Rulesets supported in Unified Routing

Cloudflare Advanced Network Firewall Managed Rulesets are now available for accounts using Unified Routing mode, expanding feature support across Magic Transit and Cloudflare WAN deployments.

firewallnetworkingmanaged-rulesetsunified-routingmagic-transit
Feature

Browser Run crawl events now publishable to Queues

Browser Run crawl jobs can now publish lifecycle events (started, updated, finished) to Cloudflare Queues, allowing you to track progress and trigger downstream processing without polling.

browser-runqueueseventsapiintegration
Security2026-09-25

WAF emergency rules for WordPress and JFrog Artifactory vulnerabilities

Cloudflare's Web Application Firewall has added new managed rules to block critical vulnerabilities in WordPress (path traversal, LFI, XSS) and JFrog Artifactory (authentication bypass). Administrators should apply vendor patches to fully secure their origin servers.

wafsecuritywordpressjfrogvulnerability
Feature

Workers Metrics now shows every release and gradual deployment progression

Workers Metrics charts now display every release and the full progression of gradual deployments, making it easier to correlate performance changes like memory, CPU, errors, or latency with code versions. Hover over rollouts to see version details, duration, and traffic percentage at each step.

workersmetricsdeploymentmonitoringobservability
Feature

Email Service - Suppress recipients for one sending domain

Email Sending suppressions now support domain-level scope in addition to account-level scope, allowing you to manage bounce and complaint suppressions per sending domain. This prevents issues with one domain from affecting suppressions across your entire account, with automatic creation of domain-level suppressions and API support for specifying scope.

emailsuppressionssending-domainapigranularity
Announcement

MCP server portals now generally available

MCP server portals are now generally available to all Cloudflare customers, providing a single endpoint for approved Model Context Protocol servers with activity logging. The feature now includes gateway routing for HTTP logging and DLP scanning, Code Mode policies for tool optimization, static OAuth credentials, session management, service token authentication for machine-to-machine access, and Logpush support for SIEM integration.

accessmcpaisecuritylogging
Feature

1.1.1.1 now supports RFC 8509 root key trust anchor sentinels

1.1.1.1 resolver now supports RFC 8509 root key trust anchor sentinels, allowing you to verify whether the resolver trusts a specific DNSSEC root key ahead of a key rollover. This enables testing for DNSSEC root key readiness using special sentinel domain queries.

dnsdnssecsecurityrfc8509resolver
Feature

R2 bandwidth usage metrics

R2 now provides product-level bandwidth usage metrics accessible via the Cloudflare dashboard and GraphQL Analytics API, allowing users to monitor upload and download throughput across all buckets or individually per bucket.

r2metricsanalyticsdashboardbandwidth
Feature

Declare Workflows in the exports configuration

Workers can now declare Workflows directly in the exports field of the Wrangler configuration file, eliminating the need for a workflows binding when the Worker doesn't call the Workflow itself. This enables cleaner configuration and automatic Workflow creation or updates during deployment.

workflowsworkersconfigurationwrangler
Improvement

Durable Object name search now supports 128 characters

Durable Object name searches in the Cloudflare dashboard now accept up to 128 characters instead of 20, with search results and recent invocation lists displaying up to 128 characters before truncation. This applies to the object filter on the Metrics tab and object search in Data Studio.

durable-objectsdashboardsearchimprovement
Feature

Traffic Destination selector in Gateway policies

Gateway HTTP and Network policies now support a Traffic Destination selector that identifies how traffic exits Cloudflare, enabling administrators to write policies targeting specific off-ramp methods like public Internet, Cloudflare Tunnel, WAN, or Mesh.

gatewaypoliciesnetworktraffic-routingcloudflare-one
Feature

Cloudflare Images - View transformation analytics

Users can now view account-level analytics for Images transformation usage, including request breakdowns by source type, top zones, configurations, origins, and Worker scripts. This helps identify which zones and configurations generate the most image transformation requests.

imagesanalyticstransformationsmonitoring
Improvement

Cloudflare Mesh - Guided onboarding for adding participants

Cloudflare Mesh now includes guided onboarding in the dashboard to simplify adding and managing Mesh nodes and client devices. The updated interface provides deployment options for multiple container platforms, platform-specific installation guidance, and a unified table to manage all participants.

