← All provider guides

Cloudflare API breaking changes (2025–2026): complete tracker and fixes

cloudflare 48 breaking / deprecation entries 2025–2026

Cloudflare ships API and SDK changes continuously. Most are additive — but the ones that are not can silently break integrations that worked yesterday. This page is the complete, continuously regenerated record of every Cloudflare breaking change and deprecation in the mendapi change database: 48 entries (45 breaking, 3 deprecation), each linked to its upstream source and, where possible, to a concrete fix.

How to read this page

Every entry carries a fixability verdict from the mendapi adjudication pipeline: code-fixable means a mechanical code change repairs the break (38 entries); not code-fixable means the change requires a business decision, credential provisioning, or upstream action that no codemod can produce (10 entries). Entries marked auto-fix pack have a deterministic, gold-tested migration pack that mendapi fix can apply locally.

Am I affected?

Reading a changelog tells you what changed — not whether your code uses the affected surface. The mendapi scanner answers that locally, in about 30 seconds, without any code leaving your machine:

npx mendapi sync
# -> one network call: pulls the change feed into a local database
npx mendapi scan
# -> N findings: file, line, provider, confidence
mendapi deps --match
# -> which of the changes below actually hit your endpoints

See Getting Started for the full workflow and the security model for why zero code upload is the default and only mode.

