---
title: Changelogs
image: https://edgetunnel-b2h.pages.dev/cf-twitter-card.png
---

> Documentation Index  
> Fetch the complete documentation index at: https://edgetunnel-b2h.pages.dev/changelog/llms.txt  
> Use this file to discover all available pages before exploring further. 

[Skip to content](#%5Ftop) 

# Changelog

New updates and improvements at Cloudflare.

[ Subscribe to RSS ](https://edgetunnel-b2h.pages.dev/changelog/rss/index.xml) [ View RSS feeds ](https://edgetunnel-b2h.pages.dev/fundamentals/new-features/available-rss-feeds/) 

All products

![hero image](https://edgetunnel-b2h.pages.dev/_astro/hero.CVYJHPAd_26AMqX.svg) 

Mar 10, 2026
1. ### [WARP client for Windows (version 2026.3.566.1)](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-10-warp-windows-beta/)  
[ Cloudflare One Client ](https://edgetunnel-b2h.pages.dev/cloudflare-one/team-and-resources/devices/cloudflare-one-client/)  
A new Beta release for the Windows WARP client is now available on the [beta releases downloads page](https://edgetunnel-b2h.pages.dev/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/beta-releases/).  
This release contains minor fixes and introduces a brand new visual style for the client interface. The new Cloudflare One Client interface changes connectivity management from a toggle to a button and brings useful connectivity settings to the home screen. The redesign also introduces a collapsible navigation bar. When expanded, more client information can be accessed including connectivity, settings, and device profile information. If you have any feedback or questions, visit the [Cloudflare Community forum](https://community.cloudflare.com/t/introducing-the-new-cloudflare-one-client-interface/901362) and let us know.

**Changes and improvements**

  * Consumer-only CLI commands are now clearly distinguished from Zero Trust commands.
  * Added detailed QUIC connection metrics to diagnostic logs for better troubleshooting.
  * Added monitoring for tunnel statistics collection timeouts.
  * Switched tunnel congestion control algorithm to Cubic for improved reliability across platforms.
  * Fixed packet capture failing on tunnel interface when the tunnel interface is renamed by SCCM VPN boundary support.
  * Fixed unnecessary registration deletion caused by RDP connections in multi-user mode.
  * Fixed increased tunnel interface start-up time due to a race between duplicate address detection (DAD) and disabling NetBT.
  * Fixed tunnel failing to connect when the system DNS search list contains unexpected characters.
  * Empty MDM files are now rejected instead of being incorrectly accepted as a single MDM config.
  * Fixed an issue in proxy mode where the client could become unresponsive due to upstream connection timeouts.
  * Fixed emergency disconnect state from a previous organization incorrectly persisting after switching organizations.
  * Fixed initiating managed network detection checks when no network is available, which caused device profile flapping.

**Known issues**

  * The client may unexpectedly terminate during captive portal login. To work around this issue, use a web browser to authenticate with the captive portal and then re-launch the client.
  * An error indicating that Microsoft Edge can't read and write to its data directory may be displayed during captive portal login; this error is benign and can be dismissed.
  * The client may become stuck in a `Connecting` state. To resolve this issue, reconnect the client by selecting **Disconnect** and then **Connect** in the client user interface. Alternatively, change the client's operation mode.
  * The client may display an empty white screen upon the device waking from sleep. To resolve this issue, exit and then open the client to re-launch it.
  * Canceling login during a single MDM configuration setup results in an empty page with no way to resume authentication. To work around this issue, exit and relaunch the client.
  * For Windows 11 24H2 users, Microsoft has confirmed a regression that may lead to performance issues like mouse lag, audio cracking, or other slowdowns. Cloudflare recommends users experiencing these issues upgrade to a minimum [Windows 11 24H2 version KB5062553](https://support.microsoft.com/en-us/topic/july-8-2025-kb5062553-os-build-26100-4652-523e69cb-051b-43c6-8376-6a76d6caeefd) or higher for resolution.
  * Devices with KB5055523 installed may receive a warning about `Win32/ClickFix.ABA` being present in the installer. To resolve this false positive, update Microsoft Security Intelligence to [version 1.429.19.0](https://www.microsoft.com/en-us/wdsi/definitions/antimalware-definition-release-notes?requestVersion=1.429.19.0) or later. This warning will be omitted from future release notes. This Microsoft Security Intelligence update was released in May 2025.
  * DNS resolution may be broken when the following conditions are all true:
    * The client is in Secure Web Gateway without DNS filtering (tunnel-only) mode.
    * A custom DNS server address is configured on the primary network adapter.
    * The custom DNS server address on the primary network adapter is changed while the client is connected. To work around this issue, reconnect the client by selecting **Disconnect** and then **Connect** in the client user interface.

Mar 10, 2026
1. ### [Audit logs (version 2) - General Availability](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-10-audit-logs-v2-ga/)  
[ Audit Logs ](https://edgetunnel-b2h.pages.dev/fundamentals/account/account-security/review-audit-logs/)  
Audit Logs v2 is now generally available to all Cloudflare customers.  
![Audit Logs v2 GA](https://edgetunnel-b2h.pages.dev/_astro/auditlogsv2.C3pqAR33_1qYU5j.webp)  
Audit Logs v2 provides a unified and standardized system for tracking and recording all user and system actions across Cloudflare products. Built on Cloudflare's API Shield / OpenAPI gateway, logs are generated automatically without requiring manual instrumentation from individual product teams, ensuring consistency across \~95% of Cloudflare products.

**What's available at GA:**

  * **Standardized logging** — Audit logs follow a consistent format across all Cloudflare products, making it easier to search, filter, and investigate activity.
  * **Expanded product coverage** — \~95% of Cloudflare products covered, up from \~75% in v1.
  * **Granular filtering** — Filter by actor, action type, action result, resource, raw HTTP method, zone, and more. Over 20 filter parameters available via the API.
  * **Enhanced context** — Each log entry includes authentication method, interface (API or dashboard), Cloudflare Ray ID, and actor token details.
  * **18-month retention** — Logs are retained for 18 months. Full history is accessible via the API or Logpush.

**Access:**

  * **Dashboard**: Go to **Manage Account** \> **Audit Logs**. Audit Logs v2 is shown by default.
  * **API**: `GET https://api.cloudflare.com/client/v4/accounts/{account_id}/logs/audit`
  * **Logpush**: Available via the `audit_logs_v2` account-scoped dataset.

**Important notes:**

  * Approximately 30 days of logs from the Beta period (back to \~February 8, 2026) are available at GA. These Beta logs will expire on \~April 9, 2026\. Logs generated after GA will be retained for the full 18 months. Older logs remain available in Audit Logs v1.
  * The UI query window is limited to 90 days for performance reasons. Use the API or Logpush for access to the full 18-month history.
  * `GET` requests (view actions) and `4xx` error responses are not logged at GA. `GET` logging will be selectively re-enabled for sensitive read operations in a future release.
  * Audit Logs v1 continues to run in parallel. A deprecation timeline will be communicated separately.
  * Before and after values — the ability to see what a value changed from and to — is a highly requested feature and is on our roadmap for a post-GA release. In the meantime, we recommend using Audit Logs v1 for before and after values. Audit Logs v1 will continue to run in parallel until this feature is available in v2.  
For more details, refer to the [Audit Logs v2 documentation](https://edgetunnel-b2h.pages.dev/fundamentals/account/account-security/audit-logs/).