meshnetworkingonboardingdashboardmanagement
Feature

Workers Builds now supports Cursor Origin

Workers Builds now integrates with Cursor Origin repositories, enabling automatic building and deployment of production changes, preview generation for non-production branches, and build status visibility in pull requests.

workersci-cdgit-integrationbuildsdeployment
Feature2026-09-22

WAF: New SSRF and SSTI threat detections

The WAF now includes new detections for Server-Side Request Forgery attacks using non-standard IP notations and jar loopback payloads, plus defenses against Server-Side Template Injection targeting Jinja environments.

wafsecurityssrfsstithreat-detection
Feature

Automatically manage inactive Access service tokens

Cloudflare Access administrators can now automatically disable or delete inactive service tokens by setting an inactivity period from 30 to 365 days. Cleanup runs gradually in the background for tokens that are older than the configured period and have not authenticated during that time.

accesstokensservice-tokenssecurityadministration
Improvement

concat() now supports up to 32 arguments

The concat() function in Cloudflare Rules now accepts up to 32 arguments instead of 16, enabling you to combine more request data directly in Rules expressions and simplify configurations that add dynamic headers and values to requests.

rulesapifunctionsexpressions
Feature

Test every pull request in an isolated environment with Worker Previews

Worker Previews let you test each change in an isolated, production-like environment with its own code, configuration, URL, and observability. Each Preview gets a stable URL that updates with every push, full observability including logs and metrics, and can use production-like hostnames on custom domains for testing authentication and integrations before deploying to production.

workerspreviewtestingdeploymentci-cd
Feature

Private MCP server support for Access portals

MCP server portals can now connect to private MCP servers on your network via Cloudflare Gateway without exposing them publicly. Set up a connection using Cloudflare Tunnel or Mesh, configure a private hostname or CIDR route, and enable Gateway traffic routing.

accessmcpsecuritynetworkinggateway
Announcement2026.8.1755.1

Cloudflare One Client for macOS Beta Release 2026.8.1755.1

Beta release featuring multiple bug fixes and reliability improvements for the Cloudflare One Client on macOS, including enhancements to split tunnel handling, reauthentication, DNS reliability, and network connectivity checks.

macosbetavpnwarpnetworking
Improvement2026.8.1755.1

Cloudflare One Client for Windows (Beta)

Beta release includes multiple fixes and improvements for traffic blocking, reauthentication, network reliability, DNS performance, and UI stability. Key improvements include better MTU handling, expanded LAN routing support, and removal of WLAN AutoConfig dependency.

warpwindowsvpnbetastability
Feature

Grant teammates scoped access to specific Workers from dashboard

You can now invite teammates directly from the Workers dashboard and grant them scoped access levels (Metadata Read-Only, Content Read-Only, Editor, or Admin) to specific Workers. Super Administrators can manage these invitations with automatic account integration for existing members.

workersaccess-controlpermissionscollaborationdashboard
Feature

Browser Run adds session and DevTools methods to browser bindings

Browser Run now provides typed methods for session management and DevTools operations, including acquire, launch, and connectSession methods with support for outbound routing through Workers. You can manage sessions, create Live View URLs, and perform target operations without manual HTTP requests.

browser-runapibindingsdevtoolssession-management
Feature

Filter DDoS attack traffic from Logpush jobs

Logpush jobs can now exclude distributed denial-of-service attack traffic from delivered logs, reducing noise and focusing on legitimate traffic. This feature supports http_requests, firewall_events, and network_analytics_logs datasets via a new filter_attack_traffic flag.

logpushddoslogssecurityapi
Feature

Browser Run - Inspect logs, network requests, and DOM in Session Recordings

Browser Run Session Recordings now include an Inspect panel with Logs, Network, and DOM tabs, allowing you to search console output, view detailed network requests with HAR export, inspect page structure, and access recorded data via API without reproducing sessions.

browser-rundebuggingsession-recordingsapinetwork-analysis
Announcement

Unified Routing now generally available for WAN and Magic Transit

Unified Routing is now generally available for Cloudflare WAN and Magic Transit, improving integration between Cloudflare One and standard connectivity onramps. It supports new features including Automatic Return Routing, BGP, and custom client subnets.

wanmagic-transitroutingnetworkingga
Feature4.125.0

Delete Workflow instances individually or in batches

You can now delete one or up to 100 Workflow instances and their stored state via the Workflows API or Wrangler 4.125.0 and later. Deleting an instance frees its stored state, stops execution, and reduces storage billing.

