Access service token secrets use scannable format
New Cloudflare Access service token Client Secrets created on or after August 26, 2026 use a scannable format with cfast_ prefix and checksum, making them easier for secret scanning tools to detect with fewer false positives. Existing secrets remain compatible and do not require rotation.
Cloudflare Access service token Client Secrets created on or after August 26, 2026, use the format cfast_[40 alphanumeric characters][8-character checksum]. The prefix and checksum make these credentials easier for secret scanning tools to identify with fewer false positives.
Existing service token secrets continue to work and do not require rotation. Both formats use the same Client ID and the same CF-Access-Client-Id and CF-Access-Client-Secret authentication headers.
For more information, refer to Service tokens.
Source: original entry ↗