---
title: Changelogs
image: https://edgetunnel-b2h.pages.dev/cf-twitter-card.png
---

> Documentation Index  
> Fetch the complete documentation index at: https://edgetunnel-b2h.pages.dev/changelog/llms.txt  
> Use this file to discover all available pages before exploring further. 

[Skip to content](#%5Ftop) 

# Changelog

New updates and improvements at Cloudflare.

[ Subscribe to RSS ](https://edgetunnel-b2h.pages.dev/changelog/rss/index.xml) [ View RSS feeds ](https://edgetunnel-b2h.pages.dev/fundamentals/new-features/available-rss-feeds/) 

All products

![hero image](https://edgetunnel-b2h.pages.dev/_astro/hero.CVYJHPAd_26AMqX.svg) 

Mar 20, 2026
1. ### [Stream logs from multiple replicas of Cloudflare Tunnel simultaneously](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-20-tunnel-replica-overview-and-multi-log-streaming/)  
[ Cloudflare Tunnel ](https://edgetunnel-b2h.pages.dev/tunnel/)[ Cloudflare Tunnel for SASE ](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-tunnel/)  
In the Cloudflare One dashboard, the overview page for a specific Cloudflare Tunnel now shows all [replicas](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-availability/) of that tunnel and supports streaming logs from multiple replicas at once.  
![View replicas and stream logs from multiple connectors](https://edgetunnel-b2h.pages.dev/_astro/tunnel-multiconn.DEOEaLlu_ZDxArh.webp)  
Previously, you could only stream logs from one replica at a time. With this update:

  * **Replicas on the tunnel overview** — All active replicas for the selected tunnel now appear on that tunnel's overview page under **Connectors**. Select any replica to stream its logs.
  * **Multi-connector log streaming** — Stream logs from multiple replicas simultaneously, making it easier to correlate events across your infrastructure during debugging or incident response. To try it out, log in to [Cloudflare One ↗](https://one.dash.cloudflare.com/) and go to **Networks** \> **Connectors** \> **Cloudflare Tunnels**. Select **View logs** next to the tunnel you want to monitor.  
For more information, refer to [Tunnel log streams](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-tunnel/monitor-tunnels/logs/) and [Deploy replicas](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-availability/deploy-replicas/).

Mar 20, 2026
1. ### [Observability for Workers VPC Services](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-20-metrics-and-settings-dashboard/)  
[ Workers VPC ](https://edgetunnel-b2h.pages.dev/workers-vpc/)  
Each VPC Service now has a **Metrics** tab so you can monitor connection health and debug failures without leaving the dashboard.  
![Workers VPC Metrics dashboard showing connections, latency, and errors charts](https://edgetunnel-b2h.pages.dev/_astro/2026-03-20-metrics-dashboard.6kfnbqQd_1Oc7Ft.webp)  
  * **Connections** — See successful and failed connections over time, broken down by what is responsible: your origin (Bad Upstream), your configuration (Client), or Cloudflare (Internal).
  * **Latency** — Track connection and DNS resolution latency trends.
  * **Errors** — Drill into specific error codes grouped by category, with filters to isolate upstream, client, or internal failures.  
You can also view and edit your VPC Service configuration, host details, and port assignments from the **Settings** tab.  
For a full list of error codes and what they mean, refer to [Troubleshooting](https://edgetunnel-b2h.pages.dev/workers-vpc/reference/troubleshooting/).

Mar 19, 2026
1. ### [Service Key authentication deprecated](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-19-service-key-authentication-deprecated/)  
[ Cloudflare Fundamentals ](https://edgetunnel-b2h.pages.dev/fundamentals/)  
Service Key authentication for the Cloudflare API is deprecated. Service Keys will stop working on September 30, 2026.  
[API Tokens](https://edgetunnel-b2h.pages.dev/fundamentals/api/get-started/create-token/) replace Service Keys with fine-grained permissions, expiration, and revocation.  
#### What you need to do  
Replace any use of the `X-Auth-User-Service-Key` header with an [API Token](https://edgetunnel-b2h.pages.dev/fundamentals/api/get-started/create-token/) scoped to the permissions your integration requires.  
If you use `cloudflared`, update to a version from November 2022 or later. These versions already use API Tokens.  
If you use [origin-ca-issuer ↗](https://github.com/cloudflare/origin-ca-issuer), update to a version that supports API Token authentication.  
For more information, refer to [API deprecations](https://edgetunnel-b2h.pages.dev/fundamentals/api/reference/deprecations/).

Mar 19, 2026
1. ### [Hyperdrive now supports custom TLS/SSL certificates for MySQL](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-19-hyperdrive-mysql-custom-certificate-support/)  
[ Hyperdrive ](https://edgetunnel-b2h.pages.dev/hyperdrive/)  
Hyperdrive now supports custom TLS/SSL certificates for MySQL databases, bringing the same certificate options previously available for PostgreSQL to MySQL connections.  
You can now configure:

  * **Server certificate verification** with `VERIFY_CA` or `VERIFY_IDENTITY` SSL modes to verify that your MySQL database server's certificate is signed by the expected certificate authority (CA).
  * **Client certificates** (mTLS) for Hyperdrive to authenticate itself to your MySQL database with credentials beyond username and password.  
Create a Hyperdrive configuration with custom certificates for MySQL:  
```bash  
# Upload a CA certificate  
npx wrangler cert upload certificate-authority --ca-cert your-ca-cert.pem --name your-custom-ca-name  
# Create a Hyperdrive with VERIFY_IDENTITY mode  
npx wrangler hyperdrive create your-hyperdrive-config \
  --connection-string="mysql://user:password@hostname:port/database" \
  --ca-certificate-id <CA_CERT_ID> \
  --sslmode VERIFY_IDENTITY  
```  
For more information, refer to [SSL/TLS certificates for Hyperdrive](https://edgetunnel-b2h.pages.dev/hyperdrive/configuration/tls-ssl-certificates-for-hyperdrive/) and [MySQL TLS/SSL modes](https://edgetunnel-b2h.pages.dev/hyperdrive/examples/connect-to-mysql/).

