Sign in

Cloudflare

@cloudflare.social
12K followers 59 following 1.4K posts

Cloudflare is the world’s leading connectivity cloud, and we have our eyes set on an ambitious goal — to help build a better Internet.

PostsRepliesMedia
Cloudflare @cloudflare.social · 1m
Pay Per Use is now in beta. AI companies report when they use publishers’ content, and Cloudflare handles billing, payouts, and reporting, so our customers are paid according to use. cfl.re/4rOLSv1 #BirthdayWeek
blog.cloudflare.com
Pay Per Use: when AI uses your work, you should get paid
Pay Per Use is now in beta. AI companies report when they use publishers’ content, and Cloudflare handles billing, payouts, and reporting, so our customers are paid according to use.
010
Cloudflare @cloudflare.social · 32m
Today, we are releasing Cloudflare's Auto Router in public beta, available through AI Gateway. Find out more: cfl.re/3VI2gBs #BirthdayWeek
blog.cloudflare.com
Cut your AI spend with AI Gateway's Auto Router
Cloudflare AI Gateway now features a model router that evaluates request complexity using an edge-deployed classifier to select the optimal model. By balancing expected output quality against token co...
010
Cloudflare @cloudflare.social · 1h
Today, we’re making the Cloudflare Monetization Gateway available as part of a closed beta, and showcasing four customer use cases that are in production today. cfl.re/4y4IwWs #BirthdayWeek
blog.cloudflare.com
Monetization Gateway beta: charge AI agents for consumption with HTTP 402
Cloudflare’s AI Gateway, Ceramic.ai, Stocktwits, and more are using the Cloudflare Monetization Gateway today to charge agents for access to tokens, APIs, and MCP tools. U.S.-based sellers can now app
041
Cloudflare @cloudflare.social · 1h
You can now use built-in error monitoring in Cloudflare Workers to group production failures and send stack traces, logs, traces, and application context directly to a coding agent to investigate further and open a pull request. cfl.re/4AI8PEg #BirthdayWeek
blog.cloudflare.com
Detect and send production issues straight to your agent
You can now use built-in error monitoring in Cloudflare Workers to group production failures and send stack traces, logs, traces, and application context directly to a coding agent to investigate furt...
050
Cloudflare @cloudflare.social · 2h
Cloudflare Registrar’s new search delivers fast, transparent results across 420+ extensions using Workers, Durable Objects, and WebSockets. Its expanded API and cf CLI also let agents search, register, and transfer domains. cfl.re/4rL7Jni #BirthdayWeek
blog.cloudflare.com
Simplifying domains for people and agents
Cloudflare Registrar’s new search delivers fast, transparent results across 420+ extensions using Workers, Durable Objects, and WebSockets. Its expanded API and cf CLI also let agents search, register...
030
Cloudflare @cloudflare.social · 2h
AI Gateway User Insights now adds task, model, turn, and user categories to help teams understand AI adoption and make better model decisions. This is available free to AI Gateway users. cfl.re/4xX5fn9 #BirthdayWeek
blog.cloudflare.com
Identify AI model overuse with User Insights
AI Gateway User Insights now adds task, model, turn, and user categories to help teams understand AI adoption and make better model decisions. This is available free to AI Gateway users.
030
Cloudflare @cloudflare.social · 3h
This week, Cloudflare's Impact programs will reach $100 million in donated services. Thousands of entities including journalists, civil society, state and local governments, election management bodies, and public schools are being protected from cyberattacks. cfl.re/4xVEFLb #BirthdayWeek
blog.cloudflare.com
Cloudflare Impact reaches $100 million in donations
This week, Cloudflare's Impact programs will reach $100 million in donated services. This milestone means that thousands of entities including journalists, civil society, state and local governments, ...
031
Cloudflare @cloudflare.social · 3h
Cloudflare Containers now start 6x faster, let your agent choose each sandbox's image and instance type at runtime, and support filesystem snapshots in public beta, all controlled from a Durable Object. cfl.re/4z9xz6Q #BirthdayWeek
blog.cloudflare.com
Cloudflare Containers, rebuilt to scale agent sandboxes
140
Cloudflare @cloudflare.social · 3h
More than half the traffic reaching sites on Cloudflare is now automated, and AI agents are the fastest-growing part of it. We're giving site owners the tools to see who's visiting, decide who gets in, and charge for access. cfl.re/4iWCwuU #BirthdayWeek
blog.cloudflare.com
The Internet has a second audience
092
Cloudflare @cloudflare.social · 19h
Thank you #CloudflareConnect Diamond sponsor Oracle! 💎 Build secure, high-performance application and AI experiences across hybrid and multicloud deployments with Cloudflare and Oracle Cloud Infrastructure (OCI). Register to experience the event together: cfl.re/4yRYLYx
042
Cloudflare @cloudflare.social · 29/09/2026
Cloudflare introduces an adaptive security framework connecting risk discovery, agent governance, runtime protection, and AI-powered response in a continuous learning loop. cfl.re/4yh1Yjq #BirthdayWeek
blog.cloudflare.com
Adaptive application security for the AI era: how Cloudflare connects code, traffic, and intelligence to stop attacks
Cloudflare introduces an adaptive security framework connecting risk discovery, agent governance, runtime protection, and AI-powered response in a continuous learning loop.
