{"slug":"cloudflare-os-access","verification":{"valid":false,"broken_at":2,"reason":"hash mismatch"},"count":23,"sources":[{"id":"s1","type":"specification","url":"https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/","title":"Authorization cookie","publisher":"Cloudflare","quote":"When you protect a site with Cloudflare Access, Cloudflare checks every HTTP request bound for that site to ensure that the request has a valid `CF_Authorization` cookie.","summary":"Specifies the browser session cookie checked on protected HTTP requests.","claim_ids":["c1","c2"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"genesis","hash":"4772a7e4fab4e24aa6a452a69cac536c0d97bdbf0d3c7e563d7f3ac63520aefa"},{"id":"s2","type":"specification","url":"https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/application-token/","title":"Application token","publisher":"Cloudflare","quote":"Validation of the header alone is not sufficient — the JWT and signature must be confirmed to avoid identity spoofing.","summary":"Defines the signed application token forwarded to an origin and warns against trusting an unverified header.","claim_ids":["c1","c2"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"4772a7e4fab4e24aa6a452a69cac536c0d97bdbf0d3c7e563d7f3ac63520aefa","hash":"f9c66f5527e8d5372e10d980921fddb7d25d438d46eea8292d8c2138f0262056"},{"id":"s3","type":"specification","url":"https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/validating-json/","title":"Validate JWTs","publisher":"Cloudflare","quote":"We recommend validating the `Cf-Access-Jwt-Assertion` header instead of the `CF_Authorization` cookie, since the cookie is not guaranteed to be passed.","summary":"Documents origin JWT validation and the two-key rotation behavior of the team JWKS.","claim_ids":["c1","c10","c11","c2"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"f9c66f5527e8d5372e10d980921fddb7d25d438d46eea8292d8c2138f0262056","hash":"0203131b199a02c6e39830fe36dd1cbd9057c86a3f71e338568f663c62d14349"},{"id":"s4","type":"publisher_documentation","url":"https://developers.cloudflare.com/cloudflare-one/access-controls/policies/","title":"Access policies","publisher":"Cloudflare","quote":"The Bypass action in Cloudflare Access disables Access enforcement for specific traffic.","summary":"Defines Allow, Block, Bypass and Service Auth behavior, including the loss of Access logs on bypassed traffic.","claim_ids":["c4","c5"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"0203131b199a02c6e39830fe36dd1cbd9057c86a3f71e338568f663c62d14349","hash":"49ba1d224dd549423687fdbd50f6bee94ca2431896f043e2e9245f59ef55eb04"},{"id":"s5","type":"publisher_documentation","url":"https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/service-tokens/","title":"Service tokens","publisher":"Cloudflare","quote":"Make sure to set the policy action to Service Auth; otherwise, Access will prompt for an identity provider login.","summary":"Explains service-token creation, the two default headers, single-header mode and Service Auth policy requirement.","claim_ids":["c5","c7"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"49ba1d224dd549423687fdbd50f6bee94ca2431896f043e2e9245f59ef55eb04","hash":"baa2144b975ef35a40c9228f989d2ec997eead832277982c8f08675b9bf11005"},{"id":"s6","type":"publisher_documentation","url":"https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/self-hosted-public-app/","title":"Add a self-hosted application","publisher":"Cloudflare","quote":"Access applications are deny by default.","summary":"Gives the dashboard creation sequence and default-deny posture for self-hosted applications.","claim_ids":["c3"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"baa2144b975ef35a40c9228f989d2ec997eead832277982c8f08675b9bf11005","hash":"cf61155f6c68dffe4621d724256d99f619aaaf598429f0461a8c87066d623e61"},{"id":"s7","type":"publisher_documentation","url":"https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/create/","title":"Create an Access application","publisher":"Cloudflare API","quote":"Adds a new application to Access.","summary":"Primary REST reference for creating an Access application.","claim_ids":["c13","c6"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"cf61155f6c68dffe4621d724256d99f619aaaf598429f0461a8c87066d623e61","hash":"abf2eea94b155e2279504d0db7e63d4bdb9d52619a47dd555b5c154da691d821"},{"id":"s8","type":"publisher_documentation","url":"https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/service_tokens/methods/create/","title":"Create a service token","publisher":"Cloudflare API","quote":"This is the only time you can get the Client Secret. If you lose the Client Secret, you will have to create a new Service Token.","summary":"Primary REST reference for service-token creation and its one-time secret.","claim_ids":["c13","c6"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"abf2eea94b155e2279504d0db7e63d4bdb9d52619a47dd555b5c154da691d821","hash":"f18f12824a21b0068e0a16b9b57378d60c7a568ac38ea6cf57afd825f9bf9d7b"},{"id":"s9","type":"publisher_documentation","url":"https://www.cloudflare.com/plans/zero-trust-services/","title":"Zero