Securing non-human identities: automated revocation, OAuth, and scoped permissions

TL;DR AI
2 min readKey summary
Cloudflare announced new security controls for non-human identities used by agents, scripts, and third-party apps.
The updates include scannable token formats and automatic revocation of exposed public tokens to reduce credential leakage risk.
They also improve OAuth visibility and add resource-scoped RBAC permissions to limit overly broad access.
The goal is to reduce impersonation, unauthorized access, and data loss caused by leaked secrets or compromised credentials.