Mar 10, 2026
1. ### [Crawl entire websites with a single API call using Browser Rendering](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-10-br-crawl-endpoint/)  
[ Browser Run ](https://edgetunnel-b2h.pages.dev/browser-run/)  
_Edit: this post has been edited to clarify crawling behavior with respect to site guidance._  
You can now crawl an entire website with a single API call using [Browser Rendering](https://edgetunnel-b2h.pages.dev/browser-run/)'s new [/crawl endpoint](https://edgetunnel-b2h.pages.dev/browser-run/quick-actions/crawl-endpoint/), available in open beta. Submit a starting URL, and pages are automatically discovered, rendered in a headless browser, and returned in multiple formats, including HTML, Markdown, and structured JSON. The endpoint is a [verified bot (intermediary agent)](https://edgetunnel-b2h.pages.dev/bots/concepts/bot/verified-bots/) that respects robots.txt and [AI Crawl Control ↗](https://www.cloudflare.com/ai-crawl-control/) by default, making it easy for developers to comply with website rules, and making it less likely for crawlers to ignore web-owner guidance. This is great for training models, building RAG pipelines, and researching or monitoring content across a site.  
Crawl jobs run asynchronously. You submit a URL, receive a job ID, and check back for results as pages are processed.  
```sh  
# Initiate a crawl  
curl -X POST 'https://api.cloudflare.com/client/v4/accounts/{account_id}/browser-rendering/crawl' \
  -H 'Authorization: Bearer <apiToken>' \
  -H 'Content-Type: application/json' \
  -d '{  
    "url": "https://blog.cloudflare.com/"  
  }'  
# Check results  
curl -X GET 'https://api.cloudflare.com/client/v4/accounts/{account_id}/browser-rendering/crawl/{job_id}' \
  -H 'Authorization: Bearer <apiToken>'  
```  
Key features:

  * **Multiple output formats** \- Return crawled content as HTML, Markdown, and structured JSON (powered by [Workers AI](https://edgetunnel-b2h.pages.dev/workers-ai/))
  * **Crawl scope controls** \- Configure crawl depth, page limits, and wildcard patterns to include or exclude specific URL paths
  * **Automatic page discovery** \- Discovers URLs from sitemaps, page links, or both
  * **Incremental crawling** \- Use `modifiedSince` and `maxAge` to skip pages that haven't changed or were recently fetched, saving time and cost on repeated crawls
  * **Static mode** \- Set `render: false` to fetch static HTML without spinning up a browser, for faster crawling of static sites
  * **Well-behaved bot** \- Honors `robots.txt` directives, including `crawl-delay`  
Available on both the Workers Free and Paid plans.

**Note**: the /crawl endpoint cannot bypass Cloudflare bot detection or captchas, and self-identifies as a bot.  
To get started, refer to the [crawl endpoint documentation](https://edgetunnel-b2h.pages.dev/browser-run/quick-actions/crawl-endpoint/). If you are setting up your own site to be crawled, review the [robots.txt and sitemaps best practices](https://edgetunnel-b2h.pages.dev/browser-run/reference/robots-txt/).

Mar 09, 2026
1. ### [New Vulnerability Scanner for API Shield](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-09-vulnerability-scanner/)  
[ API Shield ](https://edgetunnel-b2h.pages.dev/api-shield/)  
Introducing Cloudflare's Web and API Vulnerability Scanner (Open Beta)  
Cloudflare is launching the [Open Beta of the **Web and API Vulnerability Scanner** ↗](https://blog.cloudflare.com/vulnerability-scanner) for all [API Shield](https://edgetunnel-b2h.pages.dev/api-shield/) customers. This new, stateful Dynamic Application Security Testing (DAST) platform helps teams proactively find logic flaws in their APIs.  
The initial release focuses on detecting Broken Object Level Authorization (BOLA) vulnerabilities by building API call graphs to simulate attacker and owner contexts, then testing these contexts by sending real HTTP requests to your APIs.  
The scanner is now available via the Cloudflare API. To scan, set up your target environment, owner and attacker credentials, and upload your OpenAPI file with response schemas. The scanner will be available in the Cloudflare dashboard in a future release.

**Access**: This feature is only available to API Shield subscribers via the Cloudflare API. We hope you will use the API for programmatic integration into your CI/CD pipelines and security dashboards.

**Documentation**: Refer to the [developer documentation](https://edgetunnel-b2h.pages.dev/api-shield/security/vulnerability-scanner/) to start scanning your endpoints today.

Mar 09, 2026
1. ### [New MCP Portal Logs dataset and new fields across multiple Logpush datasets in Cloudflare Logs](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-09-log-fields-updated/)  
[ Logs ](https://edgetunnel-b2h.pages.dev/logs/)  
Cloudflare has added new fields across multiple [Logpush datasets](https://edgetunnel-b2h.pages.dev/logs/logpush/logpush-job/datasets/):  
#### New dataset

  * **MCP Portal Logs**: A new dataset with fields including `ClientCountry`, `ClientIP`, `ColoCode`, `Datetime`, `Error`, `Method`, `PortalAUD`, `PortalID`, `PromptGetName`, `ResourceReadURI`, `ServerAUD`, `ServerID`, `ServerResponseDurationMs`, `ServerURL`, `SessionID`, `Success`, `ToolCallName`, `UserEmail`, and `UserID`.  
#### New fields in existing datasets

  * **DEX Application Tests**: `HTTPRedirectEndMs`, `HTTPRedirectStartMs`, `HTTPResponseBody`, and `HTTPResponseHeaders`.
  * **DEX Device State Events**: `ExperimentalExtra`.
  * **Firewall Events**: `FraudUserID`.
  * **Gateway HTTP**: `AppControlInfo` and `ApplicationStatuses`.
  * **Gateway DNS**: `InternalDNSDurationMs`.
  * **HTTP Requests**: `FraudEmailRisk`, `FraudUserID`, and `PayPerCrawlStatus`.
  * **Network Analytics Logs**: `DNSQueryName`, `DNSQueryType`, and `PFPCustomTag`.
  * **WARP Toggle Changes**: `UserEmail`.
  * **WARP Config Changes**: `UserEmail`.
  * **Zero Trust Network Session Logs**: `SNI`.  
For the complete field definitions for each dataset, refer to [Logpush datasets](https://edgetunnel-b2h.pages.dev/logs/logpush/logpush-job/datasets/).