Trust services plans","publisher":"Cloudflare","quote":"$7 user / month","summary":"Current plan page listing Free for teams under 50 and pay-as-you-go at seven dollars per user per month.","claim_ids":["c16"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"f18f12824a21b0068e0a16b9b57378d60c7a568ac38ea6cf57afd825f9bf9d7b","hash":"3f91577a338eff7d436144d74712908d49f0ec34f6f96c3dcf395085a1b4d8e2"},{"id":"s10","type":"publisher_documentation","url":"https://developers.cloudflare.com/cloudflare-one/remote-browser-isolation/","title":"Remote Browser Isolation","publisher":"Cloudflare","quote":"Cloudflare Browser Isolation is available as an add-on for Cloudflare One plans.","summary":"Current documentation classifies browser isolation as an add-on without supplying the historical ten-dollar figure used by an operator in 2023.","claim_ids":["c17"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"3f91577a338eff7d436144d74712908d49f0ec34f6f96c3dcf395085a1b4d8e2","hash":"8bd679d7a822598b84c0c199113cfb07ab68f9ef0ab81e336ec5c5e657d67c2a"},{"id":"s11","type":"publisher_documentation","url":"https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/","title":"Cloudflare Tunnel","publisher":"Cloudflare","quote":"Cloudflare Tunnel provides you with a secure way to connect your resources to Cloudflare without a publicly routable IP address.","summary":"Defines the private-origin side of the Tunnel-plus-Access pattern.","claim_ids":["c19"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"8bd679d7a822598b84c0c199113cfb07ab68f9ef0ab81e336ec5c5e657d67c2a","hash":"19b3957680495679c4ddc81d9b095aa0b53a224d33ccb28e9b6c7bffae692dd9"},{"id":"s12","type":"repository","url":"https://github.com/panva/jose","title":"panva/jose","publisher":"GitHub","author":"Filip Skokan and contributors","quote":"`jose` is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), and JSON Web Key Set (JWKS).","summary":"Repository for the standards-based JWT/JWKS library used in the origin-verification example.","claim_ids":["c10"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"19b3957680495679c4ddc81d9b095aa0b53a224d33ccb28e9b6c7bffae692dd9","hash":"0db27a53b6c523a179cc2c6743bbd42fa32dcd79ad0acecde15f1a96dfe1e7a4"},{"id":"p1","type":"github","url":"https://github.com/jarnedemeulemeester/findroid/issues/1016","title":"Add support for Cloudflare Access Service Tokens (Custom Headers)","author":"kennypy","publisher":"GitHub — jarnedemeulemeester/findroid","date":"2025-07-20","quote":"While browser access works (via Google SSO), the app fails because it can’t pass the required authentication headers to bypass Cloudflare Access. This limits Findroid to LAN-only use","summary":"A native Jellyfin client cannot use an Access-fronted deployment because it lacks a custom-header extension point.","claim_ids":["c8"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"0db27a53b6c523a179cc2c6743bbd42fa32dcd79ad0acecde15f1a96dfe1e7a4","hash":"4733182f1284165d252fb9053e816b99165ebe4433fefae1db2bf19fb4648a19"},{"id":"p2","type":"github","url":"https://github.com/argoproj-labs/mcp-for-argocd/issues/115","title":"Support custom HTTP headers on outbound ArgoCD API requests","author":"hippiuS","publisher":"GitHub — argoproj-labs/mcp-for-argocd","date":"2026-05-13","quote":"Requests bypass the proxy auth and get a 302 to the SSO page (which a non-browser MCP client can't follow) or a 403.","summary":"An MCP client cannot reach ArgoCD behind Access without a way to supply service-token headers.","claim_ids":["c8"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"4733182f1284165d252fb9053e816b99165ebe4433fefae1db2bf19fb4648a19","hash":"a0ef23ca39c941abb679fb186e7773392ffcd601f4802d953f767ec8fb63c31b"},{"id":"p3","type":"independent_measurement","url":"https://github.com/dataGriff/outcome-app-pattern-whiskey/issues/4","title":"Give Access service-token callers a usable identity","author":"dataGriff","publisher":"GitHub — dataGriff/outcome-app-pattern-whiskey","date":"2026-07-12","quote":"Access service-token JWTs carry an empty `sub` and no email, so a machine caller has no user id to write reviews by and no admin standing — the post-deploy smoke breaks the moment Access is enforced.","summary":"An independent implementation report showing the application-level identity gap after edge authentication succeeds.","claim_ids":["c9"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"a0ef23ca39c941abb679fb186e7773392ffcd601f4802d953f767ec8fb63c31b","hash":"55affd12c300f72e0bbe71483ff01c7e87a3ab2c104d6d0fc1c0436ddb81fa69"},{"id":"p4","type":"github","url":"https://github.com/lesbass/ai-newsroom/issues/4","title":"Cloudflare Access blocker prevents Paperclip API operations","author":"lesbass","publisher":"GitHub — lesbass/ai-newsroom","date":"2026-07-23","quote":"All Paperclip API calls fail with `RESPONSIBLE_USER_UNAVAILABLE` error due to Cloudflare