workflowsworkersapiwranglerbulk-operations
Feature

Create additional Free accounts through the dashboard and API

Cloudflare now allows customers to create additional Free accounts via self-serve dashboard flows, programmatically through API tokens or OAuth, and directly within Enterprise Organizations. Super Administrators can provision up to five Free accounts per Organization for easier account management.

accountsapidashboardenterpriseself-serve
Feature

Validate Rulesets changes before deployment

Cloudflare Rules now validates ruleset changes before deployment, catching invalid expressions, action parameters, permission issues, and quota limit violations. The dashboard performs validation automatically, and the Rulesets API supports dry_run=true queries to validate changes without persisting them.

rulesetsapivalidationsecuritydeployment
Feature

Workers AI - Reject busy synchronous inference requests

Added rejectIfBusy option for Workers AI inference requests, allowing applications to fail immediately instead of waiting in the capacity queue when resources are unavailable. This option can be passed to both the Workers AI binding and the REST API.

workers-aiapifeatureinferencecapacity
Feature

Workers traces now automatically include JavaScript RPC session spans

Workers traces can now follow JavaScript RPC calls across Worker boundaries and into Durable Objects, showing caller-side sessions, method invocations, and nested calls. Enable tracing via a single Wrangler configuration setting without code changes.

workersdurable-objectstracingobservabilityrpc
Feature

Hyperdrive support for Python Workers

Python Workers can now connect to PostgreSQL and MySQL databases through Hyperdrive, enabling serverless database connectivity from Python-based applications.

workershyperdrivepythondatabase
Feature

R2 Data Catalog adds table maintenance visibility and manual queueing

R2 Data Catalog now provides table-level maintenance visibility and manual compaction queueing in the Cloudflare dashboard. Users can view maintenance schedules, recent operation details, and request maintenance directly from the table view without navigating away.

r2data-catalogmaintenancedashboardstorage
Feature

Stream Workflow instance events via .subscribe()

Workflow instances now support event streaming through WorkflowInstance.subscribe() and the GET /subscribe API endpoint, allowing Workers and HTTP clients to react to workflow events like attempts, sleeps, waits, and rollbacks without polling. Subscriptions stream the complete event history first, then wait for new events in real-time, with optional filtering by event type or cursor position.

workflowsworkersapieventsstreaming
Feature

Workers - Grant teammates and agents access to specific Workers

Cloudflare Workers now supports granular, role-based access control, allowing you to grant teammates, agents, and CI/CD workflows access to specific Workers with four configurable roles: Metadata Read-Only, Content Read-Only, Editor, and Admin. These permissions can be configured via the Cloudflare dashboard, API, or Terraform.

workersaccess-controlpermissionsrbacapi
Feature

Access for Infrastructure now supports tagged targets and tag-based criteria

Access for Infrastructure now integrates with Resource Tagging, allowing you to attach key-value tags to infrastructure targets and use them in access policies with flexible target criteria operators (include, require, exclude) that match by hostname, tag, or both.

accessinfrastructuretaggingpolicyapi
Feature

Passive Detection for Data Loss Prevention

Cloudflare Data Loss Prevention now includes Passive Detection, which analyzes sampled Gateway traffic to identify sensitive data types and their destinations before you create blocking policies. This helps you understand your organization's data flows and build effective DLP policies without requiring an existing policy.

data-loss-preventiongatewaysecuritydetectionzero-trust
Feature

Access - Require fresh authentication for SAML identity providers

Cloudflare Access now supports requiring fresh authentication from SAML identity providers on every login. Users can enable this via the dashboard or set force_authn to true in the API to enforce reauthentication instead of relying on cached identity provider sessions.

accesssamlauthenticationapiidentity
Feature

DNS shadowed record warnings now available for all zones

Cloudflare now displays warnings for shadowed DNS records across all zones, helping identify records that may not resolve as expected. Shadow metadata is also available via the DNS records API with the include_shadow_metadata parameter to identify delegating NS records and glue records.

dnsrecordsapiwarningszones
Feature

AI Gateway - Prevent Unified Billing fallback for BYOK third-party providers

AI Gateway now supports requiring provider credentials for third-party requests, preventing automatic fallback to Cloudflare-managed Unified Billing credentials. You can enforce this at the gateway level or per-request using the byok_only setting or cf-aig-no-wholesale header.

