Get the latest tech news

The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch


Do you register with Google, Amazon or Microsoft to use the web?

Authentication for that world isn’t “ask Cloudflare for a hall pass.” It’s verifiable chains of delegation and request-level proof: open, portable, and independent of any one company. That would let a service authenticate a third party simply by checking DNS (without anyone filling forms, asking permission, or registering with a central directory). We now have tools that allow us to issue tokens with constraints: granular, short-lived, and delegable (like macaroons or biscuits) and Open policy engines (like OPA or AWS Cedar) can also be used for RBAC/ABAC for this use case.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Web

Web

Photo of Gatekeepers

Gatekeepers

Photo of Cloudflare

Cloudflare

Related news:

News photo

BBC reveals web of spammers profiting from AI Holocaust images

News photo

AWS, Cloudflare, Digital Ocean, and Google helped Feds investigate alleged Rapper Bot DDoS perp

News photo

Cloudflare incident on August 21, 2025