Mar 19, 2026
1. ### [Manage Cloudflare Tunnels with Wrangler](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-19-wrangler-tunnel-commands/)  
[ Cloudflare Tunnel ](https://edgetunnel-b2h.pages.dev/tunnel/)[ Workers ](https://edgetunnel-b2h.pages.dev/workers/)  
You can now manage [Cloudflare Tunnels](https://edgetunnel-b2h.pages.dev/tunnel/) directly from [Wrangler](https://edgetunnel-b2h.pages.dev/workers/wrangler/), the CLI for the Cloudflare Developer Platform. The new [wrangler tunnel](https://edgetunnel-b2h.pages.dev/workers/wrangler/commands/tunnel/) commands let you create, run, and manage tunnels without leaving your terminal.  
![Wrangler tunnel commands demo](https://edgetunnel-b2h.pages.dev/_astro/wrangler-tunnel.DOqrtGGg_7EDX0.webp)  
Available commands:

  * `wrangler tunnel create` — Create a new remotely managed tunnel.
  * `wrangler tunnel list` — List all tunnels in your account.
  * `wrangler tunnel info` — Display details about a specific tunnel.
  * `wrangler tunnel delete` — Delete a tunnel.
  * `wrangler tunnel run` — Run a tunnel using the cloudflared daemon.
  * `wrangler tunnel quick-start` — Start a free, temporary tunnel without an account using [Quick Tunnels](https://edgetunnel-b2h.pages.dev/tunnel/setup/#quick-tunnels-development).  
Wrangler handles downloading and managing the [cloudflared](https://edgetunnel-b2h.pages.dev/tunnel/downloads/) binary automatically. On first use, you will be prompted to download `cloudflared` to a local cache directory.  
These commands are currently experimental and may change without notice.  
To get started, refer to the [Wrangler tunnel commands documentation](https://edgetunnel-b2h.pages.dev/workers/wrangler/commands/tunnel/).

Mar 19, 2026
1. ### [Moonshot AI Kimi K2.5 now available on Workers AI](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-19-kimi-k2-5-workers-ai/)  
[ Workers AI ](https://edgetunnel-b2h.pages.dev/workers-ai/)  
Workers AI is officially in the big models game. [@cf/moonshotai/kimi-k2.5](https://edgetunnel-b2h.pages.dev/workers-ai/models/kimi-k2.5/) is the first frontier-scale open-source model on our AI inference platform — a large model with a full 256k context window, multi-turn tool calling, vision inputs, and structured outputs. By bringing a frontier-scale model directly onto the Cloudflare Developer Platform, you can now run the entire agent lifecycle on a single, unified platform.  
The model has proven to be a fast, efficient alternative to larger proprietary models without sacrificing quality. As AI adoption increases, the volume of inference is skyrocketing — now you can access frontier intelligence at a fraction of the cost.  
#### Key capabilities

  * **256,000 token context window** for retaining full conversation history, tool definitions, and entire codebases across long-running agent sessions
  * **Multi-turn tool calling** for building agents that invoke tools across multiple conversation turns
  * **Vision inputs** for processing images alongside text
  * **Structured outputs** with JSON mode and JSON Schema support for reliable downstream parsing
  * **Function calling** for integrating external tools and APIs into agent workflows  
#### Prefix caching and session affinity  
When an agent sends a new prompt, it resends all previous prompts, tools, and context from the session. The delta between consecutive requests is usually just a few new lines of input. Prefix caching avoids reprocessing the shared context, saving time and compute from the prefill stage. This means faster Time to First Token (TTFT) and higher Tokens Per Second (TPS) throughput.  
Workers AI has done prefix caching, but we are now surfacing cached tokens as a usage metric and offering a discount on cached tokens compared to input tokens (pricing is listed on the [model page](https://edgetunnel-b2h.pages.dev/workers-ai/models/kimi-k2.5/)).  
```bash  
curl -X POST \  
  "https://api.cloudflare.com/client/v4/accounts/{account_id}/ai/run/@cf/moonshotai/kimi-k2.5" \
  -H "Authorization: Bearer {api_token}" \
  -H "Content-Type: application/json" \
  -H "x-session-affinity: ses_12345678" \
  -d '{  
    "messages": [  
      {  
        "role": "system",  
        "content": "You are a helpful assistant."  
      },  
      {  
        "role": "user",  
        "content": "What is prefix caching and why does it matter?"  
      }  
    ],  
    "max_tokens": 2400,  
    "stream": true  
  }'  
```  
Some clients like [OpenCode ↗](https://opencode.ai) implement session affinity automatically. The [Agents SDK ↗](https://github.com/cloudflare/agents) starter also sets up the wiring for you.  
#### Redesigned asynchronous API  
For volumes of requests that exceed synchronous rate limits, you can submit batches of inferences to be completed asynchronously. We have revamped the [Asynchronous Batch API](https://edgetunnel-b2h.pages.dev/workers-ai/features/batch-api/) with a pull-based system that processes queued requests as soon as capacity is available. With internal testing, async requests usually execute within 5 minutes, but this depends on live traffic.  
The async API is the best way to avoid capacity errors in durable workflows. It is ideal for use cases that are not real-time, such as code scanning agents or research agents.  
To use the asynchronous API, pass `queueRequest: true`:

**JavaScript**  
```js  
// 1. Push a batch of requests into the queue  
const res = await env.AI.run(  
  "@cf/moonshotai/kimi-k2.5",  
  {  
    requests: [  
      {  
        messages: [{ role: "user", content: "Tell me a joke" }],  
      },  
      {  
        messages: [{ role: "user", content: "Explain the Pythagoras theorem" }],  
      },  
    ],  
  },  
  { queueRequest: true },  
);  
// 2. Grab the request ID  
const requestId = res.request_id;  
// 3. Poll for the result  
const result = await env.AI.run("@cf/moonshotai/kimi-k2.5", {  
  request_id: requestId,  
});  
if (result.status === "queued" || result.status === "running") {  
  // Retry by polling again  
} else {  
  return Response.json(result);  
}  
```  
You can also set up [event notifications](https://edgetunnel-b2h.pages.dev/workers-ai/platform/event-subscriptions/) to know when inference is complete instead of polling.  
#### Get started  
Use Kimi K2.5 through the [Workers AI binding](https://edgetunnel-b2h.pages.dev/workers-ai/configuration/bindings/) (`env.AI.run()`), the REST API at `/run` or `/v1/chat/completions`, [AI Gateway](https://edgetunnel-b2h.pages.dev/ai-gateway/), or via the [OpenAI-compatible endpoint](https://edgetunnel-b2h.pages.dev/workers-ai/configuration/open-ai-compatibility/).  
For more information, refer to the [Kimi K2.5 model page](https://edgetunnel-b2h.pages.dev/workers-ai/models/kimi-k2.5/), [pricing](https://edgetunnel-b2h.pages.dev/workers-ai/platform/pricing/), and [prompt caching](https://edgetunnel-b2h.pages.dev/workers-ai/features/prompt-caching/).

Mar 18, 2026
1. ### [SCIM provisioning for Authentik is now Generally Available](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-17-scim-authentik-support/)  
[ Cloudflare Fundamentals ](https://edgetunnel-b2h.pages.dev/fundamentals/)  
Cloudflare dashboard SCIM provisioning now supports [Authentik ↗](https://goauthentik.io/) as an identity provider, joining Okta and Microsoft Entra ID as explicitly supported providers.  
Customers can now sync users and group information from Authentik to Cloudflare, apply Permission Policies to those groups, and manage the lifecycle of users & groups directly from your Authentik Identity Provider.  
Note  
SCIM provisioning for the Cloudflare dashboard is available to Enterprise customers. You must be a Super Administrator to complete the initial setup.  
For more information:

  * [SCIM provisioning overview](https://edgetunnel-b2h.pages.dev/fundamentals/account/account-security/scim-setup/)
  * [Provision with Authentik](https://edgetunnel-b2h.pages.dev/fundamentals/account/account-security/scim-setup/authentik/)

Mar 18, 2026
1. ### [SCIM audit logging Support](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-18-scim-audit-logging/)  
[ Cloudflare Fundamentals ](https://edgetunnel-b2h.pages.dev/fundamentals/)  
Cloudflare dashboard SCIM provisioning operations are now captured in [Audit Logs v2](https://edgetunnel-b2h.pages.dev/fundamentals/account/account-security/audit-logs/), giving you visibility into user and group changes made by your identity provider.  
![SCIM audit logging](https://edgetunnel-b2h.pages.dev/_astro/2026-03-18-scim-audit-logging.DPKMiE8X_ZojL4c.webp)  

**Logged actions:**

| Action Type       | Description                             |
| ----------------- | --------------------------------------- |
| Create SCIM User  | User provisioned from IdP               |
| Replace SCIM User | User fully replaced (PUT)               |
| Update SCIM User  | User attributes modified (PATCH)        |
| Delete SCIM User  | Member deprovisioned                    |
| Create SCIM Group | Group provisioned from IdP              |
| Update SCIM Group | Group membership or attributes modified |
| Delete SCIM Group | Group deprovisioned                     |  
For more details, refer to the [Audit Logs v2 documentation](https://edgetunnel-b2h.pages.dev/fundamentals/account/account-security/audit-logs/).

Mar 18, 2026
1. ### [Worker execution timing field now available in Rules](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-18-worker-timing-field/)  
[ Rules ](https://edgetunnel-b2h.pages.dev/rules/)  
The `cf.timings.worker_msec` field is now available in the Ruleset Engine. This field reports the wall-clock time that a Cloudflare Worker spent handling a request, measured in milliseconds.  
You can use this field to identify slow Worker executions, detect performance regressions, or build rules that respond differently based on Worker processing time, such as logging requests that exceed a latency threshold.  
#### Field details

| Field                   | Type    | Description                                                                                       |
| ----------------------- | ------- | ------------------------------------------------------------------------------------------------- |
| cf.timings.worker\_msec | Integer | The time spent executing a Cloudflare Worker in milliseconds. Returns 0 if no Worker was invoked. |  
Example filter expression:  
```plaintext  
cf.timings.worker_msec > 500  
```  
For more information, refer to the [Fields reference](https://edgetunnel-b2h.pages.dev/ruleset-engine/rules-language/fields/reference/cf.timings.worker%5Fmsec/).

Mar 18, 2026
1. ### [Real-time logo match preview](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-18-brand-protection-logo-match-preview/)  
[ Security Center ](https://edgetunnel-b2h.pages.dev/security-center/)  
We are introducing **Logo Match Preview**, bringing the same pre-save visibility to visual assets that was previously only available for string-based queries. This update allows you to fine-tune your brand detection strategy before committing to a live monitor.  
#### What’s new:

  * Upload your brand logo and immediately see a sample of potential matches from recently detected sites before finalizing the query
  * Adjust your similarity score (from 75% to 100%) and watch the results refresh in real-time to find the balance between broad detection and noise reduction
  * Review the specific logos triggered by your current settings to ensure your query is capturing the right level of brand infringement  
If you are ready to test your brand assets, go to the [Brand Protection dashboard ↗](https://edgetunnel-b2h.pages.dev/security-center/brand-protection/) to try the new preview tool.

