Zum Inhalt springen

Cloudflare One Updates & Release Notes

319 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Cloudflare One, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neue Erstellungsoberfläche für Access-Anwendungen und Gateway-Policies

Der Gateway-Rule-Builder und der Builder für selbst gehostete Access-Anwendungen im Cloudflare-One-Dashboard wurden mit klarerer Bedienung, Wirefilter-Bearbeitung, Vorschau, weniger Schritten und Inline-Policy-Erstellung neu gestaltet.

The Cloudflare One dashboard now features redesigned builders for two core workflows: creating Gateway policies and configuring self-hosted Access applications.

Gateway rule builder

The Gateway rule builder now features a redesigned user experience, bringing it in line with the Access policy builder experience. Improvements include:

  • Streamlined UX with clearer states and improved user interactions
  • Wirefilter editing for viewing and editing Gateway rules directly from wirefilter expressions
  • Preview state to review the impact of your policy in a simple graphic

New Gateway rule builder

For more information, refer to Traffic policies.

Access application builder for self-hosted apps

The self-hosted Access application builder now offers a simplified creation workflow with fewer steps from setup to save. Improvements include:

  • New application selection experience that makes choosing the right application type before you begin easier.
  • Streamlined creation flow with fewer clicks to build and save an application
  • Inline policy creation for building Access policies directly within the application creation flow …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DEM: Konsistenterer „Last seen“-Zeitstempel für Cloudflare One Client

Der „Last seen“-Zeitstempel von Cloudflare One Client-Geräten wird im Dashboard nun konsistenter angezeigt.

The last seen timestamp for Cloudflare One Client devices is now more consistent across the dashboard. IT teams will see more consistent information about the most recent client event between a device and Cloudflare's network.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP: Einstellungen auf Account-Ebene

Erweiterte DLP-Einstellungen wie OCR, KI-Kontextanalyse und Payload-Masking lassen sich nun auf Account-Ebene für alle DLP-Profile konfigurieren, wobei auf Profilebene aktivierte Einstellungen automatisch übernommen werden und die profilbezogenen Einstellungen künftig entfallen.

Account-level DLP settings are now available in Cloudflare One. You can now configure advanced DLP settings at the account level, including OCR, AI context analysis, and payload masking. This provides consistent enforcement across all DLP profiles and simplifies configuration management.

Key changes:

  • Consistent enforcement: Settings configured at the account level apply to all DLP profiles
  • Simplified migration: Settings enabled on any profile are automatically migrated to account level
  • Deprecation notice: Profile-level advanced settings will be deprecated in a future release

Migration details:

During the migration period, if a setting is enabled on any profile, it will automatically be enabled at the account level. This means profiles that previously had a setting disabled may now have it enabled if another profile in the account had it enabled.

Settings are evaluated using OR logic - a setting is enabled if it is turned on at either the account level or the profile level. However, profile-level settings cannot be enabled when the account-level setting is off.

For more details, refer to the DLP settings documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Einführung von Cloudflare Mesh

Cloudflare Mesh ist verfügbar und verbindet Server, Laptops und Telefone über post-quantum-verschlüsselte private Netzwerke mit Mesh-IPs, CIDR-Routen und Hochverfügbarkeit, wobei Gateway-Netzwerkrichtlinien und Posture Checks auf alle Verbindungen angewendet werden.

Cloudflare Mesh is now available (blog post ↗︎). Mesh connects your services and devices with post-quantum encrypted networking, allowing you to route traffic privately between servers, laptops, and phones over TCP, UDP, and ICMP.

Cloudflare Mesh network map showing nodes and devices connected through Cloudflare

What Cloudflare Mesh does

  • Assigns a private Mesh IP to every enrolled device and node.
  • Enables any participant to reach any other participant by IP — including client-to-client, without deploying any infrastructure.
  • Supports CIDR routes for subnet routing through Mesh nodes.
  • Supports high availability with active-passive replicas for nodes with routes.
  • All traffic flows through Cloudflare, so Gateway network policies, device posture checks, and access rules apply to every connection.

What changed

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP erkennt Cloudflare-API-Tokens

Das DLP-Profil „Credentials and Secrets“ enthält drei neue Einträge zur Erkennung von Cloudflare-API-Schlüsseln und -Tokens mit den Präfixen cfk_, cfut_ und cfat_, wobei vor der Formatumstellung erzeugte Zugangsdaten nicht erkannt werden.