ai-gatewaybillingbyokcredentialsapi
Feature

Browser Run - Guardrails for hostname access control

Browser Run now supports guardrails to limit HTTP and HTTPS requests to permitted hostnames, enabling secure browser workflows for specific websites and third-party APIs. Additionally, Live View now supports read-only mode for observing sessions without interaction.

browser-automationsecurityapiguardrails
Feature0.4.0

Inspect Voice Agent turn latency and outcomes

The @cloudflare/voice package now provides detailed per-turn metrics showing where each voice agent turn spends time and how it ends, with typed summaries including outcomes, latency breakdowns for speech-to-text, model inference, text-to-speech stages, and new browser console diagnostics for local debugging.

voice-agentsobservabilityperformancemetricsdebugging
Announcement2026.09.10

Workflows: Default instance retention reduced to 7 days for Workers Paid

New Workflows on the Workers Paid plan now retain completed and errored instance state for 7 days by default instead of 30 days, helping reduce storage costs while maintaining a maximum retention limit of 30 days. Existing Workflows are unaffected, and users can customize retention periods using the successRetention and errorRetention options.

workflowsworkersstoragepricingretention
Feature

Use Cloudflare Containers with OpenAI Agents API and Codex

Cloudflare Containers can now serve as the execution environment for the OpenAI Agents API, allowing applications to run Codex with self-hosted infrastructure. An open-source Workers template is available as a reference implementation with built-in session management and automatic lifecycle handling.

containersopenaiapiworkerscodex
Security2026-09-10

Emergency WAF update: Adobe Commerce RCE protection (CVE-2026-75650)

Cloudflare WAF now blocks a critical zero-day RCE vulnerability (CVE-2026-75650) targeting Adobe Commerce and Magento storefronts. This emergency virtual patch provides immediate edge-level defense against unauthenticated attackers injecting PHP payloads through style properties, though urgent patching and credential rotation on origin applications are required.

wafsecurityadobe-commercercezero-day
Improvement2026.8.1290.1

Cloudflare One Client for macOS 2026.8.1290.1 Beta

A new beta release for macOS Cloudflare One Client with improvements to DNS reliability, API resilience, and WARP tunnel routing support, plus multiple bug fixes for connectivity, diagnostics, and UI stability.

macoswarpdnsbetavpn
Improvement2026.8.1290.1

Cloudflare One Client for Windows 2026.8.1290.1 Beta

Beta release includes routing improvements for non-RFC 1918 networks, enhanced DNS reliability on low-MTU connections, improved API retry logic, and numerous stability fixes including fixes for captive portal checks, WireGuard protocol switching, DEX HTTP validation, and UI crashes.

warpwindowsvpndnsstability
Feature

AI Gateway custom costs now support cache token rates

AI Gateway custom costs now support per_cache_read_token and per_cache_write_token rates via the cf-aig-custom-cost header, allowing custom cost metrics to reflect negotiated cache pricing across different providers. The system automatically handles provider differences and prevents double-counting of cache tokens.

ai-gatewaycostspricingcacheapi
Feature

Cloudflare CASB integrates with Zoom for security scanning

Cloudflare CASB now offers native integration with Zoom to continuously scan for security misconfigurations, including weak password policies, unprotected meetings, insecure user accounts, and publicly accessible recordings. The integration uses pre-built OAuth and requires no manual setup, delivering findings in the Cloudflare One dashboard within minutes.

casbzoomsecurityssosaas
Improvement

Improved iOS tap-to-type experience for Browser Isolation

Browser Isolation now displays tap-to-type prompts inline over text fields on iOS instead of full-screen overlays, reducing disruption during text entry. If space is limited, a keyboard icon appears instead.

browser-isolationiosuxcloudflare-one
Improvement2026-09-08

WAF: Enhanced Next.js RCE Detection with Consolidated Rules

Cloudflare WAF enhanced its detection logic for Next.js remote code execution vulnerabilities by consolidating active beta rules into baseline signatures. Two beta rules targeting Next.js Image Optimizer RCE and CVE-2026-75604 are now merged into their respective primary rules with logging behavior upgraded to blocking.

wafsecurityrcenext.jscve
Improvement2026-09-08

Workers - Python 3.14 for Python Workers

Python workers now use Python 3.14 by default for all new workers with compatibility date 2026-09-08 or later, with the Pyodide runtime updated to 314.0.6.