Mar 06, 2026
1. ### [Workflow steps now expose retry attempt number via step context](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-06-step-context-available/)  
[ Workflows ](https://edgetunnel-b2h.pages.dev/workflows/)[ Workers ](https://edgetunnel-b2h.pages.dev/workers/)  
Cloudflare Workflows allows you to configure specific retry logic for each step in your workflow execution. Now, you can access **which** retry attempt is currently executing for calls to `step.do()`:

**TypeScript**  
```ts  
await step.do("my-step", async (ctx) => {  
  // ctx.attempt is 1 on first try, 2 on first retry, etc.  
  console.log(`Attempt ${ctx.attempt}`);  
});  
```  
You can use the step context for improved logging & observability, progressive backoff, or conditional logic in your workflow definition.  
Note that the current attempt number is 1-indexed. For more information on retry behavior, refer to [Sleeping and Retrying](https://edgetunnel-b2h.pages.dev/workflows/build/sleeping-and-retrying/).

Mar 06, 2026
1. ### [Region Filtering, AS Traffic Volume, and Navigation Improvements on Cloudflare Radar](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-06-radar-region-filtering-traffic-volume-navigation/)  
[ Radar ](https://edgetunnel-b2h.pages.dev/radar/)  
[**Radar**](https://edgetunnel-b2h.pages.dev/radar/) ships several new features that improve the flexibility and usability of the platform, as well as visibility into what is happening on the Internet.  
#### Region filtering  
All location-aware pages now support filtering by region, including continents, geographic subregions ([Middle East ↗](https://radar.cloudflare.com/middle-east), [Eastern Asia ↗](https://radar.cloudflare.com/eastern-asia), etc.), political regions ([EU ↗](https://radar.cloudflare.com/european-union), [African Union ↗](https://radar.cloudflare.com/african-union)), and US Census regions/divisions (for example, [New England ↗](https://radar.cloudflare.com/traffic/us-new-england), [US Northeast ↗](https://radar.cloudflare.com/traffic/us-northeast)).  
![Screenshot of region filtering on Radar - Middle east](https://edgetunnel-b2h.pages.dev/_astro/region-filtering-middle-east.D__dYNBw_i7aR.webp)  
#### Traffic volume by top autonomous systems and locations  
A new traffic volume view shows the top autonomous systems and countries/territories for a given location. This is useful for quickly determining which network providers in a location may be experiencing connectivity issues, or how traffic is distributed across a region.  
![Screenshot of traffic volume by top autonomous systems in US](https://edgetunnel-b2h.pages.dev/_astro/traffic-volume-top-as-us.DhnbB8gy_ZyvEEM.webp)  
The new AS and location dimensions have also been added to the [Data Explorer ↗](https://radar.cloudflare.com/explorer) for the HTTP, DNS, and NetFlows datasets. Combined with other available filters, this provides a powerful tool for generating unique insights.  
![Screenshot of AS and location dimensions in Data Explorer](https://edgetunnel-b2h.pages.dev/_astro/data-explorer-top-as-pt.DAWOCd_b_1riM1l.webp)  
Finally, breadcrumb navigation is now available on most pages, allowing easier navigation between parent and related pages.  
Check out these features on [Cloudflare Radar ↗](https://radar.cloudflare.com).

Mar 06, 2026
1. ### [Real-time transcription in RealtimeKit now supports 10 languages with regional variants](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-06-realtimekit-multilingual-transcription/)  
[ Workers AI ](https://edgetunnel-b2h.pages.dev/workers-ai/)[ Realtime ](https://edgetunnel-b2h.pages.dev/realtime/)  
[Real-time transcription](https://edgetunnel-b2h.pages.dev/realtime/realtimekit/ai/transcription/) in RealtimeKit now supports 10 languages with regional variants, powered by [Deepgram Nova-3](https://edgetunnel-b2h.pages.dev/workers-ai/models/nova-3/) running on [Workers AI](https://edgetunnel-b2h.pages.dev/workers-ai/).  
During a meeting, participant audio is routed through [AI Gateway](https://edgetunnel-b2h.pages.dev/ai-gateway/) to Nova-3 on Workers AI — so transcription runs on Cloudflare's network end-to-end, reducing latency compared to routing through external speech-to-text services.  
Set the language when [creating a meeting](https://edgetunnel-b2h.pages.dev/realtime/realtimekit/concepts/meeting/) via `ai_config.transcription.language`:  
```json  
{  
  "ai_config": {  
    "transcription": {  
      "language": "fr"  
    }  
  }  
}  
```  
Supported languages include English, Spanish, French, German, Hindi, Russian, Portuguese, Japanese, Italian, and Dutch — with regional variants like `en-AU`, `en-GB`, `en-IN`, `en-NZ`, `es-419`, `fr-CA`, `de-CH`, `pt-BR`, and `pt-PT`. Use `multi` for automatic multilingual detection.  
If you are building voice agents or real-time translation workflows, your agent can now transcribe in the caller's language natively — no extra services or routing logic needed.

  * [Transcription docs](https://edgetunnel-b2h.pages.dev/realtime/realtimekit/ai/transcription/)
  * [Nova-3 model page](https://edgetunnel-b2h.pages.dev/workers-ai/models/nova-3/)
  * [Workers AI](https://edgetunnel-b2h.pages.dev/workers-ai/)
  * [AI Gateway](https://edgetunnel-b2h.pages.dev/ai-gateway/)

Mar 06, 2026
1. ### [Dismiss and filter matches in Brand Protection](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-06-brand-protection-dismiss-match/)  
[ Security Center ](https://edgetunnel-b2h.pages.dev/security-center/)  
We have introduced new triage controls to help you manage your Brand Protection results more efficiently. You can now clear out the noise by dismissing matches while maintaining full visibility into your historical decisions.  
#### What's new

  * **Dismiss matches**: Users can now mark specific results as dismissed if they are determined to be benign or false positives, removing them from the primary triage view.
  * **Show/Hide toggle**: A new visibility control allows you to instantly switch between viewing only active matches and including previously dismissed ones.
  * **Persistent review states**: Dismissed status is saved across sessions, ensuring that your workspace remains organized and focused on new or high-priority threats.  
#### Key benefits of the dismiss match functionality:

  * Reduce alert fatigue by hiding known-safe results, allowing your team to focus exclusively on unreviewed or high-risk infringements.
  * Auditability and recovery through the visibility toggle, ensuring that no match is ever truly "lost" and can be re-evaluated if a site's content changes.
  * Improved collaboration as your team members can see which matches have already been vetted and dismissed by others.  
Ready to clean up your match queue? Learn more in our [Brand Protection documentation](https://edgetunnel-b2h.pages.dev/security-center/brand-protection/).

Mar 04, 2026
1. ### [Browser Rendering: 3x higher REST API request rate](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-04-br-rest-api-limit-increase/)  
[ Browser Run ](https://edgetunnel-b2h.pages.dev/browser-run/)  
[Browser Rendering](https://edgetunnel-b2h.pages.dev/browser-run/) REST API rate limits for Workers Paid plans have been increased from 3 requests per second (180/min) to **10 requests per second (600/min)**. No action is needed to benefit from the higher limit.  
![Browser Rendering REST API rate limit increased from 3 to 10 requests per second](https://edgetunnel-b2h.pages.dev/_astro/rest-api-limit-increase.DJHY7xYF_1U7IJn.webp)  
The [REST API](https://edgetunnel-b2h.pages.dev/browser-run/quick-actions/) lets you perform common browser tasks with a single API call, and you can now do it at a higher rate.

