WHO
Integrators, platform/SRE, and Origin CA automation owners still on Cloudflare Service Key / X-Auth-User-Service-Key; security/infra on cloudflared pre-Nov 2022 or origin-ca-issuer without Token support.
CfSvcKey · Waitlist
Multi-select where you still send X-Auth-User-Service-Key (CI, Terraform, scripts, Origin CA, cloudflared, issuer) and your env (prod / CI). Get a suggested Token permission matrix, swap steps, verify curls, and a pre-Sep-30 revoke checklist. Not the Cloudflare Dashboard — never paste real Service Keys.
Market-validation page · Free waitlist · No fake user counts · Never paste real keys
Problem
Cloudflare deprecated Service Key authentication and will stop it on September 30, 2026. Any script, CI job, Terraform provider, Origin CA flow, or tool still sending X-Auth-User-Service-Key will fail auth. The official replacement is fine-grained API Tokens (Authorization: Bearer), with cloudflared ≥ Nov 2022 and origin-ca-issuer Token support required. Docs say “migrate” — they don’t turn usage surfaces × env into a permission matrix, swap steps, verify curls, and a pre-Sep-30 revoke checklist.
Solution
A Service Key → API Token migration decision-readiness layer for integrators, platform/SRE, and Origin CA owners still on X-Auth-User-Service-Key: usage surfaces × env → suggested Token permission matrix + swap steps + verify curls + pre-Sep-30 revoke checklist — not the Cloudflare Dashboard, and never asking for real Service Keys.
Integrators, platform/SRE, and Origin CA automation owners still on Cloudflare Service Key / X-Auth-User-Service-Key; security/infra on cloudflared pre-Nov 2022 or origin-ca-issuer without Token support.
Service Keys stop working Sep 30, 2026. Official docs require API Tokens but don’t map your surfaces × env to permission groups, verify curls, and a revoke checklist — so one missed CI secret or old cloudflared means production 401s.
Multi-select usage surfaces (CI / Terraform / scripts / Origin CA / cloudflared / issuer) + env (prod / CI) → suggested Token permission matrix, swap steps, verify curls, pre-Sep-30 revoke checklist + waitlist. MVP never asks for real Service Keys.
Align where you still use Service Keys → what Token to build → how to verify → when to revoke — before Sep 30 kills auth, not after production APIs and signing go 401.
Features
Marketing points from the product hypothesis — for demand validation, not a formal spec promise.
Multi-select CI secret, Terraform, REST/scripts, Origin CA, cloudflared, origin-ca-issuer → suggested API Token permission groups (with uncertainty flags).
Prod vs CI split: least privilege, expiry hints, whether to split Tokens so one key doesn’t rule them all.
Header swap from X-Auth-User-Service-Key → Authorization: Bearer; local verify curl skeletons with placeholders — never real secrets.
Inventory → create Token → verify → cut over → monitor → revoke old Service Key; call out cloudflared ≥ Nov 2022 and issuer Token support gates.
Form + matrix + steps + curls + checklist + waitlist. Explicitly out: pasting keys, holding secrets, logging into Cloudflare, creating Tokens for you.
How it works
A three-step loop matching the waitlist-stage product hypothesis.
CI / Terraform / scripts / Origin CA / cloudflared / issuer; prod or CI.
Suggested permission groups (with uncertainty flags); prod vs CI split.
Header swap, verify examples, pre-Sep-30 revoke — never paste real keys.
Use cases
If these situations sound familiar, join the waitlist to help us validate.
Need a CI-scoped Token suggestion and verify curl before scheduling revoke.
Need permission matrix + swap steps so apply day doesn’t 401.
Confirm Token path and revoke timing so signing doesn’t die after Sep 30.
Version / support gate checklist first — then permissions.
One-page inventory → matrix → verify → revoke instead of emergency wiki meetings.
Public signals
Public Cloudflare documentation only — not customer testimonials or invented metrics.
FAQ
Official docs are the rules. We turn usage surfaces × env into a permission matrix, swap steps, verify curls, and a revoke checklist.
The Dashboard creates Tokens but doesn’t inventory where you still send Service Keys. We are a decision-readiness layer — we never log into your account.
Those are hand-maintained. We structure the Sep-30 Service Key EOL into a surface mapper.
Scanners find strings. We understand Service Key → API Token migration semantics and permission suggestions.
No. Never ask, never hold, never store secrets.
No. MVP is a static form + matrix + steps + curls + checklist.
Per Cloudflare: cloudflared must be Nov 2022 or newer; origin-ca-issuer must support Tokens.
Static form + permission matrix + swap steps + verify curls + revoke checklist + waitlist. Holding keys and Dashboard automation are out.
Waitlist invites go out in batches by email. No fake launch date.
Assumed small audit or team seat later; formal pricing comes with launch email. Waitlist is free.
Waitlist
Leave your email for CfSvcKey early access and launch notes. Never paste real Service Keys in any field.
We’ll email early-access invites and launch updates in batches. Check your inbox for a confirmation if enabled. Unsubscribe anytime.