logo

HTTPS-only for Cloudflare APIs: shutting the door on cleartext traffic

ID: b60b8dbc-de30-5f6a-be73-b0ecc7710575

STIX ID: report--b60b8dbc-de30-5f6a-be73-b0ecc7710575

Feed Name: Cloudflare Blog

Date Published: 2025-03-20

Date Updated: 2026-04-27

Author: Suleman Ahmad

...
...

Cloudflare announces it is enforcing HTTPS-only for api.cloudflare.com by closing all plaintext HTTP ports at the transport layer to prevent credential exposure, introducing DNS/IP agility and a move away from static IPs, and planning to deprecate non-SNI clients; the company will offer customers an opt-in feature to disable HTTP on their own domains by late 2025, supported by analytics and rollout tooling (Tubular, Topaz, iptables) for safe, scalable deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.