C

Cloudflare Changelog

C
Cloudflare Changelog Cloud

AI Gateway, Web Search API - Introducing Web Search API

Web Search API is now available in beta. Web Search API lets your AI agents and applications search the Internet and ground their responses in live information, instead of guessing URLs or relying on a model's training cutoff. At launch, you can choose between three search providers: Ceramic.ai, Exa, and Linkup. All three support Zero Data Retention for requests made through Cloudflare, and all ha…

C
Cloudflare Changelog Cloud

Access, Cloudflare One - New strict service token authentication setting for Access

The strict service token authentication setting applies consistent behavior to requests made with service tokens. When the setting is on for a Zero Trust organization, Access handles requests with service token headers as follows: If authentication or authorization fails, Access always returns 401 or 403 instead of redirecting the client to the login page with 302. Only Service Auth policies can a…

C
Cloudflare Changelog Cloud

Agents, Workers - Run the Pi Durable harness on Cloudflare with the Agents SDK

The Agents SDK now provides first-class support for building agents using the Pi harness. You can build long-running agents using the combination of Pi 1.0 ↗︎, Pi Durable ↗︎, and the new PiHarness class that the Cloudflare Agents SDK provides, ensuring your agent's work is durably persisted, even if interrupted mid-turn. Built with Earendil ↗︎, this integration is our first step toward first-class…

C
Cloudflare Changelog Cloud

Rules - hash_in_range() is globally available for HTTP products

hash_in_range() is globally available for HTTP products on all plans. It hashes fields into an integer within a specified range. Use this result to select a portion of requests. Use cf.random_seed to select approximately 10% of requests at random: hash_in_range(0, 100, cf.random_seed) < 10 With Cloudflare for SaaS, use custom metadata to control rollout progression. Define rollout_pct as a custom…

C
Cloudflare Changelog Cloud

Analytics - Workers Observability logs and traces in Custom Dashboards

You can now build Custom Dashboards charts from Workers Observability data. Two new datasets, Workers Observability — Logs and Workers Observability — Traces (OTel), let you chart Worker invocations, log levels, errors, CPU and wall time, span counts, and durations next to HTTP traffic, security events, and other analytics datasets. This gives you one dashboard for an application that spans Cloudf…

C
Cloudflare Changelog Cloud

Analytics - 30 days of analytics data on every plan

Every plan now gets at least 30 days of analytics data. Adaptive analytics datasets, such as HTTP requests, security events, and DNS analytics, retain at least 31 days of data for Free and Pro domains, and you can query up to 30 days in a single request. Previously, Free and Pro domains could see between 24 hours and 8 days of history depending on the dataset. A full month of history lets you inve…

C
Cloudflare Changelog Cloud

KV - Workers KV namespace jurisdictions are now generally available

Jurisdictions for Workers KV namespaces are now generally available. When you create a namespace, you can set a jurisdiction to make sure the namespace's data is only durably stored within that region. Jurisdictions can help you comply with data localization regulations such as GDPR or FedRAMP. Supported jurisdictions are eu, us, and fedramp. A jurisdiction can only be set when a namespace is crea…

C
Cloudflare Changelog Cloud

Cloudflare Tunnel - Protect Quick Tunnels with email authentication

You can now restrict who can access a Quick Tunnel. Use the new --allowed-mail flag in cloudflared to require visitors to authenticate with a one-time PIN sent to their email before they reach your local service. cloudflared tunnel --url http://localhost:8080 --allowed-mail alice@example.com Previously, anyone with a trycloudflare.com URL could access the service behind it. Protected Quick Tunnels…

C
Cloudflare Changelog Cloud

Workers AI - Introducing Clef: Cloudflare's first open-source decision models, now on Workers AI

Meet @cf/cloudflare/clef and @cf/cloudflare/clef-flash, the first models trained by the Cloudflare Workers AI team, available on Workers AI today. Clef is a decision model, in the same family as Typesafe's Jev ↗︎. Instead of generating text, it reads an input state and a set of typed questions, then returns a probability for every allowed answer. Your agent gets a structured decision it can act on…

C
Cloudflare Changelog Cloud

Cloudflare Fundamentals - Account members can self-serve create Account API tokens

Account API token creation is no longer limited to Super Administrators. Members with the API Token Provisioning role can now create Account API tokens via the Dashboard, API, Terraform, or CF CLI, making it easier for developers and platform teams to provision credentials without depending on a Super Administrator for Account API Token Provisioning. What's new Delegated creation: Members with the…