140
Cloudflare @cloudflare.social · 29/09/2026
We built a WAF tester that adapted each request based on what the WAF blocked or passed. This helped us explore variations that a fixed test might miss. cfl.re/4jvBrdD #BirthdayWeek
blog.cloudflare.com
We tested our own WAF with frontier AI models. Here’s what we found
We built a WAF tester that adapted each request based on what the WAF blocked or passed. This helped us explore variations that a fixed test might miss. We ran it across six attack categories on an au...
040
Cloudflare @cloudflare.social · 29/09/2026
Cloudflare has added visibility into post-quantum (PQ) encryption in TLS 1.3 directly into HTTP Analytics, Log Explorer, and Logpush. Learn how to make sure your domain is protected with PQ encryption. cfl.re/4ABlqsM #BirthdayWeek
blog.cloudflare.com
Is your domain using post-quantum encryption? Now you can see for yourself
Cloudflare has added visibility into post-quantum (PQ) encryption in TLS 1.3 directly into HTTP Analytics, Log Explorer, and Logpush. Learn how to make sure your domain is protected with PQ encryption...
080
Cloudflare @cloudflare.social · 29/09/2026
We’re building CryptoLabe, an internal AI-powered tool that discovers cryptography across our codebase, surfaces dependencies, and helps us progress toward a full post-quantum migration by 2029. Here’s what we’ve learned so far. cfl.re/4hkQVjo #BirthdayWeek
blog.cloudflare.com
Using AI to chart a course for our post-quantum migration
We’re building CryptoLabe, an internal AI-powered tool that discovers cryptography across our codebase, surfaces dependencies, and helps us progress toward a full post-quantum migration by 2029. Here’...
061
Cloudflare @cloudflare.social · 29/09/2026
A sophisticated attacker with a quantum computer can exploit a protocol design flaw to downgrade post-quantum IPsec tunnels to classical crypto. We helped the IETF develop a transcript authentication extension to prevent these attacks. cfl.re/4ylR0JH #BirthdayWeek
blog.cloudflare.com
Preventing quantum downgrade attacks against IPsec
A sophisticated attacker with a quantum computer can exploit a protocol design flaw to downgrade post-quantum IPsec tunnels to classical crypto. We helped the IETF develop a transcript authentication ...
050
Cloudflare @cloudflare.social · 29/09/2026
We are expanding access to Cloudforce One's Threat Events Platform to every Cloudflare account and introducing Threat Signals. Threat Signals automatically parses open-source threat reporting, and connects threat context directly to your WAF rules. cfl.re/4ddbE6a #BirthdayWeek
blog.cloudflare.com
Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account
We are expanding access to Cloudforce One's Threat Events Platform to every Cloudflare account and introducing Threat Signals. Threat Signals automatically parses open-source threat reporting, extract...
080
Cloudflare @cloudflare.social · 29/09/2026
Cloudflare learns the structure of your HTTP requests and identifies deviations. You can add a positive security layer that helps reduce attack surface as AI makes it easier for attackers to generate and vary payloads. cfl.re/4z5922I #BirthdayWeek
blog.cloudflare.com
Enforce positive security with Cloudflare Application Profiles
Cloudflare learns the structure of your HTTP requests and identifies deviations. You can add a positive security layer that helps reduce attack surface as AI makes it easier for attackers to generate ...
060
Cloudflare @cloudflare.social · 29/09/2026
As post-quantum signatures threaten to inflate TLS handshakes and certificate transparency logs, Merkle Tree Certificates offer a path to compact, auditable authentication. Cloudflare’s new certificate authority will support MTC issuance at scale. cfl.re/4ynqS12 #BirthdayWeek
blog.cloudflare.com
Building a post-quantum certificate authority with Merkle Tree Certificates
Cloudflare’s new certificate authority will support MTC issuance at scale.