workerspythonruntimeupgrade
Breaking5

Miniflare v5 prepares local development for the cf CLI

Miniflare v5 introduces a new configuration shape aligned with cloudflare.config.ts and removes deprecated APIs, legacy D1 bindings, and internal APIs to prepare the local development tooling for the upcoming cf CLI. Most projects using wrangler dev or the Vite plugin will not require action.

workersminiflarelocal-developmentbreakingcli
Feature

Radar search now includes Internet events

Cloudflare Radar search now includes Internet events and outages in search results, with the ability to filter by event descriptions, locations, ASes, bots, and domains. Event links preserve date ranges for easier investigation, and results are also available to browser-based AI agents through WebMCP.

radarsearchinternet-eventsoutagesobservability
Feature

WAF - Enforce positive security with Application Profiles

Application Profiles introduce positive-security to Cloudflare WAF by learning what valid requests to your application look like and flagging traffic that deviates from expected structures. Schema Profiles learn path variables, query parameters, headers, cookies, and request bodies with field type validation, and can be enforced via custom rules after review in Security Analytics.

wafsecurityapi-securityapplication-profilesthreat-detection
Feature4.113.0

Email Routing addresses now configurable with Wrangler

Wrangler 4.113.0 and later can now manage Email Routing rules directly through configuration, allowing you to define literal recipient addresses or apex-domain catch-all patterns without manual setup.

email-routingwranglerworkersconfiguration
Feature

Manage Email Routing rules with Wrangler

You can now configure Email Routing rules directly in your Wrangler configuration file to route emails to Workers. Wrangler will automatically create, update, and remove rules when you deploy, with confirmation prompts for destructive changes.

email-routingworkerswranglerconfiguration
Feature

Enterprise customers can self-serve CDN upload limits up to 5 GB

Enterprise customers can now configure CDN maximum upload size up to 5 GB directly from the Cloudflare dashboard, eliminating the need to contact support for request bodies between 500 MB and 5 GB. The default remains 500 MB, with limits above 5 GB still requiring account team assistance.

cdnenterpriseuploadsconfigurationworkers
Improvement

Workers - Deploy larger Workers up to 64 MiB for all plans

Cloudflare removed compressed size limits for Workers and now only enforces a 64 MiB uncompressed size limit across free and paid plans, allowing developers to deploy larger dependencies and frameworks without restrictions.

workersdeploymentlimitsimprovement
Announcement

R2 Data Access Logs now generally available

R2 Data Access Logs are now generally available, allowing you to record object read, write, list, multipart upload, and delete operations across S3-compatible API, Cloudflare API, dashboard, Workers bindings, and public buckets. Logs are viewable in Workers Observability with filtering capabilities.

r2loggingobservabilityapistorage
Feature

Configure DHCP options from the dashboard on Cloudflare One Appliance

Users can now configure custom DHCP options directly from the Cloudflare dashboard when the One Appliance acts as a DHCP server, with support for common options like PXE boot, VoIP provisioning, and vendor-specific configurations, complementing existing API and Terraform workflows.

dhcpappliancedashboardnetworkingconfiguration
Feature

Create multiple Cloudflare Tunnel and Mesh routes at once

You can now create multiple Cloudflare Tunnel and Cloudflare Mesh routes in a single action from the Routes page, including support for comma-separated destinations, batching, and retry-only-failed functionality.

tunnelmeshroutesbulk-operationsui
Feature

Define custom applications for breakout and prioritized traffic from dashboard

You can now create, edit, and delete custom applications for traffic breakout and prioritization directly from the Cloudflare One Appliance dashboard without using the API. Custom applications can be matched by hostnames, IP subnets, and the new source subnets field for matching by source IP range.

cloudflare-oneappliancetraffic-managementdashboardui
Feature

Text rasterization and updates to the Images binding

Cloudflare Images now supports text rasterization to render text into images with customizable styling, metadata filtering to manage hosted images, server-side signing for private image URLs, and direct creator uploads. The Images binding also adds header management and improved caching options.

imagesapitext-renderingcloudflare-workersimage-optimization
Feature

Cache Rules now support configuring Origin Range Requests via Rulesets API

The Rulesets API now supports Origin Range Requests in Cache Rules, allowing Cloudflare to fetch large files from your origin in cache-aligned byte ranges. You can set origin_range_requests.mode to on, off, or default to control this behavior for any traffic matched by a Cache Rule.