C
Cloudflare Changelog Cloud

Cloudflare One, Access - Simplified permissions for tagging targets with Access for Infrastructure

You can now tag targets using only the Zero Trust Write API token permission. Previously, tagging targets through the API required both Zero Trust Write and Tag Write permissions on the API token. This change applies to inline target tagging through the Infrastructure Access Targets API. Tagging resources through the general Resource Tagging API still requires the Tag Admin, Tag Write, or equivale…

C
Cloudflare Changelog Cloud

Agents, Workers - The best way to do MCP auth just got better: Workers OAuth Provider goes v1, with a new split API and full support for MCP 2026-07-28

@cloudflare/workers-oauth-provider ↗︎ is now v1, with a new split API. One Worker acts as the authorization server: it signs users in and issues tokens. Your MCP server acts as the resource server, and can run in another Worker. It validates each token with the authorization server over a Service Binding, without crossing the public Internet. It supports the MCP 2026-07-28 authorization specificat…

C
Cloudflare Changelog Cloud

Artifacts, Workers - Artifacts is now in open beta

Artifacts, Cloudflare's versioned file system that speaks Git, is now in open beta. Artifacts is built for scale, so you can create a repository per project, user, session, or task. With Artifacts, you can: Deploy repositories to Workers — Connect an Artifacts repository through Workers Builds. Pushes to the production branch deploy the updated Worker, while other branches create or update Worker…

C
Cloudflare Changelog Cloud

WAF - WAF Release - 2026-10-01 - Emergency

This update provides immediate defense against a vulnerability affecting Citrix NetScaler ADC and Gateway appliances, deploying protection against improper input validation vectors. Key Findings CVE-2026-88771: An improper input validation vulnerability affecting Citrix NetScaler ADC and Gateway allows an unauthenticated attacker to execute arbitrary commands. Impact We strongly recommend that adm…

C
Cloudflare Changelog Cloud

Rules - Compare dynamic values in Rules expressions

Cloudflare Rules expressions now support dynamic values on both sides of equality and ordering comparisons. You can compare request fields or function results with one another. For example, compare the current request path with its original value: http.request.uri.path ne raw.http.request.uri.path For supported operators and examples, refer to Compare dynamic values.

C
Cloudflare Changelog Cloud

Rules - Handle missing values with coalesce()

The coalesce() function returns the first argument that is not nil. Use it to provide a fallback in rule expressions: http.request.uri.path eq coalesce(http.request.uri.args["expected_path"][0], "/") For details, refer to the coalesce() function reference.

C
Cloudflare Changelog Cloud

AI Search - AI Search is generally available

AI Search is now generally available. Usage-based billing begins on November 1, 2026, with included monthly ingestion, storage, semantic query, and full-text query usage. Cloudflare will send a reminder email the week before billing begins. Refer to Limits & pricing for rates and included usage. Hybrid search is on by default New AI Search instances use hybrid search by default. Hybrid search comb…

C
Cloudflare Changelog Cloud

Basin, Basin Pipelines, Basin Catalog, Basin SQL - Cloudflare Basin is now generally available

Basin, formerly the Cloudflare Data Platform, is now generally available. Basin brings an end-to-end analytics platform to the Developer Platform, enabling you to collect data from a variety of sources, such as apps, infrastructure, devices, and other Cloudflare services, then query it to answer analytical questions. Basin Pipelines Basin Pipelines, formerly Cloudflare Pipelines, ingests events fr…

C
Cloudflare Changelog Cloud

Basin Pipelines, Basin - Basin Pipelines ingest limit increased to 1 GB/s

Each Basin Pipelines stream can now ingest up to 1 GB/s, increased from 5 MB/s. The higher per-stream limit gives high-volume application events, telemetry, and logs more room to grow without splitting ingestion across streams solely to stay within the previous limit. For the full list of stream, sink, and pipeline limits, refer to Basin Pipelines limits.