Mar 18, 2026
1. ### [Media Transformations binding for Workers](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-18-media-transformations-workers-binding/)  
[ Stream ](https://edgetunnel-b2h.pages.dev/stream/)  
You can now use a Workers binding to transform videos with Media Transformations. This allows you to resize, crop, extract frames, and extract audio from videos stored anywhere, even in private locations like R2 buckets.  
The Media Transformations binding is useful when you want to:

  * Transform videos stored in private or protected sources
  * Optimize videos and store the output directly back to R2 for re-use
  * Extract still frames for classification or description with Workers AI
  * Extract audio tracks for transcription using Workers AI  
To get started, add the Media binding to your Wrangler configuration:

  * [  wrangler.jsonc ](#tab-panel-5049)
  * [  wrangler.toml ](#tab-panel-5050)

**JSONC**  
```jsonc  
{  
  "$schema": "./node_modules/wrangler/config-schema.json",  
  "media": {  
    "binding": "MEDIA"  
  }  
}  
```

**TOML**  
```toml  
[media]  
binding = "MEDIA"  
```  
Then use the binding in your Worker to transform videos:

  * [  JavaScript ](#tab-panel-5057)
  * [  TypeScript ](#tab-panel-5058)

**JavaScript**  
```js  
export default {  
  async fetch(request, env) {  
    const video = await env.R2_BUCKET.get("input.mp4");  
    const result = env.MEDIA.input(video.body)  
      .transform({ width: 480, height: 270 })  
      .output({ mode: "video", duration: "5s" });  
    return await result.response();  
  },  
};  
```

**TypeScript**  
```ts  
export default {  
  async fetch(request, env) {  
    const video = await env.R2_BUCKET.get("input.mp4");  
    const result = env.MEDIA.input(video.body)  
      .transform({ width: 480, height: 270 })  
      .output({ mode: "video", duration: "5s" });  
    return await result.response();  
  },  
};  
```  
Output modes include `video` for optimized MP4 clips, `frame` for still images, `spritesheet` for multiple frames, and `audio` for M4A extraction.  
For more information, refer to the [Media Transformations binding documentation](https://edgetunnel-b2h.pages.dev/stream/transform-videos/bindings/).

Mar 17, 2026
1. ### [@cloudflare/codemode v0.2.1: MCP barrel export, zero-dependency main entry point, and custom sandbox modules](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-17-codemode-sdk-v021/)  
[ Agents ](https://edgetunnel-b2h.pages.dev/agents/)[ Workers ](https://edgetunnel-b2h.pages.dev/workers/)  
The latest releases of [@cloudflare/codemode ↗](https://www.npmjs.com/package/@cloudflare/codemode) add a new MCP barrel export, remove `ai` and `zod` as required peer dependencies from the main entry point, and give you more control over the sandbox.  
#### New `@cloudflare/codemode/mcp` export  
A new `@cloudflare/codemode/mcp` entry point provides two functions that wrap MCP servers with Code Mode:

  * **`codeMcpServer({ server, executor })`** — wraps an existing MCP server with a single `code` tool where each upstream tool becomes a typed `codemode.*` method.
  * **`openApiMcpServer({ spec, executor, request })`** — creates `search` and `execute` MCP tools from an OpenAPI spec with host-side request proxying and automatic `$ref` resolution.

  * [  JavaScript ](#tab-panel-5055)
  * [  TypeScript ](#tab-panel-5056)

**JavaScript**  
```js  
import { codeMcpServer } from "@cloudflare/codemode/mcp";  
import { DynamicWorkerExecutor } from "@cloudflare/codemode";  
const executor = new DynamicWorkerExecutor({ loader: env.LOADER });  
// Wrap an existing MCP server — all its tools become  
// typed methods the LLM can call from generated code  
const server = await codeMcpServer({ server: upstreamMcp, executor });  
```

**TypeScript**  
```ts  
import { codeMcpServer } from "@cloudflare/codemode/mcp";  
import { DynamicWorkerExecutor } from "@cloudflare/codemode";  
const executor = new DynamicWorkerExecutor({ loader: env.LOADER });  
// Wrap an existing MCP server — all its tools become  
// typed methods the LLM can call from generated code  
const server = await codeMcpServer({ server: upstreamMcp, executor });  
```  
#### Zero-dependency main entry point

**Breaking change in v0.2.0:** `generateTypes` and the `ToolDescriptor` / `ToolDescriptors` types have moved to `@cloudflare/codemode/ai`:

  * [  JavaScript ](#tab-panel-5053)
  * [  TypeScript ](#tab-panel-5054)

**JavaScript**  
```js  
// Before  
import { generateTypes } from "@cloudflare/codemode";  
// After  
import { generateTypes } from "@cloudflare/codemode/ai";  
```

**TypeScript**  
```ts  
// Before  
import { generateTypes } from "@cloudflare/codemode";  
// After  
import { generateTypes } from "@cloudflare/codemode/ai";  
```  
The main entry point (`@cloudflare/codemode`) no longer requires the `ai` or `zod` peer dependencies. It now exports:

| Export                      | Description                                                 |
| --------------------------- | ----------------------------------------------------------- |
| sanitizeToolName            | Sanitize tool names into valid JS identifiers               |
| normalizeCode               | Normalize LLM-generated code into async arrow functions     |
| generateTypesFromJsonSchema | Generate TypeScript type definitions from plain JSON Schema |
| jsonSchemaToType            | Convert a single JSON Schema to a TypeScript type string    |
| DynamicWorkerExecutor       | Sandboxed code execution via Dynamic Worker Loader          |
| ToolDispatcher              | RPC target for dispatching tool calls from sandbox to host  |  
The `ai` and `zod` peer dependencies are now optional — only required when importing from `@cloudflare/codemode/ai`.  
#### Custom sandbox modules  
`DynamicWorkerExecutor` now accepts an optional `modules` option to inject custom ES modules into the sandbox:

  * [  JavaScript ](#tab-panel-5059)
  * [  TypeScript ](#tab-panel-5060)

**JavaScript**  
```js  
const executor = new DynamicWorkerExecutor({  
  loader: env.LOADER,  
  modules: {  
    "utils.js": `export function add(a, b) { return a + b; }`,  
  },  
});  
// Sandbox code can then: import { add } from "utils.js"  
```

**TypeScript**  
```ts  
const executor = new DynamicWorkerExecutor({  
  loader: env.LOADER,  
  modules: {  
    "utils.js": `export function add(a, b) { return a + b; }`,  
  },  
});  
// Sandbox code can then: import { add } from "utils.js"  
```  
#### Internal normalization and sanitization  
`DynamicWorkerExecutor` now normalizes code and sanitizes tool names internally. You no longer need to call `normalizeCode()` or `sanitizeToolName()` before passing code and functions to `execute()`.  
#### Upgrade  
```sh  
npm i @cloudflare/codemode@latest  
```  
See the [Code Mode documentation](https://edgetunnel-b2h.pages.dev/agents/tools/codemode/) for the full API reference.

Mar 17, 2026
1. ### [Log AI Gateway request metadata without storing payloads](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-17-collect-log-payload-header/)  
[ AI Gateway ](https://edgetunnel-b2h.pages.dev/ai-gateway/)  
AI Gateway now supports the `cf-aig-collect-log-payload` header, which controls whether request and response bodies are stored in logs. By default, this header is set to `true` and payloads are stored alongside metadata. Set this header to `false` to skip payload storage while still logging metadata such as token counts, model, provider, status code, cost, and duration.  
This is useful when you need usage metrics but do not want to persist sensitive prompt or response data.  
```bash  
curl https://gateway.ai.cloudflare.com/v1/$ACCOUNT_ID/$GATEWAY_ID/openai/chat/completions \
  --header "Authorization: Bearer $TOKEN" \
  --header 'Content-Type: application/json' \
  --header 'cf-aig-collect-log-payload: false' \
  --data '{  
    "model": "gpt-4o-mini",  
    "messages": [  
      {  
        "role": "user",  
        "content": "What is the email address and phone number of user123?"  
      }  
    ]  
  }'  
```  
For more information, refer to [Logging](https://edgetunnel-b2h.pages.dev/ai-gateway/observability/logging/#collect-log-payload-cf-aig-collect-log-payload).

Mar 17, 2026
1. ### [New Security Overview UI](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-17-new-security-overview-ui/)  
[ Security Overview ](https://edgetunnel-b2h.pages.dev/security/overview/)  
The Security Overview has been updated to provide Application Security customers with more actionable insights and a clearer view of their security posture.  
Key improvements include:

  * **Criticality for all Insights**: Every insight now includes a criticality rating, allowing you to prioritize the most impactful security action items first.
  * **Detection Tools Section**: A new section displays the security detection tools available to you, indicating which are currently enabled and which can be activated to strengthen your defenses.
  * **Industry Peer Comparison** (Enterprise customers): A new module from Security Reports benchmarks your security posture against industry peers, highlighting relative strengths and areas for improvement.  
![New Security Overview UI](https://edgetunnel-b2h.pages.dev/_astro/overview-ui.D7FzaCLm_Ze702A.webp)  
For more information, refer to [Security Overview](https://edgetunnel-b2h.pages.dev/security/overview/).

Mar 16, 2026
1. ### [Return up to 50 query results with values or metadata](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-16-topk-limit-increased-to-50/)  
[ Vectorize ](https://edgetunnel-b2h.pages.dev/vectorize/)  
You can now set `topK` up to `50` when a Vectorize query returns values or full metadata. This raises the previous limit of `20` for queries that use `returnValues: true` or `returnMetadata: "all"`.  
Use the higher limit when you need more matches in a single query response without dropping values or metadata. Refer to the [Vectorize API reference](https://edgetunnel-b2h.pages.dev/vectorize/reference/client-api/) for query options and current `topK` limits.

Mar 15, 2026
1. ### [Unlimited result paging in Investigations](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-15-infinite-paging-investigations/)  
[ Email security ](https://edgetunnel-b2h.pages.dev/cloudflare-one/email-security/)  
Investigations now support unlimited result paging in both the dashboard and the API, removing the previous 1,000-record cap. Security teams can page through complete result sets when searching across large mail volumes, giving SOC analysts and automated workflows deeper visibility for forensics and threat hunting.  
In the dashboard, infinite paging is now supported in the Investigations view. The 1,000-record ceiling has been removed, so you can navigate through the full result set directly in the UI. The [Investigations API](https://edgetunnel-b2h.pages.dev/api/resources/email%5Fsecurity/subresources/investigate/methods/list) now returns up to 10,000 records per page (up from 1,000), with no cap on total result volume across pages.  
For high-volume use cases, we recommend:

  * **[Logpush](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/logs/logpush/email-security-logs/) to a SIEM** for full-fidelity datasets and long-term retention.
  * **SOAR playbooks** against the async bulk action API for large-scale remediation. Bulk actions initiated from the dashboard remain capped at 1,000 messages per action.
  * **The Investigations API** for report exports larger than 1,000 results, which is the dashboard download cap.  
This applies to all Email Security packages:

  * **Advantage**
  * **Enterprise**
  * **Enterprise + PhishGuard**

Mar 15, 2026
1. ### [Access Durable Object name via \`ctx.id.name\`](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-15-durable-object-id-name/)  
[ Durable Objects ](https://edgetunnel-b2h.pages.dev/durable-objects/)[ Workers ](https://edgetunnel-b2h.pages.dev/workers/)  
When your Worker accesses a Durable Object via `idFromName()` or `getByName()`, the same name is now available on `ctx.id.name` inside the object — no need to pass it through method arguments or persist it in storage. This brings the runtime behavior in line with the [Workers runtime types](https://edgetunnel-b2h.pages.dev/workers/languages/typescript/).  
This is especially useful for [alarms](https://edgetunnel-b2h.pages.dev/durable-objects/api/alarms/), where there is no calling client to pass the name as an argument. When an alarm handler runs, `ctx.id.name` will hold the same name the object was originally accessed with.

