Cloudflare began scanning Authorization headers on 20 August 2026, and the docs did not change
Cloudflare turned on Authorization header scanning for every zone with leaked credentials detection enabled, with no configuration change and no update to the page that documents it since 5 May 2026.