Secure all your internal vibe-coded applications — in one click
Cybersecurity Classified by Officially
AI has enabled employees across every team to build applications faster than ever before.
But that speed is also what's keeping every CISO up at night: any employee can build an application, deploy it to the public Internet, and accidentally expose internal work or company data.
Today, we're launching new tools to make it easy to keep your applications hosted on Workers private. You can now apply Cloudflare Access directly to a Worker or to every Worker in your account, so that your applications are behind your company login by default, without relying on each developer to set that up themselves.
You can now:
- Set a policy at the account level to ensure that all preview and production deployments are behind your company login by default.
- Set a policy on a single application to ensure authentication is enforced on every domain associated with it, no matter how it's deployed.
- See exactly who visits your application. Get every authenticated user’s email, name, and groups directly in your code — no JWT (JSON Web Token) validation required.
- Deploy an internal platform where every deployment is private by default. We've open-sourced an example: an internal static site platform where every Worker deployed is private.
Access on Workers: how it works
When you enable Access on a Worker, Cloudflare enforces authentication before any request reaches your application code. It doesn't matter how the request gets to your Worker, whether it's through a custom domain, a route, a workers.dev subdomain, or a preview URL. If Access is on, the user has to authenticate first.
This is an extract. The publication continues at the source.
Read the original at the source: https://blog.cloudflare.com/workers-protected-by-access/
Officially imported this from Cloudflare’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Cloudflare — imported from official source
- Official source
- https://blog.cloudflare.com/rss/ RSS
- Imported
- September 18, 2026 11:34
- Versions
- 1 recorded
- Identity
01KZW0MF4VJTZW3F7601QANQ7Z