The Credentials and Secrets DLP profile now includes three new predefined entries for detecting Cloudflare API credentials:

Entry name

Token prefix

Detects

Cloudflare User API Key

cfk_

User-scoped API keys

Cloudflare User API Token

cfut_

User-scoped API tokens

Cloudflare Account Owned API Token

cfat_

Account-scoped API tokens

These detections target the new Cloudflare API credential format, which uses a structured prefix and a CRC32 checksum suffix. The identifiable prefix makes it possible to detect leaked credentials with high confidence and low false positive rates — no surrounding context such as Authorization: Bearer headers is required.

Credentials generated before this format change will not be matched by these entries.

How to enable Cloudflare API token detections

  1. In the Cloudflare dashboard ↗︎, go to Zero Trust > DLP > DLP Profiles.
  2. Select the Credentials and Secrets profile.
  3. Turn on one or more of the new Cloudflare API token entries.
  4. Use the profile in a Gateway HTTP policy to log or block traffic containing these credentials.

Example policy:

Selector

Operator

Value

Action

DLP Profile

in

Credentials and Secrets

Block …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP: Darstellung sensibler Daten in Payload-Logs konfigurierbar

In den DLP-Einstellungen lässt sich über „Payload log masking“ nun zwischen Full Mask (Standard, mit erhaltener Zeichenanzahl), Partial Mask und Clear Text wählen, wobei die Auswahl vor der Verschlüsselung angewendet wird.

You can now configure how sensitive data matches are displayed in your DLP payload match logs — giving your incident response team the context they need to validate alerts without compromising your security posture.

To get started, go to the Cloudflare dashboard ↗︎, select Zero Trust > Data loss prevention > DLP settings and find the Payload log masking card.

Previously, all DLP payload logs used a single masking mode that obscured matched data entirely and hid the original character count, making it difficult to distinguish true positives from false positives. This update introduces three options:

  • Full Mask (default): Masks the match while preserving character count and visual formatting (for example, ***-**-**** for a Social Security Number). This is an improvement over the previous default, which did not preserve character count.
  • Partial Mask: Reveals 25% of the matched content while masking the remainder (for example, ***-**-6789).
  • Clear Text: Stores the full, unmasked violation for deep investigation (for example, 123-45-6789).

Important: The masking level you select is applied at detection time, before the payload is encrypted. This means the chosen format is what your team will see after decrypting the log with your private key — the existing encryption workflow is unchanged. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Browser Isolation: Canvas Remoting verbessert Leistung von Produktivitäts-Apps

Remote Browser Isolation sendet für HTML5-Canvas-Anwendungen nun Vektor-Zeichenbefehle statt Bitmaps, was laut Text die Bandbreite stark senkt, standardmäßig aktiv ist und nur 2D-Canvas unterstützt.

Remote Browser Isolation now supports Canvas Remoting, improving performance for HTML5 Canvas applications by sending vector draw commands instead of rasterized bitmaps.

Key improvements

  • 10x bandwidth reduction: Microsoft Word and other Office apps use 90% less bandwidth
  • Smooth performance: Google Sheets maintains consistent 30fps rendering
  • Responsive terminals: Web-based development environments and AI notebooks work in real-time
  • Zero configuration: Enabled by default for all Browser Isolation customers

How it works

Instead of sending rasterized bitmaps for every Canvas update, Browser Isolation now:

  1. Captures Canvas draw commands at the source
  2. Converts them to lightweight vector instructions
  3. Renders Canvas content on the client

This reduces bandwidth from hundreds of kilobytes per second to tens of kilobytes per second.

Managing Canvas Remoting

To temporarily disable for troubleshooting:

  • Right-click the isolated webpage background
  • Select Disable Canvas Remoting
  • Re-enable the same way by selecting Enable Canvas Remoting

Limitations

Currently supports 2D Canvas contexts only. WebGL and 3D graphics applications continue using bitmap rendering. For more information, refer to Canvas Remoting.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

CASB: Posture Findings per Webhook senden

Mit CASB-Webhooks in Cloudflare One lassen sich Posture-Finding-Instanzen an externe Systeme wie Chat-Plattformen, Ticketing, SIEM oder SOAR senden, mit mehreren Authentifizierungsoptionen und Testversand.

You can now use CASB webhooks in Cloudflare One to send posture finding instances to external systems such as chat platforms, ticketing systems, SIEMs, SOAR tools, and custom automation services.

This gives security teams a simple way to route CASB posture findings into the tools and workflows they already use for triage and response.

To get started, go to Integrations > Webhooks in the Cloudflare One dashboard to create a webhook destination. After you configure a webhook, open a posture finding instance and select Send webhook to send it.