**JavaScript**  
```js  
import { DurableObject } from "cloudflare:workers";  
export class ChatRoom extends DurableObject {  
  async getRoomName() {  
    // ctx.id.name returns the name passed to getByName() or idFromName()  
    return this.ctx.id.name;  
  }  
}  
// Worker  
export default {  
  async fetch(request, env) {  
    const stub = env.CHAT_ROOM.getByName("general");  
    const roomName = await stub.getRoomName();  
    return new Response(`Welcome to ${roomName}!`);  
  },  
};  
```  
`ctx.id.name` is `undefined` in the following cases:

  * For Durable Objects created with `newUniqueId()`.
  * When accessed via `idFromString()`, even if the ID was originally created from a name.
  * For [names longer than 1,024 bytes](https://edgetunnel-b2h.pages.dev/durable-objects/api/id/#name).  
This works the same way in local development with `wrangler dev` as it does in production. Run `npm update wrangler` to ensure you are on a version with this support.  
For more information, refer to the [Durable Object ID documentation](https://edgetunnel-b2h.pages.dev/durable-objects/api/id/#name).

Mar 12, 2026
1. ### [SSH into running Container instances](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-12-ssh-support/)  
[ Containers ](https://edgetunnel-b2h.pages.dev/containers/)  
You can now SSH into running Container instances using Wrangler. This is useful for debugging, inspecting running processes, or executing one-off commands inside a Container.  
To connect, enable `wrangler_ssh` in your Container configuration and add your `ssh-ed25519` public key to `authorized_keys`:

  * [  wrangler.jsonc ](#tab-panel-5051)
  * [  wrangler.toml ](#tab-panel-5052)

**JSONC**  
```jsonc  
{  
  "containers": [  
    {  
      "wrangler_ssh": {  
        "enabled": true  
      },  
      "authorized_keys": [  
        {  
          "name": "<NAME>",  
          "public_key": "<YOUR_PUBLIC_KEY_HERE>"  
        }  
      ]  
    }  
  ]  
}  
```

**TOML**  
```toml  
[[containers]]  
[containers.wrangler_ssh]  
enabled = true  
[[containers.authorized_keys]]  
name = "<NAME>"  
public_key = "<YOUR_PUBLIC_KEY_HERE>"  
```  
Then connect with:  
```sh  
wrangler containers ssh <INSTANCE_ID>  
```  
You can also run a single command without opening an interactive shell:  
```sh  
wrangler containers ssh <INSTANCE_ID> -- ls -al  
```  
Use `wrangler containers instances <APPLICATION>` to find the instance ID for a running Container.  
For more information, refer to the [SSH documentation](https://edgetunnel-b2h.pages.dev/containers/ssh/).

Mar 12, 2026
1. ### [List Container instances with \`wrangler containers instances\`](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-12-wrangler-containers-instances/)  
[ Containers ](https://edgetunnel-b2h.pages.dev/containers/)  
A new [wrangler containers instances](https://edgetunnel-b2h.pages.dev/workers/wrangler/commands/containers/#containers-instances) command lists all instances for a given Container application. This mirrors the instances view in the Cloudflare dashboard.  
The command displays each instance's ID, name, state, location, version, and creation time:  
```sh  
wrangler containers instances <APPLICATION_ID>  
```  
Use the `--json` flag for machine-readable output, which is also the default format in non-interactive environments such as CI pipelines.  
For the full list of options, refer to the [containers instances command reference](https://edgetunnel-b2h.pages.dev/workers/wrangler/commands/containers/#containers-instances).

Mar 12, 2026
1. ### [Retry-After HTTP header for retryable 1xxx errors](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-12-retry-after-header-for-1xxx-errors/)  
[ Cloudflare Fundamentals ](https://edgetunnel-b2h.pages.dev/fundamentals/)  
Cloudflare-generated 1xxx error responses now include a standard `Retry-After` HTTP header when the error is retryable. Agents and HTTP clients can read the recommended wait time from response headers alone — no body parsing required.  
#### Changes  
Seven retryable error codes now emit `Retry-After`:

| Error code | Retry-After (seconds) | Error name                  |
| ---------- | --------------------- | --------------------------- |
| 1004       | 120                   | DNS resolution error        |
| 1005       | 120                   | Banned zone                 |
| 1015       | 30                    | Rate limited                |
| 1033       | 120                   | Argo Tunnel error           |
| 1038       | 60                    | HTTP headers limit exceeded |
| 1200       | 60                    | Cache connection limit      |
| 1205       | 5                     | Too many redirects          |  
The header value matches the existing `retry_after` body field in JSON and Markdown responses.  
If a WAF rate limiting rule has already set a dynamic `Retry-After` value on the response, that value takes precedence.  
#### Availability  
Available for all zones on all plans.  
#### Verify  
Check for the header on any retryable error:  
```bash  
curl -s --compressed -D - -o /dev/null -H "Accept: application/json" -A "TestAgent/1.0" -H "Accept-Encoding: gzip, deflate" "<YOUR_DOMAIN>/cdn-cgi/error/1015" | grep -i retry-after  
```  
References:

  * [RFC 9110 section 10.2.3 - Retry-After ↗](https://www.rfc-editor.org/rfc/rfc9110#section-10.2.3)
  * [Cloudflare 1xxx error documentation](https://edgetunnel-b2h.pages.dev/support/troubleshooting/http-status-codes/cloudflare-1xxx-errors/)

Mar 12, 2026
1. ### [WAF Release - 2026-03-12 - Emergency](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-12-emergency-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  
This week's release introduces new detections for vulnerabilities in Ivanti Endpoint Manager Mobile (CVE-2026-1281 and CVE-2026-1340), alongside a new generic detection rule designed to identify and block Cross-Site Scripting (XSS) injection attempts within the `Content-Security-Policy` (CSP) HTTP request header.