cacheapirulesetsoriginperformance
Feature

Sandbox SDK - Run Cursor Cloud Agents on Cloudflare

Cursor self-hosted machines now enable running Cursor Cloud Agents on Cloudflare infrastructure, with agent execution isolated in containers and tools running in your controlled environment. An open-source Workers template simplifies deployment with all necessary resources including Durable Objects, R2 buckets, and cron triggers.

sdkagentscontainersworkerscloudflare
Feature

Python Workers now support WSGI and ASGI frameworks

Python Workers now support WSGI and ASGI web frameworks, enabling you to use popular frameworks like Django, Flask, FastAPI, and Starlette. You can use the wsgi.entrypoint or asgi.entrypoint utilities to integrate these frameworks with your Workers applications.

pythonworkerswsgiasgiframeworks
Security2026-09-01

WAF - Improved SQL Injection Detection for Complex Query Syntax

Cloudflare WAF now includes enhanced protection against SQL injection attempts that exploit complex query syntax, specifically covering WHERE comparisons combined with WITH clauses. This new detection rule blocks these attacks by default.

wafsecuritysql-injectionthreat-detection
Announcement

D1 enforces free tier daily query limits

Starting September 1, 2026, D1 queries on the Workers Free plan will fail when exceeding daily row read or write limits, returning errors until the limit resets at midnight UTC. Users can upgrade to a paid plan or optimize queries by adding indexes and reviewing full table scans to reduce row reads.

d1databaseworkersfree-tierlimits
Feature

Browser Run crawl endpoint respects Content Signals use directive

The /crawl endpoint now respects the use directive from the Content Signals standard, allowing site owners to control how their content may be used. A new contentUse parameter lets you declare your intended usage level (reference or full), and requests are rejected if they exceed a target site's robots.txt restrictions.

apibrowser-runcrawlcompliancecontent-signals
Feature

Load Balancing now supports pool sets

Load Balancing now supports pool sets via API, enabling geographic matching with location-specific traffic steering. One load balancer can use different routing behavior and steering policies for different geographic locations, countries, or regions.

load-balancingapitraffic-steeringgeo-routing
Feature

AI Search now supports GLM-5.3 Flash

AI Search now supports the GLM-5.3 Flash model for text generation, which features a 1,048,576-token context window and runs on Workers AI. Users can configure this model for their AI Search instances.

ai-searchworkers-aimodelsglm
Fix2026.7.1376.0

Cloudflare One Client for Windows GA release

Fixed a critical issue where the client could fail to connect or switch organizations due to invalid registration after version switches, and resolved DNS query failures affecting a small percentage of queries across platforms.

windowsclientdnsconnectivityfix
Fix2026.7.1377.0

Cloudflare One Client for Linux 2026.7.1377.0

A new GA release is now available for the Linux Cloudflare One Client. This hotfix resolves an issue where a small but noticeable percentage of DNS queries were failing across platforms.

dnslinuxstabilityclient
Feature

Z.ai GLM-5.3 now available on Workers AI

Cloudflare has released Z.ai's GLM-5.3 agentic coding model on Workers AI with substantial performance improvements over GLM-5.2, including 50% gains on Z.ai Code Bench and 6x improvements on Terminal Bench 3.0, while maintaining the same pricing of $1.40 per M input tokens and $4.40 per M output tokens.

workers-aiai-modelscodingperformanceglm-5-3
Improvement

Log Explorer - Improved dataset configuration

Log Explorer now offers a refreshed dataset configuration experience with grouped field selection, field details showing data types and requirements, bulk controls for field selection, and ingestion filters to control which events are ingested.

log-explorerlogginguiconfigurationdata-management
Improvement

Durable Objects support up to ten concurrent Dynamic Workers

Durable Objects can now use up to ten distinct Dynamic Workers with in-flight requests, increased from four, enabling better concurrency for shared I/O contexts. Other Workers retain a limit of four distinct Dynamic Workers per request.

durable-objectsworkerslimitsconcurrency
Fix

APO caches crawler and bot traffic again

Fixed a regression in Automatic Platform Optimization that prevented caching of HTML requests without explicit Accept: text/html headers, commonly from crawlers, bots, and monitors. These requests are now cached properly without requiring workarounds.