  * [/content - Fetch HTML](https://edgetunnel-b2h.pages.dev/browser-run/quick-actions/content-endpoint/)
  * [/screenshot - Capture screenshot](https://edgetunnel-b2h.pages.dev/browser-run/quick-actions/screenshot-endpoint/)
  * [/pdf - Render PDF](https://edgetunnel-b2h.pages.dev/browser-run/quick-actions/pdf-endpoint/)
  * [/markdown - Extract Markdown from a webpage](https://edgetunnel-b2h.pages.dev/browser-run/quick-actions/markdown-endpoint/)
  * [/snapshot - Take a webpage snapshot](https://edgetunnel-b2h.pages.dev/browser-run/quick-actions/snapshot/)
  * [/scrape - Scrape HTML elements](https://edgetunnel-b2h.pages.dev/browser-run/quick-actions/scrape-endpoint/)
  * [/json - Capture structured data using AI](https://edgetunnel-b2h.pages.dev/browser-run/quick-actions/json-endpoint/)
  * [/links - Retrieve links from a webpage](https://edgetunnel-b2h.pages.dev/browser-run/quick-actions/links-endpoint/)  
If you use the [Browser Sessions](https://edgetunnel-b2h.pages.dev/browser-run/#integration-methods) method, increases to concurrent browser and new browser limits are coming soon. Stay tuned.  
For full details, refer to the [Browser Rendering limits page](https://edgetunnel-b2h.pages.dev/browser-run/limits/).

Mar 04, 2026
1. ### [User risk score selector in Access policies](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-04-user-risk-score-access-policies/)  
[ Cloudflare One ](https://edgetunnel-b2h.pages.dev/cloudflare-one/)[ Access ](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/policies/)  
You can now use [user risk scores](https://edgetunnel-b2h.pages.dev/cloudflare-one/team-and-resources/users/risk-score/) in your [Access policies](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/policies/). The new **User Risk Score** selector allows you to create Access policies that respond to user behavior patterns detected by Cloudflare's risk scoring system, including impossible travel, high DLP policy matches, and more.  
For more information, refer to [Use risk scores in Access policies](https://edgetunnel-b2h.pages.dev/cloudflare-one/team-and-resources/users/risk-score/#use-risk-scores-in-access-policies).

Mar 04, 2026
1. ### [Gateway Authorization Proxy and hosted PAC files (open beta)](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-04-gateway-authorization-proxy-open-beta/)  
[ Gateway ](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/)  
The [Gateway Authorization Proxy](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#authorization-endpoint) and [PAC file hosting](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#create-a-hosted-pac-file) are now in open beta for all plan types.  
Previously, [proxy endpoints](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#source-ip-endpoint) relied on static source IP addresses to authorize traffic, providing no user-level identity in logs or policies. The new authorization proxy replaces IP-based authorization with [Cloudflare Access](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/policies/) authentication, verifying who a user is before applying Gateway filtering without installing the WARP client.  
This is ideal for environments where you cannot deploy a device client, such as virtual desktops (VDI), mergers and acquisitions, or compliance-restricted endpoints.  
#### Key capabilities

  * **Identity-aware proxy traffic** — Users authenticate through your identity provider (Okta, Microsoft Entra ID, Google Workspace, and others) via Cloudflare Access. Logs now show exactly which user accessed which site, and you can write [identity-based policies](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/identity-selectors/) like "only the Finance team can access this accounting tool."
  * **Multiple identity providers** — Display one or multiple login methods simultaneously, giving flexibility for organizations managing users across different identity systems.
  * **Cloudflare-hosted PAC files** — Create and host [PAC files](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#create-a-hosted-pac-file) directly in Cloudflare One with pre-configured templates for Okta and Azure, hosted at `https://pac.cloudflare-gateway.com/<account-id>/<slug>` on Cloudflare's global network.
  * **Simplified billing** — Each user occupies a seat, exactly like they do with the Cloudflare One Client. No new metrics to track.  
#### Get started

  1. In [Cloudflare One ↗](https://one.dash.cloudflare.com/), go to **Networks** \> **Resolvers & Proxies** \> **Proxy endpoints**.
  2. [Create an authorization proxy endpoint](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#authorization-endpoint) and configure Access policies.
  3. [Create a hosted PAC file](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#create-a-hosted-pac-file) or write your own.
  4. [Configure browsers](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#3b-configure-browser-to-use-pac-file) to use the PAC file URL.
  5. [Install the Cloudflare certificate](https://edgetunnel-b2h.pages.dev/cloudflare-one/team-and-resources/devices/user-side-certificates/) for HTTPS inspection.  
For more details, refer to the [proxy endpoints documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) and the [announcement blog post ↗](https://blog.cloudflare.com/gateway-authorization-proxy-identity-aware-policies/).

Mar 04, 2026
1. ### [New conversion options for Markdown Conversion](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-04-new-markdown-conversion-options/)  
[ Workers AI ](https://edgetunnel-b2h.pages.dev/workers-ai/)  
You can now customize how the [Markdown Conversion](https://edgetunnel-b2h.pages.dev/workers-ai/features/markdown-conversion/) service processes different file types by passing a `conversionOptions` object.  
Available options:

  * **Images**: Set the language for AI-generated image descriptions
  * **HTML**: Use CSS selectors to extract specific content, or provide a hostname to resolve relative links
  * **PDF**: Exclude metadata from the output  
Use the [env.AI](https://edgetunnel-b2h.pages.dev/workers-ai/features/markdown-conversion/usage/binding/) binding:

  * [  JavaScript ](#tab-panel-5061)
  * [  TypeScript ](#tab-panel-5062)

**JavaScript**  
```js  
await env.AI.toMarkdown(  
  { name: "page.html", blob: new Blob([html]) },  
  {  
    conversionOptions: {  
      html: { cssSelector: "article.content" },  
      image: { descriptionLanguage: "es" },  
    },  
  },  
);  
```

**TypeScript**  
```ts  
await env.AI.toMarkdown(  
  { name: "page.html", blob: new Blob([html]) },  
  {  
    conversionOptions: {  
      html: { cssSelector: "article.content" },  
      image: { descriptionLanguage: "es" },  
    },  
  },  
);  
```  
Or call the REST API:  
```bash  
curl https://api.cloudflare.com/client/v4/accounts/{ACCOUNT_ID}/ai/tomarkdown \
  -H 'Authorization: Bearer {API_TOKEN}' \
  -F 'files=@index.html' \
  -F 'conversionOptions={"html": {"cssSelector": "article.content"}}'  
```  
For more details, refer to [Conversion Options](https://edgetunnel-b2h.pages.dev/workers-ai/features/markdown-conversion/conversion-options/).