**Key Findings**

  * CVE-2026-1281 & CVE-2026-1340: Ivanti Endpoint Manager Mobile processes HTTP requests through Apache RevwriteMap directives that pass user-controlled input to Bash scripts (`/mi/bin/map-appstore-url` and `/mi/bin/map-aft-store-url`). Bash scripts do not sanitize user input and are vulnerable to shell arithmetic expansion thereby allowing attackers to achieve unauthenticated remote code execution.
  * Generic XSS in CSP Header: This rule identifies malicious payloads embedded within the request's `Content-Security-Policy` header. It specifically targets scenarios where web frameworks or applications trust and extract values directly from the CSP header in the incoming request without sufficient validation. Attackers can provide crafted header values to inject scripts or malicious directives that are subsequently processed by the server.

**Impact**  
Successful exploitation of Ivanti EPMM vulnerability allows unauthenticated remote code execution and generic XSS in CSP header allows attackers to inject malicious scripts during page rendering. In environments using server-side caching, this poisoned XSS content can subsequently be cached and automatically served to all visitors.

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                                        | Previous Action | New Action | Comments                 |
| -------------------------- | ----------- | -------------- | ------------------------------------------------------------------ | --------------- | ---------- | ------------------------ |
| Cloudflare Managed Ruleset | ...796ea2f6 | N/A            | Ivanti EPMM - Code Injection - CVE:CVE-2026-1281 CVE:CVE-2026-1340 | Log             | Block      | This is a new detection. |
| Cloudflare Managed Ruleset | ...ee964a8c | N/A            | Anomaly:Header:Content-Security-Policy                             | N/A             | Block      | This is a new detection. |

Mar 11, 2026
1. ### [JSON responses and RFC 9457 support for Cloudflare 1xxx errors](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-11-json-rfc9457-responses-for-1xxx-errors/)  
[ Cloudflare Fundamentals ](https://edgetunnel-b2h.pages.dev/fundamentals/)  
Cloudflare-generated 1xxx errors now return structured JSON when clients send `Accept: application/json` or `Accept: application/problem+json`. JSON responses follow [RFC 9457 (Problem Details for HTTP APIs) ↗](https://www.rfc-editor.org/rfc/rfc9457), so any HTTP client that understands Problem Details can parse the base members without Cloudflare-specific code.  
#### Breaking change  
The Markdown frontmatter field `http_status` has been renamed to `status`. Agents consuming Markdown frontmatter should update parsers accordingly.  
#### Changes

**JSON format.** Clients sending `Accept: application/json` or `Accept: application/problem+json` now receive a structured JSON object with the same operational fields as Markdown frontmatter, plus RFC 9457 standard members.

**RFC 9457 standard members (JSON only):**

  * `type` — URI pointing to Cloudflare documentation for the specific error code
  * `status` — HTTP status code (matching the response status)
  * `title` — short, human-readable summary
  * `detail` — human-readable explanation specific to this occurrence
  * `instance` — Ray ID identifying this specific error occurrence

**Field renames:**

  * `http_status` \-> `status` (JSON and Markdown)
  * `what_happened` \-> `detail` (JSON only — Markdown prose sections are unchanged)

**Content-Type mirroring.** Clients sending `Accept: application/problem+json` receive `Content-Type: application/problem+json; charset=utf-8` back; `Accept: application/json` receives `application/json; charset=utf-8`. Same body in both cases.  
#### Negotiation behavior

| Request header sent                           | Response format                              |
| --------------------------------------------- | -------------------------------------------- |
| Accept: application/json                      | JSON (application/json content type)         |
| Accept: application/problem+json              | JSON (application/problem+json content type) |
| Accept: application/json, text/markdown;q=0.9 | JSON                                         |
| Accept: text/markdown                         | Markdown                                     |
| Accept: text/markdown, application/json       | Markdown (equal q, first-listed wins)        |
| Accept: \*/\*                                 | HTML (default)                               |  
#### Availability  
Available now for Cloudflare-generated 1xxx errors.  
#### Get started  
```bash  
curl -s --compressed -H "Accept: application/json" -A "TestAgent/1.0" -H "Accept-Encoding: gzip, deflate" "<YOUR_DOMAIN>/cdn-cgi/error/1015" | jq .  
```  
```bash  
curl -s --compressed -H "Accept: application/problem+json" -A "TestAgent/1.0" -H "Accept-Encoding: gzip, deflate" "<YOUR_DOMAIN>/cdn-cgi/error/1015" | jq .  
```  
References:

  * [RFC 9457 — Problem Details for HTTP APIs ↗](https://www.rfc-editor.org/rfc/rfc9457)
  * [Cloudflare 1xxx error documentation](https://edgetunnel-b2h.pages.dev/support/troubleshooting/http-status-codes/cloudflare-1xxx-errors/)

Mar 11, 2026
1. ### [Ingest field selection for Log Explorer](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-11-ingest-field-selection/)  
[ Log Explorer ](https://edgetunnel-b2h.pages.dev/log-explorer/)  
Cloudflare Log Explorer now allows you to customize exactly which data fields are ingested and stored when enabling or managing log datasets.  
Previously, ingesting logs often meant taking an "all or nothing" approach to data fields. With **Ingest Field Selection**, you can now choose from a list of available and recommended fields for each dataset. This allows you to reduce noise, focus on the metrics that matter most to your security and performance analysis, and manage your data footprint more effectively.  
#### Key capabilities