C
Cloudflare Changelog Cloud

Workers - Web Crypto adds ML-KEM and ML-DSA support

The Workers Web Crypto API now supports ML-KEM-768, ML-KEM-1024, ML-DSA-44, ML-DSA-65, and ML-DSA-87. ML-KEM establishes shared secrets, while ML-DSA signs and verifies data. The opt-in API also adds key encapsulation and decapsulation methods, getPublicKey(), SubtleCrypto.supports(), and JSON Web Keys (JWKs) with the AKP key type. Turn on the webcrypto_modern_algorithms compatibility flag to use…

C
Cloudflare Changelog Cloud

Durable Objects - Pending I/O operations allow Durable Objects to continue long-running work without a connected client

Durable Objects remain active while handling a request from a connected client. This change applies when no client is connected, such as when an agent continues a submitted job after its client disconnects. This behavior is the default for Workers with a compatibility date of 2026-10-01 or later. To use it with an earlier date, add the durable_object_io_tasks_prevent_eviction compatibility flag. T…

C
Cloudflare Changelog Cloud v1.0

Sandboxes - Sandbox SDK 1.0: control every sandbox from your own Durable Object

Sandbox SDK 1.0 is available. Your own Durable Object class now controls each sandbox container directly, through the Durable Object container API on this.ctx.container. With 1.0, your class can: Choose the image and instance size each time it starts a sandbox. One class can run sandboxes on different images, and a deploy does not restart sandboxes that are running. Save the files of a sandbox as…

C
Cloudflare Changelog Cloud v2026.8.2033.1

Cloudflare One Client - Cloudflare One Client for Windows (version 2026.8.2033.1)

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page. This beta release includes the following changes and improvements: Fixed an issue that could briefly block traffic to split tunnel excluded resources while the client was connecting or reconnecting. Improved reauthentication reliability and fixed an issue where a reauthentication could fo…

C
Cloudflare Changelog Cloud

Containers - Snapshot and restore Container filesystem

Containers now support snapshot APIs in public beta for saving and restoring point-in-time filesystem state. Create a snapshot first, then pass it back to start() to restore files after container sleep, restart, or handoff to another Durable Object. Use snapshotContainer() through the Durable Object Container API to capture the full container filesystem. Create a snapshot from a running Container,…

C
Cloudflare Changelog Cloud

Containers - New scheduling policy for Containers to configure image and instance from Durable Objects

Containers now support the durable_object scheduling policy in public beta. This policy lets a Durable Object select the image and instance size for a Container at runtime instead of using one centrally managed configuration for the application. To use custom images, configure the policy and one or more named images in Wrangler: { "containers": [ { "class_name": "AgentComputer", "scheduling_policy…

C
Cloudflare Changelog Cloud

logpush, Logs - Transformers are now generally available

Transformers are now generally available for supported Logpush datasets on Free, Pro, Business, and Enterprise plans. Use SQL to filter records, reshape fields, redact sensitive values, compute new fields, or add metadata before Logpush delivers each batch. Create and preview Transformers in Transformer Studio or through the Cloudflare API, then attach them to eligible account-scoped or zone-scope…

C
Cloudflare Changelog Cloud

logpush, Logs - Logpush is now available on all plans with usage-based pricing

Cloudflare Logpush is now available on Free, Pro, Business, and Enterprise plans with usage-based pricing. Free, Pro, and Business customers can enable Logpush through self-service. Enterprise customers continue to work with their account team. Logpush Transformers are also now generally available. Each account receives included monthly usage before charges apply: Internal exports: 25 GB per month…

C
Cloudflare Changelog Cloud

WAF - WAF Release - 2026-09-30

This release introduces new detections to enhance protection against a specific GitLab path traversal vulnerability, alongside advanced generic rules targeting HTTP request smuggling, directory traversal, and command injection attempts. Key Findings CVE-2026-85706: A path traversal vulnerability affecting GitLab. RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionCommentsCloudflare Ma…

C
Cloudflare Changelog Cloud

Browser Isolation, Gateway, Cloudflare One - Role-based access control for Browser Isolation policies

Isolation policies support role-based access control (RBAC). Because isolation policies are Gateway HTTP policies with the Isolate action, Gateway's account-level and resource-scoped roles apply to them directly. Use the Zero Trust HTTP Policies Admin account-level role to grant access to all HTTP policies in the account. You can also assign a resource-scoped role to let a team member manage a spe…

C
Cloudflare Changelog Cloud

Monetization Gateway - Monetization Gateway closed beta

Monetization Gateway is now available in closed beta. Sellers can use it to charge agents for access to APIs, Model Context Protocol (MCP) tools, sites, and datasets. Sellers (domain owners) define which requests require payment, the cost, and where the payment should be sent. Buyers receive the payment instructions, sign an authorization, and receive the resource after the payment has been settle…