Access for Infrastructure now integrates with Resource Tagging, letting you attach key-value tags to infrastructure targets and use them in access policies, managed inline on a target or via the central Resource Tagging API with tags kept in sync across both. Target criteria support include, require, and exclude operators that each match by hostname, tag, or both.
Cloudflare One
npx @buildinternet/releases get cloudflare-oneCloudflare Access can request fresh authentication from a SAML identity provider on every login by enabling Require reauthentication in the dashboard or setting force_authn to true via the API, which makes Access set ForceAuthn to true in signed and unsigned SAML authentication requests. The option defaults to false.
Passive Detection for Cloudflare Data Loss Prevention samples Gateway HTTP request and response bodies to surface sensitive data types and their destinations, without requiring a Gateway DLP policy. Existing Gateway policies continue to apply, and available detection entries depend on the account's Zero Trust plan.
A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page.
A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page.
Cloudflare CASB now integrates with Zoom through Cloudflare's pre-built OAuth application, requiring no manual app setup, and continuously scans accounts for findings after an initial scan. Scans cover account settings, user accounts, meetings, recordings, and sensitive content via DLP Profile matching.
Browser Isolation on iOS now shows the tap-to-type prompt inline over the focused text field instead of as a full-screen overlay; small fields display a keyboard icon instead. iOS users should tap twice to begin entering text.
define custom applications for breakout and prioritized traffic directly from the Appliance dashboard's Traffic Steering panel, with new Source subnets matching, without calling the API. Edit or delete existing custom applications in the same panel.
DHCP options can now be configured directly from the dashboard when the Cloudflare One Appliance acts as the LAN's DHCP server, complementing the existing API and Terraform workflow. Options include common PXE/iPXE boot, VoIP provisioning, and vendor-specific settings, or custom option codes.
You can now create multiple Cloudflare Tunnel and Cloudflare Mesh routes from the Routes page in a single action, instead of submitting one at a time. When creating a route you can add multiple destinations as a comma-separated list, queue up additional routes before creating them all together, and retry only the routes that failed in a batch since successful ones are removed from the form automatically.
Fixed an issue where a small but noticeable percentage of DNS queries fail across platforms.
Fixed a critical issue where the client could fail to connect or switch organizations due to invalid registration after switching installed client versions, and resolved DNS query failures affecting a portion of queries across platforms.
This hotfix resolves an issue where a small but noticeable percentage of DNS queries fail across platforms.
Service token Client Secrets created on or after August 26, 2026 use the cfast_ prefix plus checksum format, improving detection by secret scanning tools. Existing secrets continue to work without rotation, and both formats use the same Client ID and authentication headers.
Access administrators can now disable service tokens without deleting them; disabled tokens can't authenticate but retain their configuration for later re-enabling, and disabling also stops any previous secret in an active rotation grace period. Useful for containing suspected credential exposure or pausing an automated service.
Cloudflare Access administrators can now choose a grace period when rotating a service token secret, keeping both secrets valid during the transition instead of interrupting authentication. Grace periods range from one hour to 30 days in the dashboard, with immediate revocation available and RFC 3339 expiration times for the API.
MCP server portals now support the stateless MCP 2026-07-28 specification for both client and upstream connections. The /mcp endpoint auto-accepts stateless requests and falls back to the 2025 handshake when needed; client and upstream protocol selection are independent, and SSE continues to use the legacy protocol.
When registering a Cloudflare One Virtual Appliance, you can now select your hypervisor and download the appliance directly from the dashboard — no need to look up asset URLs. Choose from VMware ESXi (OVA image), Proxmox, or libvirt/KVM (install script), and use View setup guide for deployment instructions.
CASB remediation policies can automatically revoke or remediate Microsoft 365 and Google Workspace file-sharing findings without manual triage. Policies can also send webhooks to third-party destinations, and both actions can be combined in a single policy.
Test scan checks how Data Loss Prevention evaluates sample content—paste text, upload a file or HAR file—before applying a profile to production traffic. Content goes directly to the DLP scanner, so Gateway policies are not evaluated and no Gateway activity logs are created. Available to all Cloudflare Zero Trust customers.