Key capabilities

  • Flexible authentication — Configure destinations using None, Basic Auth, Bearer Auth, Static Headers, or HMAC-Signing.
  • Built-in testing — Use Test delivery to send a test request before sending a live finding instance.
  • Posture finding workflows — Send posture finding instances directly from the finding details workflow in Cloud & SaaS findings.
  • HTTPS destinations — Configure webhook destinations with public https:// URLs.

Learn more

CASB webhooks are now available in Cloudflare One.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Risk Score: Nutzer-Risikobewertung für riskantes Surfverhalten

Das User Risk Scoring berücksichtigt nun Gateway-DNS-Daten und erhöht den Risikowert von Nutzern, die gefährliche oder risikoreiche Domains aufrufen, über zwei neue Risikoverhalten, auch wenn der Zugriff blockiert wurde.

Cloudflare One's User Risk Scoring now incorporates direct signals from Gateway DNS traffic patterns. This update allows security teams to automatically elevate a user's risk score when they visit high-risk or malicious domains, providing a more holistic view of internal threats.

Why this matters

Browsing activity is a primary indicator of potential compromise. By tying Gateway DNS logs to specific users, administrators can now flag individuals interacting with:

  • Security threats: Domains associated with malware, phishing, or command-and-control (C2) centers.
  • High-risk content: Categories such as questionable content or violence that may violate corporate compliance.

Even if a Gateway policy is set to Block the traffic, the interaction is still captured as a "hit" to ensure the user's risk profile reflects the attempted activity.

New risk behaviors

Two new behaviors are now available in the dashboard:

  • Suspicious Security Domain Visited: Triggers when a user visits a domain in the security threats or security risk categories.
  • High risk domain visited: Triggers when a user visits domains categorized as questionable content, violence, or CIPA.

To learn more and get started, refer to the User Risk Scoring documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.3.851.0

Die neue stabile Windows-Version 2026.3.851.0 des Cloudflare One Client behebt unter anderem Probleme bei der Tunnel-Initialisierung und beim Verbindungsaufbau und ergänzt QUIC-Metriken in den Diagnoselogs.

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.

This release contains minor fixes and improvements.

The next stable release for Windows will introduce the new Cloudflare One Client UI, providing a cleaner and more intuitive design as well as easier access to common actions and information.

Changes and improvements

  • Fixed an issue causing Windows client tunnel interface initialization failure which prevented clients from establishing a tunnel for connection.
  • Consumer-only CLI commands are now clearly distinguished from Zero Trust commands.
  • Added detailed QUIC connection metrics to diagnostic logs for better troubleshooting.
  • Added monitoring for tunnel statistics collection timeouts.
  • Switched tunnel congestion control algorithm for local proxy mode to Cubic for improved reliability across platforms.
  • Fixed packet capture failing on tunnel interface when the tunnel interface is renamed by SCCM VPN boundary support.
  • Fixed unnecessary registration deletion caused by RDP connections in multi-user mode.
  • Fixed increased tunnel interface start-up time due to a race between duplicate address detection (DAD) and disabling NetBT.
  • Fixed tunnel failing to connect when the system DNS search list contains unexpected characters. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: Triage-Status für User Submissions

Die Tabelle der User Submissions in Email security zeigt nun eine Status-Spalte mit Unreviewed, Reviewed und Escalated, die für alle Pakete automatisch ohne weitere Konfiguration verfügbar ist.

Cloudflare Email security now supports Triage Status Tracking for User Submissions. This enhancement gives SOC teams a streamlined way to track, manage, and prioritize user-submitted emails directly within the Cloudflare One dashboard.

  • The User Submissions table now includes a Status column with three states: Unreviewed (new submissions awaiting triage), Reviewed (submissions assessed by the SOC team), and Escalated (submissions escalated to team submissions for further investigation). Analysts can quickly update statuses and filter the table to focus on what needs attention.
  • SOC teams can now organize their triage workflows, avoid duplicate reviews, and make sure critical threats get escalated for deeper investigation—bringing order to the chaos of high-volume submission management.

Triage Status Tracking is automatically available for all Email security customers using the user submissions feature. No additional configuration is required; customers just need to make sure user submissions are being sent to their user submission aliases.

This applies to all Email security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Link Aggregation (LACP) für Cloudflare One Appliance

Die Cloudflare One Appliance unterstützt in der Beta nun LACP und kann bis zu sechs physische LAN-Ports zu einer logischen Schnittstelle bündeln, um Bandbreite zu erhöhen und Ausfallpunkte zu vermeiden.

Cloudflare One Appliance now supports Link Aggregation Control Protocol (LACP), allowing you to bundle up to six physical LAN ports into a single logical interface. Link aggregation increases available bandwidth and eliminates single points of failure on the LAN side of the appliance.