Mar 03, 2026
1. ### [Workflows step limit increased to 25,000 steps per instance](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-03-step-limits-to-25k/)  
[ Workflows ](https://edgetunnel-b2h.pages.dev/workflows/)[ Workers ](https://edgetunnel-b2h.pages.dev/workers/)  
Each Workflow on Workers Paid now supports 10,000 steps by default, configurable up to 25,000 steps in your `wrangler.jsonc` file:  
```json  
{  
  "workflows": [  
    {  
      "name": "my-workflow",  
      "binding": "MY_WORKFLOW",  
      "class_name": "MyWorkflow",  
      "limits": {  
        "steps": 25000  
      }  
    }  
  ]  
}  
```  
Previously, each instance was limited to 1,024 steps. Now, Workflows can support more complex, long-running executions without the additional complexity of recursive or child workflow calls.  
Note that the maximum persisted state limit per Workflow instance remains **100 MB** for Workers Free and **1 GB** for Workers Paid. Refer to [Workflows limits](https://edgetunnel-b2h.pages.dev/workflows/reference/limits/) for more information.

Mar 03, 2026
1. ### [Real-time file watching in Sandboxes](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-03-sandbox-watch-file-events/)  
[ Agents ](https://edgetunnel-b2h.pages.dev/agents/)  
[Sandboxes](https://edgetunnel-b2h.pages.dev/sandbox/) now support real-time filesystem watching via `sandbox.watch()`. The method returns a [Server-Sent Events ↗](https://developer.mozilla.org/en-US/docs/Web/API/Server-sent%5Fevents) stream backed by native inotify, so your Worker receives `create`, `modify`, `delete`, and `move` events as they happen inside the container.  
#### `sandbox.watch(path, options)`  
Pass a directory path and optional filters. The returned stream is a standard `ReadableStream` you can proxy directly to a browser client or consume server-side.

  * [  JavaScript ](#tab-panel-5063)
  * [  TypeScript ](#tab-panel-5064)

**JavaScript**  
```js  
// Stream events to a browser client  
const stream = await sandbox.watch("/workspace/src", {  
  recursive: true,  
  include: ["*.ts", "*.js"],  
});  
return new Response(stream, {  
  headers: { "Content-Type": "text/event-stream" },  
});  
```

**TypeScript**  
```ts  
// Stream events to a browser client  
const stream = await sandbox.watch("/workspace/src", {  
  recursive: true,  
  include: ["*.ts", "*.js"],  
});  
return new Response(stream, {  
  headers: { "Content-Type": "text/event-stream" },  
});  
```  
#### Server-side consumption with `parseSSEStream`  
Use `parseSSEStream` to iterate over events inside a Worker without forwarding them to a client.

  * [  JavaScript ](#tab-panel-5065)
  * [  TypeScript ](#tab-panel-5066)

**JavaScript**  
```js  
import { parseSSEStream } from "@cloudflare/sandbox";  
const stream = await sandbox.watch("/workspace/src", { recursive: true });  
for await (const event of parseSSEStream(stream)) {  
  console.log(event.type, event.path);  
}  
```

**TypeScript**  
```ts  
import { parseSSEStream } from "@cloudflare/sandbox";  
import type { FileWatchSSEEvent } from "@cloudflare/sandbox";  
const stream = await sandbox.watch("/workspace/src", { recursive: true });  
for await (const event of parseSSEStream<FileWatchSSEEvent>(stream)) {  
  console.log(event.type, event.path);  
}  
```  
Each event includes a `type` field (`create`, `modify`, `delete`, or `move`) and the affected `path`. Move events also include a `from` field with the original path.  
#### Options

| Option    | Type       | Description                                                 |
| --------- | ---------- | ----------------------------------------------------------- |
| recursive | boolean    | Watch subdirectories. Defaults to false.                    |
| include   | string\[\] | Glob patterns to filter events. Omit to receive all events. |  
#### Upgrade  
To update to the latest version:  
```sh  
npm i @cloudflare/sandbox@latest  
```  
For full API details, refer to the [Sandbox file watching reference](https://edgetunnel-b2h.pages.dev/sandbox/api/file-watching/).

Mar 03, 2026
1. ### [Network Quality Test on Cloudflare Radar](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-03-radar-network-quality-test/)  
[ Radar ](https://edgetunnel-b2h.pages.dev/radar/)  
[**Radar**](https://edgetunnel-b2h.pages.dev/radar/) now includes a [Network Quality Test ↗](https://radar.cloudflare.com/speedtest) page. The tool measures Internet connection quality and performance, showing connection details such as IP address, server location, network (ASN), and IP version. For more detailed speed test results, the page links to [speed.cloudflare.com ↗](https://speed.cloudflare.com/).  
![Screenshot of the Network Quality Test page on Radar](https://edgetunnel-b2h.pages.dev/_astro/network-quality-test.BwQ-CoTH_Z90pOd.webp)

Mar 02, 2026
1. ### [Agents SDK v0.7.0: Observability rewrite, keepAlive, and waitForMcpConnections](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-02-agents-sdk-v070/)  
[ Agents ](https://edgetunnel-b2h.pages.dev/agents/)[ Workers ](https://edgetunnel-b2h.pages.dev/workers/)  
The latest release of the [Agents SDK ↗](https://github.com/cloudflare/agents) rewrites observability from scratch with `diagnostics_channel`, adds `keepAlive()` to prevent Durable Object eviction during long-running work, and introduces `waitForMcpConnections` so MCP tools are always available when `onChatMessage` runs.  
#### Observability rewrite  
The previous observability system used `console.log()` with a custom `Observability.emit()` interface. v0.7.0 replaces it with structured events published to [diagnostics channels](https://edgetunnel-b2h.pages.dev/workers/runtime-apis/nodejs/diagnostics-channel/) — silent by default, zero overhead when nobody is listening.  
Every event has a `type`, `payload`, and `timestamp`. Events are routed to seven named channels:

| Channel          | Event types                                                                                                                                      |
| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| agents:state     | state:update                                                                                                                                     |
| agents:rpc       | rpc, rpc:error                                                                                                                                   |
| agents:message   | message:request, message:response, message:clear, message:cancel, message:error, tool:result, tool:approval                                      |
| agents:schedule  | schedule:create, schedule:execute, schedule:cancel, schedule:retry, schedule:error, queue:retry, queue:error                                     |
| agents:lifecycle | connect, destroy                                                                                                                                 |
| agents:workflow  | workflow:start, workflow:event, workflow:approved, workflow:rejected, workflow:terminated, workflow:paused, workflow:resumed, workflow:restarted |
| agents:mcp       | mcp:client:preconnect, mcp:client:connect, mcp:client:authorize, mcp:client:discover                                                             |  
Use the typed `subscribe()` helper from `agents/observability` for type-safe access:

  * [  JavaScript ](#tab-panel-5073)
  * [  TypeScript ](#tab-panel-5074)

