{"id":"cloudflare-access-service-tokens","name":"Cloudflare Access Service Tokens","url":"https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/service-tokens/","category":["auth","zero-trust","security","developer-tooling","cloud-runtime"],"one_liner":"Cloudflare Access machine-to-machine credentials for automated systems, using a Client ID and one-time-visible Client Secret to satisfy Access Service Auth policies on protected applications, with REST APIs for create/li","a_score":40,"band":"unverified","provisional_band":"friction","dimensions":{"access":0,"payment":5,"interface":18,"completion":null,"docs":10},"permission":{"status":"granted","source":"https://developers.cloudflare.com/robots.txt"},"blocker":{"kind":"human-escalation"},"how_to_use":{"interface":"openapi","mcp":null,"openapi":"https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/service_tokens/","base_url":"https://api.cloudflare.com/client/v4/accounts/{account_id}/access","payment":{"model":"free-plan-with-billing-details","currencies":["USD"],"reference_task_cost_usd":0}},"verified":{"verdict":"not-attempted","at":"2026-09-20","human_interventions":0,"transcript_sha":null},"rubric":"sha256:cd605a44799f49951bf078fda63c5b21ad3c07db494f41d38ad19ce729c5551a","last_verified_at":"2026-09-20","audit_url":"/entry/cloudflare-access-service-tokens/audit.json","compact_note":"Public machine card is compacted for FANA scanner compatibility and deployment size. Full source entry and signed audit event body remain in the ag3ntsearch git tree; audit_url publishes hash-chain provenance."}