we_are_coded.by CODE · The world, decoded
БГ
Cloudflare

Cloudflare puts a lock on internal apps in one click

Cloudflare BlogBuilders

The policy now attaches to the application itself, not to the hostname. Which means it also covers the preview URLs somebody always forgets.

In short
  • On 14 August Cloudflare announced attaching Access policies directly to Workers applications.
  • The policy applies to every address of the app, including the service and preview URLs.
  • It can be switched on account wide, so every new app starts locked.
Checked on14 August 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Anyone who has shipped a quick internal tool knows where it leaks. Not through the main address. Through the preview URL you gave one colleague and forgot.

The facts: on 14 August 2026 Cloudflare announced that Access policies can attach directly to a Workers application rather than to a hostname. The check happens before the request reaches your code. Coverage includes custom domains, routes, the service address and preview URLs, and can be narrowed to previews only. It can be enabled account wide, so it applies by default to all applications. In code the signed-in identity is read through ctx.access.getIdentity(), and locally it is tested with a simulated user.

The difference is in the order of things. Until now you ship the app and then remember to fence it. Now it is born fenced and you decide what to open.

Security that needs you to remember it has already arrived late.

We keep a client area and internal panels behind exactly this kind of door. If you have a tool running on a quick fix, this is half an hour of work today.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Cloudflare Blog - Secure all your internal vibe-coded applications in one click
Original: https://wearecoded.com/en/articles/cloudflare-access-workers.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news