Complete Cloudflare breaking change timeline

DateChangeRef
2026-08-04 WAF - WAF Release - 2026-08-04
breaking not code-fixable
source
2026-07-31 Cloudflare One Client - Cloudflare One Client for macOS (version 2026.7.1210.1)
breaking not code-fixable
source
2026-07-31 Cloudflare One Client - Cloudflare One Client for Windows (version 2026.7.1210.1)
breaking not code-fixable
source
2026-07-30 Access - Admins can turn on Code Mode by default for MCP portal users
deprecation not code-fixable
source
2026-07-28 Agents, Workers - Cloudflare MCP servers support the new MCP 2026-07-28 Specification
breaking code-fixable
source
2026-07-28 1.1.1.1 - Improved DoH JSON formatting for additional record types
breaking code-fixable
source
2026-07-27 path-removed: /zones/{zone_id}/ssl/recommendation
breaking code-fixable
spec diff
2026-07-27 path-removed: /zones/{zone_id}/firewall-for-ai/settings
breaking code-fixable auto-fix pack
spec diff
2026-07-27 path-removed: /zones/{zone_id}/firewall-for-ai/custom-topics
breaking code-fixable auto-fix pack
spec diff
2026-07-27 path-removed: /users/tenants
breaking code-fixable
spec diff
2026-07-27 path-removed: /system/accounts/{account_tag}/stores/{store_id}/secrets/{secret_id}/duplicate
breaking code-fixable auto-fix pack
spec diff
2026-07-27 path-removed: /system/accounts/{account_tag}/stores/{store_id}/secrets/{secret_id}
breaking code-fixable auto-fix pack
spec diff
2026-07-27 path-removed: /system/accounts/{account_tag}/stores/{store_id}/secrets
breaking code-fixable auto-fix pack
spec diff
2026-07-27 path-removed: /system/accounts/{account_tag}/stores/{store_id}
breaking code-fixable auto-fix pack
spec diff
2026-07-27 path-removed: /system/accounts/{account_tag}/stores
breaking code-fixable auto-fix pack
spec diff
2026-07-27 path-removed: /accounts/{accountId}/resource-library/applications/{id}
breaking code-fixable
spec diff
2026-07-27 path-removed: /accounts/{accountId}/resource-library/applications
breaking code-fixable
spec diff
2026-07-27 path-removed: /accounts/{account_id}/containers
breaking code-fixable
spec diff
2026-07-27 path-removed: /accounts/{account_id}/cloudforce-one/events/queries/alerts/create
breaking code-fixable
spec diff
2026-07-27 path-removed: /accounts/{account_id}/cloudforce-one/events/queries/alerts/{alert_id}
breaking code-fixable
spec diff
2026-07-27 path-removed: /accounts/{account_id}/cloudforce-one/events/queries/alerts
breaking code-fixable
spec diff
2026-07-27 path-removed: /accounts/{account_id}/cloudforce-one/events/{dataset_id}/revert-do
breaking code-fixable
spec diff
2026-07-27 path-removed: /accounts/{account_id}/billing/usage/paygo
breaking code-fixable
spec diff
2026-07-21 Cloudflare Fundamentals - Account Role API deprecated
deprecation code-fixable auto-fix pack
source
2026-07-20 Billing, Workers - Budget alerts now on by default for Pay-as-you-go accounts
breaking not code-fixable
source
2026-07-20 Access - Browser-based login for plaintext HTTP private applications
breaking not code-fixable
source
2026-07-15 KV - Deprecate legacy Workers KV namespace API routes
deprecation code-fixable auto-fix pack
source
2026-07-13 R2 - R2 Data Catalog now supports read-only API tokens
breaking not code-fixable
source
2026-07-08 v7.0.0
breaking code-fixable auto-fix pack
cloudflare-typescript v7: documented SDK-wide migration (fetch API, multi-path-param convention) with an official
source
2026-06-23 v6.5.0
breaking not code-fixable
Additive minor release (new resources email-auth, moq, tenants)
source
2026-04-30 v6.0.0
breaking code-fixable
v6.0.0 release body (25KB, cached) decomposed: renamed client paths, positional-arg-to-params signature changes, and
source
2026-04-15 v6.0.0-beta.2
breaking not code-fixable
Pre-release beta churn (v6.0.0-beta.2)
source
2026-03-31 operation-removed: DELETE /accounts/{account_id}/cloudforce-one/events/{event_id}
breaking code-fixable
spec diff
2026-03-31 path-removed: /accounts/{account_id}/intel/ip-list
breaking code-fixable
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai/run/@hf/thebloke/llamaguard-7b-awq
breaking code-fixable
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai/run/@cf/huggingface/omni-distilbert-sst-2-int8
breaking code-fixable auto-fix pack
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai/run/@cf/google/omni-embeddinggemma-300m
breaking code-fixable auto-fix pack
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai/run/@cf/facebook/omni-detr-resnet-50
breaking code-fixable auto-fix pack
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai/run/@cf/facebook/omni-bart-large-cnn
breaking code-fixable auto-fix pack
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai/run/@cf/baai/ray-bge-large-en-v1.5
breaking code-fixable auto-fix pack
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai/run/@cf/baai/omni-bge-small-en-v1.5
breaking code-fixable auto-fix pack
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai/run/@cf/baai/omni-bge-m3
breaking code-fixable auto-fix pack
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai/run/@cf/baai/omni-bge-large-en-v1.5
breaking code-fixable auto-fix pack
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai/run/@cf/baai/omni-bge-base-en-v1.5
breaking code-fixable auto-fix pack
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai-search/instances/{id}/items/{item_id}
breaking code-fixable
spec diff
2026-03-31 path-removed: /accounts/{account_id}/ai-search/instances/{id}/items
breaking code-fixable
spec diff
2026-01-20 v6.0.0-beta.1
breaking not code-fixable
Pre-release beta churn (v6.0.0-beta.1)
source
2025-10-02 v5.2.0
breaking code-fixable
v5.2.0 removes created_at/updated_at from Zero Trust organization type with no successor fields (commit 4656a4e
source

Automated migration packs for Cloudflare

mendapi ships 6 deterministic migration packs for Cloudflare — verified, idempotent codemods you can apply locally with mendapi fix. Full details in the pack catalog.

  • cloudflare-kv-legacy-routes — Cloudflare Workers KV legacy namespace routes -> storage/kv routes (upstream reference)
  • cloudflare-secrets-store-and-ai-security-path-renames — Cloudflare REST API: legacy /system secrets-store alias removed and firewall-for-ai renamed to ai-security (OAS 2026-07-27) (upstream reference)
  • cloudflare-typescript-v7-deterministic-renames — cloudflare-typescript v7.0.0: Id->ID method renames, DEXTest type renames, import-path moves, fileFromPath removal (upstream reference)
  • cloudflare-typescript-v7-named-path-params — cloudflare-typescript v7.0.0: intermediate path parameters move into the options object (named path parameters) (upstream reference)
  • cloudflare-account-roles-to-permission-groups — Cloudflare Account Roles API -> Permission Groups API (URL move + meta.label read remap) (upstream reference)
  • cloudflare-workers-ai-model-slug-renames — Cloudflare Workers AI: omni-/ray- prefixed model slugs removed — rename to canonical successors (upstream reference)