1110
Cloudflare @cloudflare.social · 29/09/2026
Twelve years after launching Universal SSL, Cloudflare is applying to become a certificate authority. By combining an established root, an ACME-first approach, and Merkle Tree Certificates, we are building a post-quantum CA for the open web. cfl.re/4rA7ECu #BirthdayWeek
blog.cloudflare.com
Building a certificate authority for the whole Internet
Today we are announcing the first concrete milestones in that effort: We have applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs, and we have signed a definitive agreement to acquire an established, broadly trusted root from GlobalSign.
1292
Cloudflare @cloudflare.social · 28/09/2026
Cloudflare just turned 16! To celebrate we're offering $100 off #CloudflareConnect San Francisco (October 19-21). Use code CONNECT100 at checkout. Valid through October 5. cloudflare.com/connect
091
Cloudflare @cloudflare.social · 28/09/2026
Be among the first to govern connections between your workforce, MCP servers, and internal data. cfl.re/45tzEgU
030
Cloudflare @cloudflare.social · 28/09/2026
EmDash 1.0 is a stable, open source CMS built for Astro, with agent-friendly workflows, secure sandboxed plugins, and a decentralized registry that keeps publishers in control. cfl.re/4xKmgAN #BirthdayWeek
blog.cloudflare.com
EmDash 1.0: the stable CMS with a secure plugin registry
EmDash 1.0 is a stable, open source CMS built for Astro, with agent-friendly workflows, secure sandboxed plugins, and a decentralized registry that keeps publishers in control.
0274
Cloudflare @cloudflare.social · 28/09/2026
Vinext 1.0 graduates from an AI experiment to a production-ready framework, letting developers run Next.js apps on Vite. This release brings advanced cache warming, broader compatibility, and an automated testing pipeline. cfl.re/4hQbVhV #BirthdayWeek
blog.cloudflare.com
Next.js applications, powered by Vite: introducing Vinext 1.0
Vinext 1.0 graduates from an AI experiment to a production-ready framework, letting developers run Next.js apps on Vite. This release brings advanced cache warming, broader compatibility, and an autom...
0111
Cloudflare @cloudflare.social · 28/09/2026
We are releasing cf, our new command-line tool that mirrors the entire Cloudflare API and supports programmatic TypeScript configuration. We are also open-sourcing Forge, our internal SDK generator. cfl.re/4xNVnfe #BirthdayWeek
blog.cloudflare.com
Introducing cf: the agentic CLI for the entire Cloudflare API
We are releasing cf, our new command-line tool that mirrors the entire Cloudflare API and supports programmatic TypeScript configuration. We are also open-sourcing Forge, our internal SDK generator.
1396
Cloudflare @cloudflare.social · 28/09/2026
With the new experimental support for the Emscripten target in Rust Workers, many previously unsupported Rust libraries and applications can now be built and deployed directly to Cloudflare’s global Workers platform, including upcoming support for Tokio async. cfl.re/4hlHSNC #BirthdayWeek
blog.cloudflare.com
Supporting native Rust in Workers with the new Emscripten target for wasm-bindgen
With the new experimental support for the Emscripten target in Rust Workers, many previously unsupported Rust libraries and applications can now be built and deployed directly to Cloudflare’s global W...
0175
Cloudflare @cloudflare.social · 28/09/2026
We’ve updated Kitesurf, our Workers-based browser for AI agents, with WebMCP support, improved DOM performance, and terminal-based rendering. With over 730,000 Web Platform subtests passing, agents can now navigate complex sites faster. cfl.re/3T8dpeb #BirthdayWeek
blog.cloudflare.com
The road to the agentic browser: A Kitesurf update
We’ve updated Kitesurf, our Workers-based browser for AI agents, with WebMCP support, improved DOM performance, and terminal-based rendering.
080
Cloudflare @cloudflare.social · 28/09/2026
Cloudflare is launching The Cold Start, a startup competition giving five early-stage companies five minutes on stage at #CloudflareConnect. Grand Prize winner receives $500,000 in credits, a San Francisco billboard, and an invitation to our VIP speakers dinner. cfl.re/3T85s8P #BirthdayWeek
blog.cloudflare.com
Introducing The Cold Start: pitch your startup live at Cloudflare Connect
This October, as Cloudflare turns 16, we want to give five early-stage startups a stage of their own.
070
Cloudflare @cloudflare.social · 28/09/2026
Since joining Cloudflare, VoidZero has delivered more than 80 releases that drastically speed up JavaScript compilation, linting, and testing. From a 10x faster React compiler to Vite+ 1.0, here’s how we are building faster tools for developers and AI agents. cfl.re/4AwHx3L #BirthdayWeek
blog.cloudflare.com
Four months of VoidZero at Cloudflare: making the open-source JavaScript toolchain faster for all humans and agents
In the four months since VoidZero joined Cloudflare, we’ve shipped more than 80 releases, closed over 1,200 issues, and landed some big performance improvements.