cachingapoperformancebotsfix
Improvement

API Shield - Increased JWT validation configuration limits

API Shield now supports 32 token configurations per zone (up from previous limits), with each configuration supporting up to 16 keys. This expansion enables more JWT configurations and facilitates better key rotation practices.

api-shieldjwtsecurityapilimits
Feature

Create app-scoped API tokens for Flagship

You can now create API tokens with access limited to specific Flagship apps instead of all apps in your account. Choose which apps each token can access and set granular permissions (Evaluate, Read, or Write) for improved security in server-side environments like Wrangler, CI, or backend services.

api-tokensflagshipsecuritypermissions
Feature

Z.ai GLM-5.3 Flash now available on Workers AI

The Z.ai GLM-5.3 Flash multimodal model is now available on Workers AI, offering improved performance over GLM-5.2 at lower cost with support for text and image inputs. It is accessible via the Workers AI binding, REST API, OpenAI-compatible endpoint, and AI Gateway.

workers-aimodelsmultimodalai-gateway
Feature

Delete Log Explorer datasets

Cloudflare Log Explorer customers can now permanently delete account and zone datasets from the dashboard or API with built-in deletion protection enabled by default to prevent accidental data loss. Deletion is irreversible and runs asynchronously.

log-explorerdatasetsapidashboard
Feature

AI Search adds six new Workers AI text generation models

AI Search now supports six additional text generation models on Workers AI, including DeepSeek, GPT-OSS, Qwen, and Kimi models. These models are available for selection when creating or updating AI Search instances without requiring external provider keys.

ai-searchworkers-aimodelstext-generation
Announcement

Azure Functions-based Microsoft Sentinel connector deprecation

Cloudflare is deprecating the Azure Functions-based Microsoft Sentinel connector due to Microsoft's deprecation of the Azure Monitor HTTP Data Collector API. Customers must migrate to the Cloudflare for Microsoft Sentinel Codeless Connector Framework connector by September 14, 2026.

loggingintegrationmicrosoft-sentineldeprecationazure
Security2026.08.26

Access service token secrets use scannable format

New Cloudflare Access service token Client Secrets created on or after August 26, 2026 use a scannable format with cfast_ prefix and checksum, making them easier for secret scanning tools to detect with fewer false positives. Existing secrets remain compatible and do not require rotation.

accesssecuritytokensauthentication
Feature

API Shield - Symmetric key support for JWT validation

API Shield JSON Web Token validation now supports symmetric keys using HS256, HS384, and HS512 algorithms. HMAC verification keys can be configured via the Cloudflare dashboard or API, with credentials never stored in plaintext.

api-shieldjwtauthenticationsecurityapi
Feature

Temporarily turn off Access service tokens

Cloudflare Access administrators can now disable service tokens without deleting them, allowing configuration to be preserved for later re-enablement. This helps contain credential exposure or pause automated services while maintaining the token's settings.

accessservice-tokenssecuritycredentials
Feature2026-08-25

WAF Release: Four new detections moved to Block, XSS rule merged

Four new WAF detections including HTTP/2 Request Smuggling and XSS JavaScript Event Handler Coercion are moved from Log to Block mode. The XSS, HTML Injection - Script Tag - Beta rule is merged into the original rule, and a new Generic Rules - Remote Code Execution detection is added in Block mode.

wafsecuritydetectionxssblocking
Feature

Grace periods for service token rotation

Cloudflare Access now supports grace periods during service token secret rotation, allowing both old and new secrets to remain valid for 1 hour to 30 days while administrators update services. The dashboard and API both support custom rotation schedules without interrupting authentication.

accessauthtokenssecurityapi
Improvement

AI Search supports larger custom metadata values

AI Search now supports larger custom metadata values within a shared 10 KiB metadata envelope per vector. The first 64 bytes of each indexed string remain filterable.

ai-searchmetadatavectorsfeature-enhancement
Feature2026-07-28

MCP server portals support MCP 2026-07-28 specification

MCP server portals now support the stateless MCP 2026-07-28 specification for client and upstream server connections, with automatic backward compatibility for earlier 2025 clients and independent protocol selection between clients and servers.

mcpaccessprotocolcompatibilityapi

Sign up to see more

97 more changes from Cloudflare. Sign up to read the whole changelog.

Sign up free

GitHub or email — no card needed.