Recent Cloudflare releases adjudicated non-breaking

Not paging you is the other half of the job. The same pipeline that produced the timeline above also cleared 51 Cloudflare changes as additive or fix-only — releases an integrator can upgrade through without a migration. The most recent:

DateReleaseRef
2026-08-10 Turnstile - Turnstile Spin is now generally available
fix
source
2026-08-10 Cloudflare One Client - Cloudflare One Client for Windows (version 2026.6.905.0)
additive
source
2026-08-07 Hyperdrive - MySQL support in Hyperdrive is now generally available
additive
source
2026-08-07 Radar - AS-level connectivity and upstream providers on Cloudflare Radar
additive
source
2026-08-07 Cloudflare Mesh, Cloudflare One - Container image for Cloudflare Mesh
additive
source
2026-08-06 Browser Run - Introducing Kitesurf, an agent-first browser on Browser Run
additive
source
2026-08-06 AI Search - AI Search makes it easier to build a search engine for your data
additive
source
2026-08-05 AI Gateway - Track AI spend and catch anomalous usage with User Insights
additive
source

Measured: 136 raw removals, and why only 17 made this page

Two of the corridors feeding the timeline above come from diffing Cloudflare's published OpenAPI schema (api-schemas) directly. The second corridor — 7abe88500e55 (2026-03-31) -> c92b9b0fde23 (2026-07-27) — is the interesting one, because the raw diff is a trap: it reports 136 path removals. Ingest that raw and this page would page you 136 times for one quarter of one provider.

What curation measured. Of those 136 raw removals, 119 were excluded with machine-checked evidence that the surface survives: 107 path-template consolidations (the endpoint moved under a generic parameterized route), 11 parameter renames that are byte-identical at runtime, and 1 method superset. Every exclusion is evidenced against both spec snapshots — 0 exclusions rest on judgment alone — and an audit ledger asserts the arithmetic conserves: 17 kept + 119 excluded = 136. The 17 real removals that survived (“path-removed: /accounts/{account_id}/billing/usage/paygo” among them), plus 14 from the earlier corridor, are the 31 spec-diff entries in the timeline above — all 31 adjudicated code-fixable, each with a token-verified successor analysis.

Why this matters beyond Cloudflare. A schema the size of Cloudflare's moves constantly for reasons that break nobody, and a diff engine that cannot prove which removals are real is just a louder changelog. Combined with the release-feed entries above (adjudicated 38 code-fixable, 10 not, across the full set), the timeline you are reading is what remains after both layers of filtering — which is the point of reading it at all.

Monitoring Cloudflare going forward

This page is regenerated from the change database, which is fed by release feeds, changelog capture and OpenAPI spec diffing — so it does not depend on Cloudflare writing a perfect changelog. mendapi monitors 84125 change records across 20 providers; hosted plans watch your repos continuously and open fix PRs when a change lands. See pricing.

Frequently asked questions

How do I check if my codebase is affected by Cloudflare breaking changes?

Run npx mendapi scan in your repo. It statically matches your files against the 48 Cloudflare breaking changes and deprecations in this tracker and reports file, line and confidence for every hit — locally, in about 30 seconds, with zero network calls.

How many Cloudflare API breaking changes are on record?

This tracker records 48 entries for Cloudflare (45 breaking changes and 3 deprecations, 2025–2026). Each entry is adjudicated: 38 are code-fixable, 10 require a decision no codemod can make.

Are there automated fixes for Cloudflare breaking changes?

Yes — mendapi ships 6 deterministic migration packs for Cloudflare. mendapi fix applies them locally as reviewable diffs; every pack is gold-tested and idempotent.

Does my code get uploaded when scanning for Cloudflare changes?

No. mendapi scan, deps and fix run with zero network code, mechanically enforced by the test suite. Optional hosted reporting is metadata-only, secrets-redacted, and requires an explicit flag.

Related

Every entry on this page is generated from the mendapi change database at build time and links its upstream source.