2131
Cloudflare @cloudflare.social · 28/09/2026
Introducing Forge, a pluggable, open-source pipeline that runs in CI to generate SDKs, CLIs, and documentation directly from API definitions. By shifting generation upstream into individual team repositories, Forge keeps developer tools continuously in sync.https://cfl.re/4rA4Oxi #BirthdayWeek
blog.cloudflare.com
Introducing Forge: the open source pipeline for generating SDKs, CLIs, docs, and more
Forge is early in its life, but already generates the output required for the cf CLI, and over the next few months will power Cloudflare’s API documentation, SDKs, and much more.
0154
Cloudflare @cloudflare.social · 27/09/2026
The Internet is changing more today than at any point since Cloudflare launched back on September 27, 2010. As automated traffic surpasses human activity, we reflect on the rise of AI agents, new creators, and how we can help build a fair, sustainable future for the web. cfl.re/4yZ3Wou
blog.cloudflare.com
Cloudflare’s 2026 Annual Founders’ Letter
The Internet is changing more today than at any point since Cloudflare launched back on September 27, 2010. As automated traffic surpasses human activity, we reflect on the rise of AI agents, new crea...
1112
Cloudflare @cloudflare.social · 25/09/2026
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification. cfl.re/4yWDSKQ
blog.cloudflare.com
Agents can now set up your website’s security with Turnstile Spin
Turnstile Spin turns a two-part setup into a guided workflow with your coding agent.
090
Cloudflare @cloudflare.social · 24/09/2026
External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. We explain how the issue worked, how we investigated it, and the steps we took to remediate it. cfl.re/4iQLc65
blog.cloudflare.com
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
This post was prepared in collaboration with Oren Yomtov and the Accomplish security research team, whose detailed report and controlled testing helped us validate the issue and respond quickly.
0103
Cloudflare @cloudflare.social · 23/09/2026
Humbled to share that Cloudflare is on FortuneMagazine’s 2026 Change the World list for the 3rd year! Thank you for recognizing our work to democratize cybersecurity and make tools available to everyone on the web. cfl.re/4ySrWcU
fortune.com
Change the World | Fortune
These companies use the creative forces of capitalism to solve big problems—and do well by doing good.
080
Cloudflare @cloudflare.social · 23/09/2026
#CloudflareConnect 2026 is bringing together the engineers, architects, and leaders shaping the future of the web. Get hands-on training, and swap insights with the minds powering over 20% of the Internet. Only 4 weeks left until event day! Register now: cloudflare.com/connect
030
Cloudflare @cloudflare.social · 22/09/2026
We're excited to announce Accenture as a Diamond sponsor for #CloudflareConnect! 💎 A huge thank you for your continued partnership and support as we help build a better Internet. Join us and let's experience the event together! Register today: cfl.re/connect2026
071
Cloudflare @cloudflare.social · 22/09/2026
Vary support is now available in Cache Rules on every plan. You can normalize known negotiation headers, pass exact values through to the origin when those small differences matter, or bypass cache when the variation is too unpredictable. cfl.re/46yzTrN
blog.cloudflare.com
We just shipped support for the ugliest part of HTTP: Vary
Vary support is now available in Cache Rules on every plan. You can normalize known negotiation headers, pass exact values through to the origin when those small differences matter, or bypass cache wh...
2151
Cloudflare @cloudflare.social · 22/09/2026
Today we’re launching Worker Previews. Each Git branch gets a production-like place to run, with its own code, configuration, URL, observability, and state. cfl.re/4xGomBz
blog.cloudflare.com
Introducing Worker Previews: isolated preview environments for every change your agent makes
Worker Previews gives every branch its own URL, configuration, state, and observability, so you and your agents can test changes in parallel without affecting production.
1142
Cloudflare @cloudflare.social · 21/09/2026
Connect and protect your workforce, AI agents, and infrastructure. cfl.re/45tzEgU
070
Cloudflare @cloudflare.social · 21/09/2026
We're excited to announce that today Python Workers are generally available (GA). It means Python is now a first-class, fully supported language on the Cloudflare Developer Platform. Read everything about it: cfl.re/4hjJesq
blog.cloudflare.com
Python Workers are now generally available
Python Workers allow developers to run Python web frameworks and AI orchestration libraries natively in the Cloudflare Workers runtime. You can seamlessly integrate with Cloudflare's ecosystem including D1, R2, and Workers AI without writing any JavaScript glue code.
