CfSvcKey · Waitlist

Map your Cloudflare Service Key surfaces to API Tokens — before Sep 30 kills auth

Multi-select where you still send X-Auth-User-Service-Key (CI, Terraform, scripts, Origin CA, cloudflared, issuer) and your env (prod / CI). Get a suggested Token permission matrix, swap steps, verify curls, and a pre-Sep-30 revoke checklist. Not the Cloudflare Dashboard — never paste real Service Keys.

Market-validation page · Free waitlist · No fake user counts · Never paste real keys

Problem

September 30, 2026 deadline

Cloudflare deprecated Service Key authentication and will stop it on September 30, 2026. Any script, CI job, Terraform provider, Origin CA flow, or tool still sending X-Auth-User-Service-Key will fail auth. The official replacement is fine-grained API Tokens (Authorization: Bearer), with cloudflared ≥ Nov 2022 and origin-ca-issuer Token support required. Docs say “migrate” — they don’t turn usage surfaces × env into a permission matrix, swap steps, verify curls, and a pre-Sep-30 revoke checklist.

Before

  • Read Changelog / trial Token in Dashboard
  • Unclear which scopes CI/Terraform/Origin CA need
  • Miss old cloudflared/issuer or forget revoke

After

  • Surfaces × env → permission matrix + swap steps
  • Suggested permission groups per surface
  • Version gates + verify curls + revoke checklist

Join Waitlist

Solution

What CfSvcKey does

A Service Key → API Token migration decision-readiness layer for integrators, platform/SRE, and Origin CA owners still on X-Auth-User-Service-Key: usage surfaces × env → suggested Token permission matrix + swap steps + verify curls + pre-Sep-30 revoke checklist — not the Cloudflare Dashboard, and never asking for real Service Keys.

WHO

Integrators, platform/SRE, and Origin CA automation owners still on Cloudflare Service Key / X-Auth-User-Service-Key; security/infra on cloudflared pre-Nov 2022 or origin-ca-issuer without Token support.

PROBLEM

Service Keys stop working Sep 30, 2026. Official docs require API Tokens but don’t map your surfaces × env to permission groups, verify curls, and a revoke checklist — so one missed CI secret or old cloudflared means production 401s.

SOLUTION

Multi-select usage surfaces (CI / Terraform / scripts / Origin CA / cloudflared / issuer) + env (prod / CI) → suggested Token permission matrix, swap steps, verify curls, pre-Sep-30 revoke checklist + waitlist. MVP never asks for real Service Keys.

RESULT

Align where you still use Service Keys → what Token to build → how to verify → when to revoke — before Sep 30 kills auth, not after production APIs and signing go 401.

Features

Features

Marketing points from the product hypothesis — for demand validation, not a formal spec promise.

🗺️

Usage-surface mapper

Multi-select CI secret, Terraform, REST/scripts, Origin CA, cloudflared, origin-ca-issuer → suggested API Token permission groups (with uncertainty flags).

📊

Env-aware permission matrix

Prod vs CI split: least privilege, expiry hints, whether to split Tokens so one key doesn’t rule them all.

🔁

Swap steps + verify curls

Header swap from X-Auth-User-Service-Key → Authorization: Bearer; local verify curl skeletons with placeholders — never real secrets.

Pre-Sep-30 revoke checklist

Inventory → create Token → verify → cut over → monitor → revoke old Service Key; call out cloudflared ≥ Nov 2022 and issuer Token support gates.

🔒

Static MVP, no secrets

Form + matrix + steps + curls + checklist + waitlist. Explicitly out: pasting keys, holding secrets, logging into Cloudflare, creating Tokens for you.

How it works

How it works

A three-step loop matching the waitlist-stage product hypothesis.

  1. 1

    Multi-select usage surfaces & env

    CI / Terraform / scripts / Origin CA / cloudflared / issuer; prod or CI.

  2. 2

    Get a suggested Token permission matrix

    Suggested permission groups (with uncertainty flags); prod vs CI split.

  3. 3

    Swap steps, verify curls & revoke checklist

    Header swap, verify examples, pre-Sep-30 revoke — never paste real keys.

Join Waitlist

Use cases

Who it’s for

If these situations sound familiar, join the waitlist to help us validate.

CI still stores Service Key as a long-lived secret

Need a CI-scoped Token suggestion and verify curl before scheduling revoke.

Terraform / provider still on the old auth header

Need permission matrix + swap steps so apply day doesn’t 401.

Origin CA automation signing

Confirm Token path and revoke timing so signing doesn’t die after Sep 30.

cloudflared < Nov 2022 or issuer without Token

Version / support gate checklist first — then permissions.

Platform / SRE fire drill days before Sep 30

One-page inventory → matrix → verify → revoke instead of emergency wiki meetings.

FAQ

FAQ

How is CfSvcKey different from Cloudflare Changelog / deprecations?

Official docs are the rules. We turn usage surfaces × env into a permission matrix, swap steps, verify curls, and a revoke checklist.

How is it different from creating a Token in the Dashboard?

The Dashboard creates Tokens but doesn’t inventory where you still send Service Keys. We are a decision-readiness layer — we never log into your account.

How is it different from an internal wiki / Notion?

Those are hand-maintained. We structure the Sep-30 Service Key EOL into a surface mapper.

How is it different from a generic secret scanner?

Scanners find strings. We understand Service Key → API Token migration semantics and permission suggestions.

Will you ask me to paste a real Service Key?

No. Never ask, never hold, never store secrets.

Do you create Tokens or log into Cloudflare for us?

No. MVP is a static form + matrix + steps + curls + checklist.

What’s the cloudflared / origin-ca-issuer bar?

Per Cloudflare: cloudflared must be Nov 2022 or newer; origin-ca-issuer must support Tokens.

What’s in MVP scope?

Static form + permission matrix + swap steps + verify curls + revoke checklist + waitlist. Holding keys and Dashboard automation are out.

When is early access?

Waitlist invites go out in batches by email. No fake launch date.

Pricing?

Assumed small audit or team seat later; formal pricing comes with launch email. Waitlist is free.

Waitlist

Join the waitlist

Leave your email for CfSvcKey early access and launch notes. Never paste real Service Keys in any field.

Used only for waitlist, early access, and launch emails. Never paste real keys. Unsubscribe anytime.