**JavaScript**  
```js  
import { subscribe } from "agents/observability";  
const unsub = subscribe("rpc", (event) => {  
  if (event.type === "rpc") {  
    console.log(`RPC call: ${event.payload.method}`);  
  }  
  if (event.type === "rpc:error") {  
    console.error(  
      `RPC failed: ${event.payload.method} — ${event.payload.error}`,  
    );  
  }  
});  
// Clean up when done  
unsub();  
```

**TypeScript**  
```ts  
import { subscribe } from "agents/observability";  
const unsub = subscribe("rpc", (event) => {  
  if (event.type === "rpc") {  
    console.log(`RPC call: ${event.payload.method}`);  
  }  
  if (event.type === "rpc:error") {  
    console.error(  
      `RPC failed: ${event.payload.method} — ${event.payload.error}`,  
    );  
  }  
});  
// Clean up when done  
unsub();  
```  
In production, all diagnostics channel messages are automatically forwarded to [Tail Workers](https://edgetunnel-b2h.pages.dev/workers/observability/logs/tail-workers/) — no subscription code needed in the agent itself:

  * [  JavaScript ](#tab-panel-5071)
  * [  TypeScript ](#tab-panel-5072)

**JavaScript**  
```js  
export default {  
  async tail(events) {  
    for (const event of events) {  
      for (const msg of event.diagnosticsChannelEvents) {  
        // msg.channel is "agents:rpc", "agents:workflow", etc.  
        console.log(msg.timestamp, msg.channel, msg.message);  
      }  
    }  
  },  
};  
```

**TypeScript**  
```ts  
export default {  
  async tail(events) {  
    for (const event of events) {  
      for (const msg of event.diagnosticsChannelEvents) {  
        // msg.channel is "agents:rpc", "agents:workflow", etc.  
        console.log(msg.timestamp, msg.channel, msg.message);  
      }  
    }  
  },  
};  
```  
The custom `Observability` override interface is still supported for users who need to filter or forward events to external services.  
For the full event reference, refer to the [Observability documentation](https://edgetunnel-b2h.pages.dev/agents/runtime/operations/observability/).  
#### `keepAlive()` and `keepAliveWhile()`  
Durable Objects are evicted after a period of inactivity (typically 70-140 seconds with no incoming requests, WebSocket messages, or alarms). During long-running operations — streaming LLM responses, waiting on external APIs, running multi-step computations — the agent can be evicted mid-flight.  
`keepAlive()` prevents this by creating a 30-second heartbeat schedule. The alarm firing resets the inactivity timer. Returns a disposer function that cancels the heartbeat when called.

  * [  JavaScript ](#tab-panel-5069)
  * [  TypeScript ](#tab-panel-5070)

**JavaScript**  
```js  
const dispose = await this.keepAlive();  
try {  
  const result = await longRunningComputation();  
  await sendResults(result);  
} finally {  
  dispose();  
}  
```

**TypeScript**  
```ts  
const dispose = await this.keepAlive();  
try {  
  const result = await longRunningComputation();  
  await sendResults(result);  
} finally {  
  dispose();  
}  
```  
`keepAliveWhile()` wraps an async function with automatic cleanup — the heartbeat starts before the function runs and stops when it completes:

  * [  JavaScript ](#tab-panel-5067)
  * [  TypeScript ](#tab-panel-5068)

**JavaScript**  
```js  
const result = await this.keepAliveWhile(async () => {  
  const data = await longRunningComputation();  
  return data;  
});  
```

**TypeScript**  
```ts  
const result = await this.keepAliveWhile(async () => {  
  const data = await longRunningComputation();  
  return data;  
});  
```  
Key details:

  * **Multiple concurrent callers** — Each `keepAlive()` call returns an independent disposer. Disposing one does not affect others.
  * **AIChatAgent built-in** — `AIChatAgent` automatically calls `keepAlive()` during streaming responses. You do not need to add it yourself.
  * **Uses the scheduling system** — The heartbeat does not conflict with your own schedules. It shows up in `getSchedules()` if you need to inspect it.  
Note  
`keepAlive()` is marked `@experimental` and may change between releases.  
For the full API reference and when-to-use guidance, refer to [Schedule tasks — Keeping the agent alive](https://edgetunnel-b2h.pages.dev/agents/runtime/execution/schedule-tasks/#keeping-the-agent-alive).  
#### `waitForMcpConnections`  
`AIChatAgent` now waits for MCP server connections to settle before calling `onChatMessage`. This ensures `this.mcp.getAITools()` returns the full set of tools, especially after Durable Object hibernation when connections are being restored in the background.

  * [  JavaScript ](#tab-panel-5075)
  * [  TypeScript ](#tab-panel-5076)

**JavaScript**  
```js  
export class ChatAgent extends AIChatAgent {  
  // Default — waits up to 10 seconds  
  // waitForMcpConnections = { timeout: 10_000 };  
  // Wait forever  
  waitForMcpConnections = true;  
  // Disable waiting  
  waitForMcpConnections = false;  
}  
```

**TypeScript**  
```ts  
export class ChatAgent extends AIChatAgent {  
  // Default — waits up to 10 seconds  
  // waitForMcpConnections = { timeout: 10_000 };  
  // Wait forever  
  waitForMcpConnections = true;  
  // Disable waiting  
  waitForMcpConnections = false;  
}  
```

| Value                | Behavior                                      |
| -------------------- | --------------------------------------------- |
| { timeout: 10\_000 } | Wait up to 10 seconds (default)               |
| { timeout: N }       | Wait up to N milliseconds                     |
| true                 | Wait indefinitely until all connections ready |
| false                | Do not wait (old behavior before 0.2.0)       |  
For lower-level control, call `this.mcp.waitForConnections()` directly inside `onChatMessage` instead.  
#### Other improvements

  * **MCP deduplication by name and URL** — `addMcpServer` with HTTP transport now deduplicates on both server name and URL. Calling it with the same name but a different URL creates a new connection. URLs are normalized before comparison (trailing slashes, default ports, hostname case).
  * **`callbackHost` optional for non-OAuth servers** — `addMcpServer` no longer requires `callbackHost` when connecting to MCP servers that do not use OAuth.
  * **MCP URL security** — Server URLs are validated before connection to prevent SSRF. Private IP ranges, loopback addresses, link-local addresses, and cloud metadata endpoints are blocked.
  * **Custom denial messages** — `addToolOutput` now supports `state: "output-error"` with `errorText` for custom denial messages in human-in-the-loop tool approval flows.
  * **`requestId` in chat options** — `onChatMessage` options now include a `requestId` for logging and correlating events.  
#### Upgrade  
To update to the latest version:  
```sh  
npm i agents@latest @cloudflare/ai-chat@latest  
```

Mar 02, 2026
1. ### [Get started with AI Gateway automatically](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-02-default-gateway/)  
[ AI Gateway ](https://edgetunnel-b2h.pages.dev/ai-gateway/)  
You can now start using AI Gateway with a single API call — no setup required. Use `default` as your gateway ID, and AI Gateway creates one for you automatically on the first request.  
To try it out, [create an API token](https://edgetunnel-b2h.pages.dev/fundamentals/api/get-started/create-token/) with `AI Gateway - Read`, `AI Gateway - Edit`, and `Workers AI - Read` permissions, then run:  
```bash  
curl -X POST https://gateway.ai.cloudflare.com/v1/$CLOUDFLARE_ACCOUNT_ID/default/compat/chat/completions \
  --header "cf-aig-authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --header 'Content-Type: application/json' \
  --data '{  
    "model": "workers-ai/@cf/meta/llama-3.3-70b-instruct-fp8-fast",  
    "messages": [  
      {  
        "role": "user",  
        "content": "What is Cloudflare?"  
      }  
    ]  
  }'  
```  
AI Gateway gives you logging, caching, rate limiting, and access to multiple AI providers through a single endpoint. For more information, refer to [Get started](https://edgetunnel-b2h.pages.dev/ai-gateway/get-started/).