This feature is available in beta on physical appliance hardware with the latest OS. No entitlement is required.

To configure a Link Aggregation Group, refer to Configure link aggregation groups.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: DANE-Unterstützung für MX-Deployments

Regionale MX-Hostnamen von Cloudflare Email Security veröffentlichen nun DNSSEC-gestützte DANE-TLSA-Records, sodass DANE-fähige SMTP-Sender Zertifikate automatisch und ohne zusätzliche Konfiguration validieren können.

Cloudflare Email Security now supports DANE (DNS-based Authentication of Named Entities) for MX deployments. This enhancement strengthens email transport security by enabling DNSSEC-backed certificate verification for our regional MX records.

  • Regional MX hostnames now publish DANE TLSA records backed by DNSSEC, enabling DANE-capable SMTP senders to cryptographically validate certificate identities before establishing TLS connections—moving beyond opportunistic encryption to verified encrypted delivery.
  • DANE support is automatically available for all customers using regional MX deployments. No additional configuration is required; DANE-capable mail infrastructure will automatically validate MX certificates using the published records.

This applies to all Email Security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Organizations ist als öffentliche Beta für Enterprise verfügbar

Enterprise-Kunden können mit der öffentlichen Beta von Organizations mehrere Accounts, Mitglieder und geteilte WAF- oder Gateway-Policies zentral verwalten, wobei eine Organization bis zu 500 Accounts und 5000 Zonen unterstützt.

We're announcing the public beta of Organizations for enterprise customers, a new top-level Cloudflare container that lets Cloudflare customers manage multiple accounts, members, analytics, and shared policies from one centralized location.

What's New

Organizations [BETA]: Organizations are a new top-level container for centrally managing multiple accounts. Each Organization supports up to 500 accounts and 5000 zones, giving larger teams a single place to administer resources at scale.

Self-serve onboarding: Enterprise customers can create an Organization in the dashboard and assign accounts where they are already Super Administrators.

Centralized Account Management: At launch, every Organization member has the Organization Super Admin role. Organization Super Admins can invite other users and manage any child account under the Organization implicitly. Shared policies: Share WAF or Gateway policies across multiple accounts within your Organization to simplify centralized policy management. Implicit access: Members of an Organization automatically receive Super Administrator permissions across child accounts, removing the need for explicit membership on each…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.3.846.0

Die neue stabile macOS-Version 2026.3.846.0 des Cloudflare One Client enthält Fehlerbehebungen, etwa für leere MDM-Dateien, unresponsive Local-Proxy-Verbindungen und Profilwechsel, sowie zusätzliche Diagnosemetriken.

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page.

This release contains minor fixes and improvements.

The next stable release for macOS will introduce the new Cloudflare One Client UI, providing a cleaner and more intuitive design as well as easier access to common actions and information.

Changes and improvements

  • Empty MDM files are now rejected instead of being incorrectly accepted as a single MDM config.
  • Fixed an issue in local proxy mode where the client could become unresponsive due to upstream connection timeouts.
  • Fixed an issue where the emergency disconnect status of a prior organization persisted after a switch to a different organization.
  • Consumer-only CLI commands are now clearly distinguished from Zero Trust commands.
  • Added detailed QUIC connection metrics to diagnostic logs for better troubleshooting.
  • Added monitoring for tunnel statistics collection timeouts.
  • Switched tunnel congestion control algorithm for local proxy mode to Cubic for improved reliability across platforms.
  • Fixed initiating managed network detections checks when no network is available, which caused device profile flapping.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Linux 2026.3.846.0

Die neue stabile Linux-Version 2026.3.846.0 des Cloudflare One Client enthält Fehlerbehebungen, etwa für leere MDM-Dateien, unresponsive Local-Proxy-Verbindungen und Profilwechsel, sowie zusätzliche Diagnosemetriken.

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.

This release contains minor fixes and improvements.

The next stable release for Linux will introduce the new Cloudflare One Client UI, providing a cleaner and more intuitive design as well as easier access to common actions and information.