  * **Granular control:** Select only the specific fields you need when enabling a new dataset.
  * **Dynamic updates:** Update fields for existing, already enabled logstreams at any time.
  * **Historical consistency:** Even if you disable a field later, you can still query and receive results for that field for the period it was captured.
  * **Data integrity:** Core fields, such as `Timestamp`, are automatically retained to ensure your logs remain searchable and chronologically accurate.  
#### Example configuration  
When configuring a dataset via the dashboard or API, you can define a specific set of fields. The `Timestamp` field remains mandatory to ensure data indexability.  
```json  
{  
  "dataset": "firewall_events",  
  "enabled": true,  
  "fields": [  
    "Timestamp",  
    "ClientRequestHost",  
    "ClientIP",  
    "Action",  
    "EdgeResponseStatus",  
    "OriginResponseStatus"  
  ]  
}  
```  
For more information, refer to the [Log Explorer documentation](https://edgetunnel-b2h.pages.dev/log-explorer/).

Mar 11, 2026
1. ### [NVIDIA Nemotron 3 Super now available on Workers AI](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-11-nemotron-3-super-workers-ai/)  
[ Workers AI ](https://edgetunnel-b2h.pages.dev/workers-ai/)  
We're excited to partner with NVIDIA to bring [@cf/nvidia/nemotron-3-120b-a12b](https://edgetunnel-b2h.pages.dev/workers-ai/models/nemotron-3-120b-a12b/) to Workers AI. NVIDIA Nemotron 3 Super is a Mixture-of-Experts (MoE) model with a hybrid Mamba-transformer architecture, 120B total parameters, and 12B active parameters per forward pass.  
The model is optimized for running many collaborating agents per application. It delivers high accuracy for reasoning, tool calling, and instruction following across complex multi-step tasks.

**Key capabilities:**

  * **Hybrid Mamba-transformer architecture** delivers over 50% higher token generation throughput compared to leading open models, reducing latency for real-world applications
  * **Tool calling** support for building AI agents that invoke tools across multiple conversation turns
  * **Multi-Token Prediction (MTP)** accelerates long-form text generation by predicting several future tokens simultaneously in a single forward pass
  * **32,000 token context window** for retaining conversation history and plan states across multi-step agent workflows  
Prompt caching  
For optimal performance with multi-turn conversations, send the `x-session-affinity` header with a unique session identifier to enable prompt caching. This routes requests to the same model instance, reducing latency and inference costs. For details, refer to [Prompt caching](https://edgetunnel-b2h.pages.dev/workers-ai/features/prompt-caching/).  
Use Nemotron 3 Super through the [Workers AI binding](https://edgetunnel-b2h.pages.dev/workers-ai/configuration/bindings/) (`env.AI.run()`), the REST API at `/run` or `/v1/chat/completions`, or the [OpenAI-compatible endpoint](https://edgetunnel-b2h.pages.dev/workers-ai/configuration/open-ai-compatibility/).  
For more information, refer to the [Nemotron 3 Super model page](https://edgetunnel-b2h.pages.dev/workers-ai/models/nemotron-3-120b-a12b/).

Mar 10, 2026
1. ### [WARP client for macOS (version 2026.3.566.1)](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-10-warp-macos-beta/)  
[ Cloudflare One Client ](https://edgetunnel-b2h.pages.dev/cloudflare-one/team-and-resources/devices/cloudflare-one-client/)  
A new Beta release for the macOS WARP client is now available on the [beta releases downloads page](https://edgetunnel-b2h.pages.dev/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/beta-releases/).  
This release contains minor fixes and introduces a brand new visual style for the client interface. The new Cloudflare One Client interface changes connectivity management from a toggle to a button and brings useful connectivity settings to the home screen. The redesign also introduces a collapsible navigation bar. When expanded, more client information can be accessed including connectivity, settings, and device profile information. If you have any feedback or questions, visit the [Cloudflare Community forum](https://community.cloudflare.com/t/introducing-the-new-cloudflare-one-client-interface/901362) and let us know.

**Changes and improvements**

  * Empty MDM files are now rejected instead of being incorrectly accepted as a single MDM config.
  * Fixed an issue in proxy mode where the client could become unresponsive due to upstream connection timeouts.
  * Fixed emergency disconnect state from a previous organization incorrectly persisting after switching organizations.
  * Consumer-only CLI commands are now clearly distinguished from Zero Trust commands.
  * Added detailed QUIC connection metrics to diagnostic logs for better troubleshooting.
  * Added monitoring for tunnel statistics collection timeouts.
  * Switched tunnel congestion control algorithm to Cubic for improved reliability across platforms.
  * Fixed initiating managed network detection checks when no network is available, which caused device profile flapping.

**Known issues**

  * The client may become stuck in a `Connecting` state. To resolve this issue, reconnect the client by selecting **Disconnect** and then **Connect** in the client user interface. Alternatively, change the client's operation mode.
  * The client may display an empty white screen upon the device waking from sleep. To resolve this issue, exit and then open the client to re-launch it.
  * Canceling login during a single MDM configuration setup results in an empty page with no way to resume authentication. To work around this issue, exit and relaunch the client.

```json
{"@context":"https://schema.org","@type":"BlogPosting","@id":"https://edgetunnel-b2h.pages.dev/changelog/15/#page","headline":"Changelogs | Cloudflare Docs","url":"https://edgetunnel-b2h.pages.dev/changelog/15/","inLanguage":"en","image":"https://edgetunnel-b2h.pages.dev/cf-twitter-card.png","publisher":{"@type":"Organization","name":"Cloudflare","url":"https://www.cloudflare.com/"},"isPartOf":{"@type":"WebSite","@id":"https://edgetunnel-b2h.pages.dev/#website","name":"Cloudflare Docs","url":"https://edgetunnel-b2h.pages.dev/"}}
```