Mar 02, 2026
1. ### [Copy Cloudflare One resources as JSON or POST requests](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-copy-resources-as-json-or-post-requests/)  
[ Cloudflare One ](https://edgetunnel-b2h.pages.dev/cloudflare-one/)  
You can now copy Cloudflare One resources as JSON or as a ready-to-use API POST request directly from the dashboard. This makes it simple to transition workflows into API calls, automation scripts, or infrastructure-as-code pipelines.  
To use this feature, click the overflow menu (⋮) on any supported resource and select **Copy as JSON** or **Copy as POST request**. The copied output includes only the fields present on your resource, giving you a clean and minimal starting point for your own API calls.  
Initially supported resources:

  * Access applications
  * Access policies
  * Gateway policies
  * Resolver policies
  * Service tokens
  * Identity providers  
We will continue to add support for more resources throughout 2026.

Mar 02, 2026
1. ### [WAF Release - 2026-03-02](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-02-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  
This week's release introduces new detections for vulnerabilities in SmarterTools SmarterMail (CVE-2025-52691 and CVE-2026-23760), alongside improvements to an existing Command Injection (nslookup) detection to enhance coverage.

**Key Findings**

  * CVE-2025-52691: SmarterTools SmarterMail mail server is vulnerable to Arbitrary File Upload, allowing an unauthenticated attacker to upload files to any location on the mail server, potentially enabling remote code execution.
  * CVE-2026-23760: SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API permitting unaunthenticated to reset system administrator accounts failing to verify existing password or reset token.

**Impact**  
Successful exploitation of these SmarterMail vulnerabilities could lead to full system compromise or unauthorized administrative access to mail servers. Administrators are strongly encouraged to apply vendor patches without delay.

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                          | Previous Action | New Action | Comments                                                                                      |
| -------------------------- | ----------- | -------------- | ---------------------------------------------------- | --------------- | ---------- | --------------------------------------------------------------------------------------------- |
| Cloudflare Managed Ruleset | ...966ec6b1 | N/A            | SmarterMail - Arbitrary File Upload - CVE-2025-52691 | Log             | Block      | This is a new detection.                                                                      |
| Cloudflare Managed Ruleset | ...ee964a8c | N/A            | SmarterMail - Authentication Bypass - CVE-2026-23760 | Log             | Block      | This is a new detection.                                                                      |
| Cloudflare Managed Ruleset | ...75b64d99 | N/A            | Command Injection - Nslookup - Beta                  | Log             | Block      | This rule is merged into the original rule "Command Injection - Nslookup" (ID: ...b090ba9a  ) |

Mar 01, 2026
1. ### [Clipboard controls for browser-based RDP](https://edgetunnel-b2h.pages.dev/changelog/post/2026-03-01-rdp-clipboard-controls/)  
[ Access ](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/policies/)  
You can now configure clipboard controls for browser-based RDP with Cloudflare Access. Clipboard controls allow administrators to restrict whether users can copy or paste text between their local machine and the remote Windows server.  
![Enable users to copy and paste content from their local machine to remote RDP sessions in the Cloudflare One dashboard](https://edgetunnel-b2h.pages.dev/_astro/rdp-clipboard-controls.B0ZmliDb_Z1Ne5yg.webp)  
This feature is useful for organizations that support bring-your-own-device (BYOD) policies or third-party contractors using unmanaged devices. By restricting clipboard access, you can prevent sensitive data from being transferred out of the remote session to a user's personal device.  
#### Configuration options  
Clipboard controls are configured per policy within your Access application. For each policy, you can independently allow or deny:

  * **Copy from local client to remote RDP session** — Users can copy/paste text from their local machine into the browser-based RDP session.
  * **Copy from remote RDP session to local client** — Users can copy/paste text from the browser-based RDP session to their local machine.  
By default, both directions are denied for new policies. For existing Access applications created before this feature was available, clipboard access remains enabled to preserve backwards compatibility.  
When a user attempts a restricted clipboard action, the clipboard content is replaced with an error message informing them that the action is not allowed.  
For more information, refer to [Clipboard controls for browser-based RDP](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser/#clipboard-controls).

Feb 27, 2026
1. ### [Export MCP server portal logs with Logpush](https://edgetunnel-b2h.pages.dev/changelog/post/2026-02-27-mcp-portal-logpush/)  
[ Access ](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/policies/)  
Availability  
Only available on Enterprise plans.  
[MCP server portals](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/ai-controls/mcp-portals/) now supports [Logpush](https://edgetunnel-b2h.pages.dev/logs/logpush/) integration. You can automatically export MCP server portal activity logs to third-party storage destinations or security information and event management (SIEM) tools for analysis and auditing.  
#### Available log fields  
The MCP server portal logs dataset includes fields such as:

  * `Datetime` — Timestamp of the request
  * `PortalID` / `PortalAUD` — Portal identifiers
  * `ServerID` / `ServerURL` — Upstream MCP server details
  * `Method` — JSON-RPC method (for example, `tools/call`, `prompts/get`, `resources/read`)
  * `ToolCallName` / `PromptGetName` / `ResourceReadURI` — Method-specific identifiers
  * `UserID` / `UserEmail` — Authenticated user information
  * `Success` / `Error` — Request outcome
  * `ServerResponseDurationMs` — Response time from upstream server  
For the complete field reference, refer to [MCP portal logs](https://edgetunnel-b2h.pages.dev/logs/logpush/logpush-job/datasets/account/mcp%5Fportal%5Flogs/).  
#### Set up Logpush  
To configure Logpush for MCP server portal logs, refer to [Logpush integration](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/logs/logpush/).  
Note  
MCP server portals is currently in beta.

