Least‑Privilege Scopes and Expiration Enforcement in Cloudflare API Tokens
0 reputation · 21 Jan 2021, 23:16 UTC
Uncertain Expiration Handling
Cloudflare’s API Tokens allow a developer to assign fine‑grained scopes and an explicit expiration date. The documentation states that once the expiration date passes, any request using that token should be rejected with a 401 Unauthorized response.
In practice, however, some zone‑level endpoints appear to accept requests with an expired token, returning successful responses. This discrepancy raises concerns about privilege retention and the reliability of the least‑privilege model.
The goal is to determine whether the documented behavior is consistently enforced across all endpoint categories and token scopes, and to identify any exceptions that may exist.
Key questions remain:
- Will Cloudflare return a 401 Unauthorized for all API endpoints when a token has expired?
- Are there specific endpoints or scopes that still accept expired tokens?
- What verification steps can reliably confirm expiration enforcement for any given token?