Log Explorer datasets are now queried from the Logs page under Observability, which combines Log Explorer and Workers Observability datasets with a shared filter builder, SQL editor, and visualizations. The Log Explorer menu is no longer shown in dashboard navigation, though enabled datasets, saved queries, and SQL queries continue to work and the previous Log Search page remains at its direct URL.
Core Platform Changelog
npx @buildinternet/releases get cloudflare-core-platformCloudflare Organizations is now generally available for Enterprise customers and MSSP/Distributor partners, providing a top-level container for centrally managing accounts, members, analytics, and shared policies. Organization Super Administrators get implicit access to every account in their Organization without separate account memberships; Enterprise customers use a single-tier Organization while MSSP/Distributor partners can use nested sub-organizations for customer accounts. Organization Roles remains in beta with current product limitations still applying.
The new --allowed-mail flag in cloudflared requires visitors to authenticate with a one-time PIN sent to their email before reaching the local service, and accepts a single address, repeated or comma-separated addresses, or a domain wildcard like *@example.com. Previously anyone with a trycloudflare.com URL could reach the service, and access ends for everyone when the cloudflared process stops.
Two new datasets, Workers Observability — Logs and Workers Observability — Traces (OTel), let Custom Dashboards chart Worker invocations, log levels, errors, CPU and wall time, span counts, and durations alongside HTTP traffic and security events. The datasets are available for Workers with Workers Logs or Workers Traces enabled, and accounts can now have up to 100 dashboards.
hash_in_range() is globally available for HTTP products on all plans, hashing fields into an integer within a specified range to select a portion of requests. Cloudflare for SaaS users can control rollout progression with custom metadata keys like rollout_pct.
Free and Pro domains now retain at least 31 days of adaptive analytics data for HTTP requests, security events, and DNS analytics, with up to 30 days queryable per request, up from 24 hours to 8 days depending on dataset. Domain analytics also consolidate into a single dashboard view where Traffic, Performance, Security, Cache, Origin, DNS, and Visitors share one time range and filters; aggregated datasets like httpRequests1hGroups keep their existing per-plan limits.
Cloudflare Organizations now support up to 20,000 accounts and 200,000 zones, applied at the root Organization for MSSP/Distributors using sub-organizations. The new limits cover enterprise and MSSP/Distributor Organizations, while legacy reseller partner and brand partner tenants retain their existing quota behavior.
Rules expressions now support dynamic values on both sides of equality and ordering comparisons, allowing request fields or function results to be compared with one another, such as comparing the current request path with its original value via http.request.uri.path ne raw.http.request.uri.path.
Account API token creation is no longer limited to Super Administrators: members with the API Token Provisioning role can create tokens via the Dashboard, API, Terraform, or CF CLI. OAuth clients requesting the account_api_tokens:create scope can now create tokens, and Account API tokens carry creator metadata, so Administrators see all tokens while provisioning-role members see only their own.
Rule expressions can now use the coalesce() function to return the first argument that is not nil, providing fallback values as in http.request.uri.path eq coalesce(http.request.uri.args["expected_path"][0], "/").
Transformers are now generally available for supported Logpush datasets on all plans, letting users filter records, reshape fields, redact sensitive values, compute new fields, and add metadata with SQL before each batch is delivered. They can be created and previewed in Transformer Studio or the Cloudflare API and attached to NDJSON account- or zone-scoped Logpush jobs, with 1 GB of transformation input per account each month and $0.04 per GB beyond that.
Monetization Gateway is now available in closed beta, letting sellers charge agents for access to APIs, MCP tools, sites, and datasets. Sellers define which requests require payment, the cost, and where payment is sent; buyers receive payment instructions, sign an authorization, and receive the resource after settlement, with payment authorization handled in the HTTP request flow via the x402 protocol.
Logpush is now available on Free, Pro, Business, and Enterprise plans with usage-based pricing, and Logpush Transformers are generally available. Each account gets 25 GB per month of internal and external exports and 1 GB of transformations before charges apply, at $0.03, $0.10, and $0.04 per additional GB respectively.
Gateway network logs and Zero Trust Network Session Logs now identify Mesh node and Workers VPC traffic, which previously were logged as Cloudflare One Client devices or not recorded at all. New fields include OnrampType, SourceName and SourceID for the originating Worker, and DestinationReplicaID for the exact Cloudflare Tunnel, cloudflared, or Mesh node replica that served a session.
The concat() function in Cloudflare Rules now accepts up to 32 arguments, doubled from 16, letting expressions combine more request and network data into a single value. A common use case is building a request header that forwards context such as client IP, country, host, method, path, ray ID, ASN, and user agent to the origin.
Starting in 2027, Cloudflare will no longer publish new cloudflared releases for 32-bit Windows or Intel-based macOS. The change follows Windows 10 end of support in October 2025 and Apple's removal of Intel Mac support in macOS 27.
Logpush jobs can now exclude identified DDoS attack traffic to reduce attack traffic in delivered logs, supported for the http_requests, firewall_events, and network_analytics_logs datasets. Enable it via the Exclude DDoS attack traffic option under Advanced Options in the dashboard or by setting filter_attack_traffic to true in the API job request.
Ruleset changes can now be validated before deployment to catch invalid expressions, action parameters, permission issues, unavailable features, and quota limits without publishing the configuration. Supported Rulesets API mutation endpoints accept a dry_run=true query parameter that performs the same authorization and server-side validation checks but does not persist the change, and the dashboard validates automatically when rules are created or updated.
All customers can now create additional Free accounts through self-serve dashboard flows, and standalone Free accounts can be created programmatically via user-owned API tokens or OAuth access tokens. Super Administrators can also create up to five Free accounts directly within an Enterprise Organization.
Enterprise customers can configure a zone's maximum CDN upload size up to 5 GB from the Network page in the Cloudflare dashboard, without contacting their account team or Support. The default remains 500 MB, limits above 5 GB still require Support, and very large uploads may hit connection or read timeouts before reaching the configured limit.



