Cloudflare closed out Agents Week 2026 with a batch of primitives aimed at what it calls Cloud 2.0, or the agentic cloud: infrastructure built for a world where agents are a primary workload rather than a secondary one. The company's CTO Dane Knecht and VP of Product Rita Kozlov framed the week around a capacity problem — if even a fraction of knowledge workers run a few agents in parallel, that implies compute for tens of millions of simultaneous sessions. The one-app-serves-many-users model the cloud was built on was not designed for that. Workers, the containerless, serverless compute platform launched eight years ago, is being positioned as the base layer for it.

Security

Agents reach into private networks, call internal services, and act autonomously on a user's behalf. When anyone in an organization can stand up an agent of their own, the argument goes, security has to be the default rather than something bolted on afterward. Cloudflare's response is a set of launches meant to make that default easy to adopt.

Announcement

Summary

Secure private networking for everyone: users, nodes, agents, Workers — introducing Cloudflare Mesh

Cloudflare Mesh provides secure, private network access for users, nodes, and autonomous AI agents. By integrating with Workers VPC, developers can now grant agents scoped access to private databases and APIs without manual tunnels.

Managed OAuth for Access: make internal apps agent-ready in one click

Managed OAuth for Cloudflare Access helps AI agents securely navigate internal applications. By adopting RFC 9728, agents can authenticate on behalf of users without using insecure service accounts.

Securing non-human identities: automated revocation, OAuth, and scoped permissions

Cloudflare is introducing scannable API tokens, enhanced OAuth visibility, and GA for resource-scoped permissions. These tools help developers implement a true least-privilege architecture while protecting against credential leakage.

Scaling MCP adoption: our reference architecture for enterprise MCP deployments

We share Cloudflare's internal strategy for governing MCP using Access, AI Gateway, and MCP server portals. We also launch Code Mode to slash token costs and recommend new rules for detecting Shadow MCP in Cloudflare Gateway.

BLOG-3239 3

Where agents run

The workloads are not uniform. Some agents need a full operating system to install packages and run terminal commands; most need something lighter that starts in milliseconds and scales to millions. The week's announcements cover both ends of that range plus a Git-compatible workspace for agents, and extend to a path from afternoon prototype to production app. Infrastructure only helps if developers can reach it, so Cloudflare also targeted the terminal, the editor, and the prompt itself, keeping the platform accessible without context-switching.

Toolbox, context and the agentic web

A capable agent has to think and remember, communicate, and see — which means the right models plus the right tools and context for the task. Cloudflare shipped primitives for inference, search, memory, voice, email, and a browser. Separately, agents still browse an Internet built for people, so websites need ways to control what bots can access, package content for agents, and measure readiness for the shift.