Cloudflare Access Adds Grace Periods for Service Token Rotation

Cloudflare announced a new feature for Cloudflare Access that allows administrators to define a grace period during service token secret rotation. During this window, both the previous and the new secret are accepted, giving teams time to update their integrations without breaking authentication.

The dashboard provides preset grace periods ranging from one hour up to 30 days, and administrators can also revoke the old secret immediately if needed. For API‑driven workflows, the rotation schedule can be customized using an RFC 3339 timestamp.

For detailed steps on configuring token rotation, see the “Rotate service token secrets” documentation.