6275
Cloudflare @cloudflare.social · 18/09/2026
100 TB of RAM saved by shrinking a consistent hash ring. The last 90,000 hashes per server bought 0.7% load improvement. Math said stop. We stopped. Open source in pingora-ketama. cfl.re/4rgQjyo
blog.cloudflare.com
Saving another 100TB of RAM with math (and Rust)
Cloudflare's global network is immense but not limitless. As we look for small ways to trim our resource usage, we sometimes get lucky and we can cut significantly more. Here’s how we reduced one of o...
2135
Cloudflare @cloudflare.social · 16/09/2026
7 of 8 malicious payloads found on live storefronts had zero VirusTotal detections. URLScan flagged none. Page Shield ML caught all 8. It reads JavaScript as a syntax tree, not flat text. Breakdown of 4 operations: affiliate hijacking, invisible iframes, and more: cfl.re/4xp7bo5
blog.cloudflare.com
When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
A modern storefront can look healthy while malicious JavaScript quietly siphons revenue, hijacks clicks, or rewrites analytics. See how Cloudflare's machine learning models surface evasive client-side...
2111
Cloudflare @cloudflare.social · 16/09/2026
Scaling live video shouldn't come with an "integration tax." See how Layercake revolutionized sports streaming with Cloudflare, slashing operational costs by 85%, cutting setup time by 95% (down to 10 seconds), and seamlessly orchestrating 300+ live events at once. cfl.re/470VQ2E
cloudflare.com
Layercake & Cloudflare | Customer Story
Layercake uses Cloudflare to automate and scale live streaming for thousands of concurrent global sporting events within a unified, high-performance architecture.
171
Cloudflare @cloudflare.social · 15/09/2026
Today, Cloudflare is announcing a new Disallow AI Training setting that lets you easily stay indexed for search while refusing to let that same crawler train on your content. cfl.re/4j1Vmk7
blog.cloudflare.com
Have it both ways: stay discoverable in search while disallowing AI training
Cloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountable designation establish a shared model with Apple, Google, and Microsoft.
2136
Cloudflare @cloudflare.social · 15/09/2026
You can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents get only the access they need to debug, deploy, or monitor safely. cfl.re/4xNVOqO
blog.cloudflare.com
Give every teammate and agent the right level of access to your Workers
Now, you can give a teammate or agent access to a specific Worker, so that they can only make changes to that application and no other resources in your account.
2101
Cloudflare @cloudflare.social · 14/09/2026
At Cloudflare, we don’t believe in a one-size-fits-all approach to workplace design. Work isn’t static, and the environments we build shouldn't be either. Full episode here: Apple: podcasts.apple.com/us/podcast/s... Spotify: open.spotify.com/episode/1WcY...
0122
Cloudflare @cloudflare.social · 14/09/2026
Be among the first to govern connections between your workforce, MCP servers, and internal data. cfl.re/45tzEgU
160
Cloudflare @cloudflare.social · 11/09/2026
Cloudflare CASB policies introduce a native automation engine built directly on the Cloudflare developer platform to remediate SaaS risks automatically. Security teams can now design event-driven logic to revoke risky file shares and send webhooks without manual intervention. cfl.re/4gZ3eQZ
cfl.re
Introducing automatic remediation policies with Cloudflare CASB
Today, we’re making Cloudflare CASB more powerful than ever by introducing automatic remediation policies.
070
Cloudflare @cloudflare.social · 10/09/2026
The demo worked. Now 10k agents are in prod, holding state and burning your API budget. Build agentic architecture at scale using Workers, Durable Objects, and AI Gateway on a global GPU network. Bring your unsolved architecture problems to #CloudflareConnect: cfl.re/45aFML0
1110
Cloudflare @cloudflare.social · 10/09/2026
1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale. cfl.re/4yylLLa
blog.cloudflare.com
1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
With ML-DSA-44 validation enabled, 1.1.1.1 lets us test both challenges at Internet scale: carrying larger DNS responses and preventing fallback to conventional signatures.
0226
Cloudflare @cloudflare.social · 09/09/2026
Workers now enables Node.js compatibility by default, supports applications up to 64 mebibytes, and adds a URL-based module registry with import.meta, lazy compilation, shared code caches, and clearer errors. cfl.re/4crdgsI
blog.cloudflare.com
How we rebuilt Cloudflare Workers’ module registry for Node.js compatibility
You can start using it today by enabling the new_module_registry compatibility flag in your Worker.
1243