Access authentication issues.","summary":"A health path works while company-scoped requests fail because the authenticated principal is not mapped into application membership.","claim_ids":["c12"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"55affd12c300f72e0bbe71483ff01c7e87a3ab2c104d6d0fc1c0436ddb81fa69","hash":"911dd108ce3d5371cf52e5aaa9d8a6a8bef8655300a7583147a7a952eff0d21d"},{"id":"p5","type":"people","url":"https://news.ycombinator.com/item?id=31332325","title":"Comment on Cloudflare's Access console","author":"systemvoltage","publisher":"Hacker News","date":"2022-05-10","quote":"Well, except the Access/ZeroTrust app. Not sure why that's a different app that takes 10 seconds to redirect a bazillion times.","summary":"A dated operator report criticizing the Zero Trust console's speed and redirect behavior; used only as historical console evidence.","claim_ids":["c18"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"911dd108ce3d5371cf52e5aaa9d8a6a8bef8655300a7583147a7a952eff0d21d","hash":"04ec9ea8ea4d88e81c817cde201954fb5f8b6c6fece8c316a92f76928e8e259e"},{"id":"p6","type":"people","url":"https://news.ycombinator.com/item?id=35494875","title":"Comment on Browser Isolation pricing","author":"8organicbits","publisher":"Hacker News","date":"2023-04-08","quote":"CloudFlare remote browsers is a $10/user/month add-on [2].","summary":"A dated operator price observation, explicitly separated from the current plan page.","claim_ids":["c17"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"04ec9ea8ea4d88e81c817cde201954fb5f8b6c6fece8c316a92f76928e8e259e","hash":"b6cf6643b4b70a32625109d5ad6bd13219af98f6cd568d56bd9ea5b62675d78e"},{"id":"p7","type":"people","url":"https://news.ycombinator.com/item?id=41915668","title":"Comment on Tunnel plus Access","author":"tbhb","publisher":"Hacker News","date":"2024-10-22","quote":"I've been experimenting lately with CloudFlare Tunnel + Zero Trust Access as well for exposing only the endpoints I need from an application for local development like webhooks, with the rest of the site locked behind Access.","summary":"A positive operator report of selectively public webhooks with the rest of an application behind Access.","claim_ids":["c19"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"b6cf6643b4b70a32625109d5ad6bd13219af98f6cd568d56bd9ea5b62675d78e","hash":"ddd1547dd20207f94800abab7ddbe9793088cafa0539c00cdb865dc6a31f1a85"},{"id":"r1","type":"runtime_receipt","url":"https://miscsubjects.com/api/articles/cloudflare-os-access","title":"Temporary Access request-path receipt","publisher":"miscsubjects.com","date":"2026-07-26","quote":"302 before Service Auth; 403 after Service Auth; valid service token reached the origin's 404.","summary":"Redacted first-party request sequence proving edge-policy behavior without publishing the application, policy, token ids, team name or secret.","claim_ids":["c20"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"ddd1547dd20207f94800abab7ddbe9793088cafa0539c00cdb865dc6a31f1a85","hash":"a56e74cdc3557f1f5e27886c1e2c0429a04b1bd067afa7df87dfe6208aab091b"},{"id":"r2","type":"runtime_receipt","url":"https://miscsubjects.com/api/articles/cloudflare-os-access","title":"Service application-token receipt","publisher":"miscsubjects.com","date":"2026-07-26","quote":"RS256; type app; audience and common_name present; sub empty; email absent.","summary":"Bounded fields recovered from the temporary service-token JWT.","claim_ids":["c9"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"a56e74cdc3557f1f5e27886c1e2c0429a04b1bd067afa7df87dfe6208aab091b","hash":"6220755faae91395eb4bd6ae3ae278f57f7880e1fefacd7cfdee91428e3bd237"},{"id":"r3","type":"runtime_receipt","url":"https://miscsubjects.com/api/articles/cloudflare-os-access","title":"Fresh JWKS and owner-gate receipt","publisher":"miscsubjects.com","date":"2026-07-26","quote":"JWKS: HTTP 200, 4,914 bytes, two RSA/RS256 signing keys. /admin without a credential: HTTP 401, 47 bytes, keys error and login.","summary":"Fresh first-party reads of the public team JWKS and the application's bounded unauthorized machine response.","claim_ids":["c11","c15","c21"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"6220755faae91395eb4bd6ae3ae278f57f7880e1fefacd7cfdee91428e3bd237","hash":"1e374e893edeb894b11e1241a7d7e97c4781c9eaec085cf72c928c0b9cb8537a"},{"id":"r4","type":"runtime_receipt","url":"https://miscsubjects.com/api/articles/cloudflare-os-access","title":"Temporary resource deletion proof","publisher":"miscsubjects.com","date":"2026-07-26","quote":"Both authenticated lists succeeded; exact application and service-token ids and names were absent.","summary":"Fresh post-cleanup list proof for the two independent Access collections. No failed response was treated as absence.","claim_ids":["c13","c14"],"accessed_at":"2026-07-26T06:11:43.106Z","prev":"1e374e893edeb894b11e1241a7d7e97c4781c9eaec085cf72c928c0b9cb8537a","hash":"1239356d0617555ed0837ce8d37b72db5a877d7c84b8f9f5f05a089fd787b615"}]}