Feb 27, 2026
1. ### [New protocols added for Gateway Protocol Detection (Beta)](https://edgetunnel-b2h.pages.dev/changelog/post/2026-02-27-new-protocol-detection-protocols/)  
[ Gateway ](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/)  
Gateway [Protocol Detection](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/network-policies/protocol-detection/) now supports seven additional protocols in beta:

| Protocol     | Notes                                              |
| ------------ | -------------------------------------------------- |
| IMAP         | Internet Message Access Protocol — email retrieval |
| POP3         | Post Office Protocol v3 — email retrieval          |
| SMTP         | Simple Mail Transfer Protocol — email sending      |
| MYSQL        | MySQL database wire protocol                       |
| RSYNC-DAEMON | rsync daemon protocol                              |
| LDAP         | Lightweight Directory Access Protocol              |
| NTP          | Network Time Protocol                              |  
These protocols join the existing set of detected protocols (HTTP, HTTP2, SSH, TLS, DCERPC, MQTT, and TPKT) and can be used with the _Detected Protocol_ selector in [Network policies](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/network-policies/) to identify and filter traffic based on the application-layer protocol, without relying on port-based identification.  
If protocol detection is enabled on your account, these protocols will automatically be logged when detected in your Gateway network traffic.  
For more information on using Protocol Detection, refer to the [Protocol detection documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/network-policies/protocol-detection/).

Feb 27, 2026
1. ### [Post-Quantum Encryption and Key Transparency on Cloudflare Radar](https://edgetunnel-b2h.pages.dev/changelog/post/2026-02-27-radar-pq-key-transparency/)  
[ Radar ](https://edgetunnel-b2h.pages.dev/radar/)  
[**Radar**](https://edgetunnel-b2h.pages.dev/radar/) now tracks post-quantum encryption support on origin servers, provides a tool to test any host for post-quantum compatibility, and introduces a Key Transparency dashboard for monitoring end-to-end encrypted messaging audit logs.  
#### Post-quantum origin support  
The new [Post-Quantum](https://edgetunnel-b2h.pages.dev/api/resources/radar/subresources/post%5Fquantum/) API provides the following endpoints:

  * [/post\_quantum/tls/support](https://edgetunnel-b2h.pages.dev/api/resources/radar/subresources/post%5Fquantum/subresources/tls/methods/support/) \- Tests whether a host supports post-quantum TLS key exchange.
  * [/post\_quantum/origin/summary/{dimension}](https://edgetunnel-b2h.pages.dev/api/resources/radar/subresources/post%5Fquantum/methods/summary/) \- Returns origin post-quantum data summarized by key agreement algorithm.
  * [/post\_quantum/origin/timeseries\_groups/{dimension}](https://edgetunnel-b2h.pages.dev/api/resources/radar/subresources/post%5Fquantum/methods/timeseries%5Fgroups/) \- Returns origin post-quantum timeseries data grouped by key agreement algorithm.  
The new [Post-Quantum Encryption ↗](https://radar.cloudflare.com/post-quantum) page shows the share of customer origins supporting [X25519MLKEM768](https://edgetunnel-b2h.pages.dev/ssl/post-quantum-cryptography/pqc-support/#x25519mlkem768), derived from daily automated TLS scans of TLS 1.3-compatible origins. The scanner tests for algorithm support rather than the origin server's configured preference.  
![Screenshot of the origin post-quantum support graph on Radar](https://edgetunnel-b2h.pages.dev/_astro/pq-origin-support.Bn5Dw_It_Z12sKNz.webp)  
A host test tool allows checking any publicly accessible website for post-quantum encryption compatibility. Enter a hostname and optional port to see whether the server negotiates a post-quantum key exchange algorithm.  
![Screenshot of the post-quantum host test tool on Radar](https://edgetunnel-b2h.pages.dev/_astro/pq-host-test.dRqwoOvo_Z2hjMhW.webp)  
#### Key Transparency  
A new [Key Transparency ↗](https://radar.cloudflare.com/key-transparency) section displays the audit status of Key Transparency logs for end-to-end encrypted messaging services. The page launches with two monitored logs: WhatsApp and Facebook Messenger Transport.  
Each log card shows the current status, last signed epoch, last verified epoch, and the root hash of the Auditable Key Directory tree. The data is also available through the [Key Transparency Auditor API](https://edgetunnel-b2h.pages.dev/key-transparency/api/).  
![Screenshot of the Key Transparency dashboard on Radar](https://edgetunnel-b2h.pages.dev/_astro/key-transparency-dashboard.DNQgLsb0_25IWgQ.webp)  
Learn more about these features in our [blog post ↗](https://blog.cloudflare.com/radar-origin-pq-key-transparency-aspa) and check out the [Post-Quantum Encryption ↗](https://radar.cloudflare.com/post-quantum) and [Key Transparency ↗](https://radar.cloudflare.com/key-transparency) pages to explore the data.

Feb 26, 2026
1. ### [Asynchronous stale-while-revalidate](https://edgetunnel-b2h.pages.dev/changelog/post/2026-02-26-async-stale-while-revalidate/)  
[ Cache / CDN ](https://edgetunnel-b2h.pages.dev/cache/)  
Cloudflare's [stale-while-revalidate](https://edgetunnel-b2h.pages.dev/cache/concepts/cache-control/#revalidation) support is now fully asynchronous. Previously, the first request for a stale (expired) asset in cache had to wait for an origin response, after which that visitor received a REVALIDATED or EXPIRED status. Now, the first request after the asset expires triggers revalidation in the background and immediately receives stale content with an UPDATING status. All following requests also receive stale content with an `UPDATING` status until the origin responds, after which subsequent requests receive fresh content with a `HIT` status.  
`stale-while-revalidate` is a `Cache-Control` directive set by your origin server that allows Cloudflare to serve an expired cached asset while a fresh copy is fetched from the origin.  
Asynchronous revalidation brings:

  * **Lower latency**: No visitor is waiting for the origin when the asset is already in cache. Every request is served from cache during revalidation.
  * **Consistent experience**: All visitors receive the same cached response during revalidation.
  * **Reduced error exposure**: The first request is no longer vulnerable to origin timeouts or errors. All visitors receive a cached response while revalidation happens in the background.  
#### Availability  
This change is live for all Free, Pro, and Business zones. Approximately 75% of Enterprise zones have been migrated, with the remaining zones rolling out throughout the quarter.  
#### Get started  
To use this feature, make sure your origin includes the `stale-while-revalidate` directive in the `Cache-Control` header. Refer to the [Cache-Control documentation](https://edgetunnel-b2h.pages.dev/cache/concepts/cache-control/#revalidation) for details.

```json
{"@context":"https://schema.org","@type":"BlogPosting","@id":"https://edgetunnel-b2h.pages.dev/changelog/16/#page","headline":"Changelogs | Cloudflare Docs","url":"https://edgetunnel-b2h.pages.dev/changelog/16/","inLanguage":"en","image":"https://edgetunnel-b2h.pages.dev/cf-twitter-card.png","publisher":{"@type":"Organization","name":"Cloudflare","url":"https://www.cloudflare.com/"},"isPartOf":{"@type":"WebSite","@id":"https://edgetunnel-b2h.pages.dev/#website","name":"Cloudflare Docs","url":"https://edgetunnel-b2h.pages.dev/"}}
```
