Give every teammate and agent the right level of access to your Workers
- ID
- 24650
- Status
- summarized
- Published
- 15 Sep 2026, 9:00 PM
- Fetched
- 15 Sep 2026, 10:29 PM
- Provider
- Cloudflare Blog
- Category
- infrastructure
- Original URL
- https://blog.cloudflare.com/workers-granular-authorization/
- Source URL
- https://blog.cloudflare.com/rss/
Summary
- Score
- 7.0
- Created
- 15 Sep 2026, 10:30 PM
- Tags
- Audience
- developersvibe_codersai_agent_users
What happened
Cloudflare introduced per-Worker access scoping with four new roles — Metadata Read-Only, Content Read-Only, Editor, and Admin — allowing teams to restrict a teammate or AI agent to a single Worker rather than the entire account. The roles are available to all customers today and can be applied via dashboard login or scoped API tokens.
Why it matters
If you run AI agents or CI/CD against Cloudflare Workers, you should stop using account-wide API tokens and switch to per-Worker scoped tokens with the least-privileged role — especially Editor (not Admin) for deploy-only agents, or Metadata Read-Only for debugging agents — to prevent accidental production deletions or cross-Worker changes.
Discussion angle
How to map these four roles to common agent workflows — e.g., a coding agent gets Editor on one Worker, an observability agent gets Metadata Read-Only — and whether per-Worker scoping is granular enough for real production setups.