Changes and improvements

  • Empty MDM files are now rejected instead of being incorrectly accepted as a single MDM config.
  • Fixed an issue in local proxy mode where the client could become unresponsive due to upstream connection timeouts.
  • Fixed an issue where the emergency disconnect status of a prior organization persisted after a switch to a different organization.
  • Consumer-only CLI commands are now clearly distinguished from Zero Trust commands.
  • Added detailed QUIC connection metrics to diagnostic logs for better troubleshooting.
  • Added monitoring for tunnel statistics collection timeouts.
  • Switched tunnel congestion control algorithm for local proxy mode to Cubic for improved reliability across platforms.
  • Fixed initiating managed network detections checks when no network is available, which caused device profile flapping.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Sitzungsverwaltung für MCP-Server-Portale

Nutzer von MCP server portals können in der laufenden Sitzung über eine per MCP elicitation gelieferte Autorisierungs-URL zur Serverauswahl zurückkehren, um Server zu aktivieren oder zu deaktivieren sowie sich abzumelden und neu zu authentifizieren.

MCP server portals support in-session management of upstream MCP server connections. Users can return to the server selection page at any time to enable or disable servers, reauthenticate, or change which data a server has access to — all without leaving their MCP client.

To return to the server selection page, ask your AI agent with a prompt like "take me back to the server selection page." The portal responds with an authorization URL via MCP elicitation ↗︎ that you open in your browser:

https://<subdomain>.<domain>/authorize?elicitationId=<ELICITATION_ID>

From the server selection page you can:

  • Enable or disable servers — Toggle individual upstream MCP servers on or off. Disabling a server removes its tools from the active session, which reduces context window usage.
  • Log out and reauthenticate — Log out of a server and log back in to change which data the server has access to, or to reauthenticate with different permissions.

Users can also enable or disable a server inline by asking their AI agent directly, for example "enable the wiki server" or "disable my Jira server." …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Überarbeitete Logs-Oberfläche für Access und Gateway

Die Access-Authentifizierungslogs und Gateway-Aktivitätslogs (DNS, Network, HTTP) haben eine neue Oberfläche mit Filtern nach Feldwerten, anpassbaren Spalten, Detailansicht und Option zur klassischen Ansicht.

Access authentication logs and Gateway activity logs (DNS, Network, and HTTP) now feature a refreshed user interface that gives you more flexibility when viewing and analyzing your logs.

Screenshot of the new logs UI showing DNS query logs with customizable columns and filtering options

The updated UI includes:

  • Filter by field - Select any field value to add it as a filter and narrow down your results.
  • Customizable fields - Choose which fields to display in the log table. Querying for fewer fields improves log loading performance.
  • View details - Select a timestamp to view the full details of a log entry.
  • Switch to classic view - Return to the previous log viewer interface if needed.

For more information, refer to Access authentication logs and Gateway activity logs.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Code Mode für MCP server portals

MCP server portals unterstützen Code Mode, der einzelne Tool-Definitionen durch ein einziges code-Tool ersetzt und so die Nutzung des Kontextfensters reduziert; er ist standardmäßig auf allen Portalen aktiv und lässt sich unter Access controls > AI controls abschalten.

MCP server portals support Code Mode MCP server patterns, a technique that reduces context window usage by replacing individual tool definitions with a single code execution tool. Code Mode is turned on by default on all portals.

To turn it off, edit the portal in Access controls > AI controls and turn off Code Mode under Basic information.

When Code Mode is active, the portal exposes a single code tool instead of listing every tool from every upstream MCP server. The connected AI agent writes JavaScript that calls typed codemode.* methods for each upstream tool. The generated code runs in an isolated Dynamic Worker environment, keeping authentication credentials and environment variables out of the model context.

To use Code Mode, append ?codemode=search_and_execute to your portal URL when connecting from an MCP client:

https://<subdomain>.<domain>/mcp?codemode=search_and_execute

For more information, refer to Code Mode.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Kontextoptimierung für MCP server portals

MCP server portals bieten über den URL-Parameter optimize_context die Optionen minimize_tools und search_and_execute, die den Token-Verbrauch von Tool-Definitionen im Kontextfenster senken.

MCP server portals support two context optimization options that reduce how many tokens tool definitions consume in the model's context window. Both options are activated by appending the optimize_context query parameter to the portal URL.

minimize_tools

Strips tool descriptions and input schemas from all upstream tools, leaving only their names. The portal exposes a special query tool that agents use to retrieve full definitions on demand. This provides up to 5x savings in token usage.

https://<subdomain>.<domain>/mcp?optimize_context=minimize_tools

search_and_execute

Hides all upstream tools and exposes only two tools: query and execute. The query tool searches and retrieves tool definitions. The execute tool runs the upstream tools in an isolated Dynamic Worker environment. This reduces the initial token cost to a small constant, regardless of how many tools are available through the portal.

https://<subdomain>.<domain>/mcp?optimize_context=search_and_execute

For more information, refer to Optimize context.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One Updates & Release Notes (Cloudflare) – Oktober 2026 (Seite 8) | updatefeed