[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$flcq7vfa1b48g":3,"$fanuq43nlrv5g":54},{"slug":4,"title":5,"body":6,"summary":7,"tags":8,"author":14,"cover_url":15,"published_at":16,"seo_title":17,"seo_description":18,"reading_minutes":19,"related":20},"cloudflare-access-strict-service-token-auth-migration","Strict service token auth in Cloudflare Access: moving your scripts and CI over before it bites","\u003Cp>On 2 October Cloudflare published a changelog entry for a new Zero Trust setting, \u003Cstrong>strict service token authentication\u003C\u002Fstrong>. If your scripts, cron jobs or CI runners reach an Access-protected app with a service token, this setting changes how failures look and which policies apply. Organizations created on or after 5 October 2026 get it switched on and cannot turn it off. Existing organizations can choose when to switch it on.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac4a8eb0956594c947bd1e4\">\u003Cvideo src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac4a8ec0956594c947bd1eb-0-eb3a6301.mp4\" autoplay muted loop playsinline preload=\"metadata\">\u003C\u002Fvideo>\u003C\u002Ffigure>\u003Cp>This guide shows what changes, how to find the callers that will break, and how to switch it on and check the result. It takes about 15 minutes for a small account. Everything below comes from Cloudflare's changelog and service-token docs. We have not run our own benchmarks here.\u003C\u002Fp>\u003Ch2>What strict mode changes\u003C\u002Fh2>\u003Cp>The docs list three behaviour changes:\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac4a8870956594c947bd19d\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac4a8870956594c947bd1a2-0-44b02dde.png\" alt=\"Strict mode replaces redirects with explicit error codes.\" loading=\"lazy\">\u003Cfigcaption>Strict mode replaces redirects with explicit error codes.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\u003Cul>\u003Cli>\u003Cstrong>Failures are explicit.\u003C\u002Fstrong> If authentication or authorization fails, Access always returns \u003Ccode>401\u003C\u002Fcode> or \u003Ccode>403\u003C\u002Fcode> instead of redirecting the client to the login page with a \u003Ccode>302\u003C\u002Fcode>.\u003C\u002Fli>\u003Cli>\u003Cstrong>Only Service Auth policies count.\u003C\u002Fstrong> Only policies with the \u003Cem>Service Auth\u003C\u002Fem> action can authorize the request. Access ignores \u003Cem>Allow\u003C\u002Fem> policies and any \u003Ccode>CF_Authorization\u003C\u002Fcode> cookie sent with the request.\u003C\u002Fli>\u003Cli>\u003Cstrong>No cookie on success.\u003C\u002Fstrong> Access does not return a \u003Ccode>CF_Authorization\u003C\u002Fcode> cookie to the client after it authenticates successfully.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Cloudflare also says that failed requests for recognised service tokens show up in the Access authentication logs, including expired tokens, disabled tokens and wrong client secrets.\u003C\u002Fp>\u003Cp>The first change is the one that helps. Without strict mode, a script with a bad token often gets a \u003Ccode>302\u003C\u002Fcode> to an HTML login page. If the script follows redirects, it then gets a \u003Ccode>200\u003C\u002Fcode> for the login page, and only fails later when it tries to parse that page as JSON. With strict mode it gets a clean \u003Ccode>401\u003C\u002Fcode> or \u003Ccode>403\u003C\u002Fcode> on the first request.\u003C\u002Fp>\u003Ch2>Who breaks\u003C\u002Fh2>\u003Cp>Three patterns stop working when you turn strict mode on:\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac4a8870956594c947bd1a7\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac4a8870956594c947bd1ac-0-8229befb.png\" alt=\"Ensure your CI runners and scripts are configured for the new authentication flow.\" loading=\"lazy\">\u003Cfigcaption>Ensure your CI runners and scripts are configured for the new authentication flow.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\u003Col>\u003Cli>\u003Cstrong>Service tokens matched by an Allow policy.\u003C\u002Fstrong> If a policy includes a service token rule but its action is \u003Cem>Allow\u003C\u002Fem>, the token no longer authorizes anything. The policy action has to be \u003Cem>Service Auth\u003C\u002Fem>.\u003C\u002Fli>\u003Cli>\u003Cstrong>Clients that send the headers once and then rely on the cookie.\u003C\u002Fstrong> Some scripts authenticate on the first call, save cookies with a cookie jar, and drop the headers on later calls. With no cookie issued (and any cookie ignored), every request after the first gets a \u003Ccode>401\u003C\u002Fcode> or \u003Ccode>403\u003C\u002Fcode>.\u003C\u002Fli>\u003Cli>\u003Cstrong>Anything that expects the redirect.\u003C\u002Fstrong> Health checks or wrappers that treat \u003Ccode>302\u003C\u002Fcode> as \"not logged in\" and branch on it will see a different status code.\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>Step 1: find Allow policies that contain service tokens\u003C\u002Fh2>\u003Cp>In the dashboard, open each Access application that machines call and check its policies. Any policy that includes a service token (or \"any valid service token\") should have the \u003Cem>Service Auth\u003C\u002Fem> action. In the API, the Service Auth action appears as \u003Ccode>\"decision\": \"non_identity\"\u003C\u002Fcode>.\u003C\u002Fp>\u003Cp>To check reusable policies from the command line, use an API token with Access read permissions:\u003C\u002Fp>\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">\u003Cspan class=\"hljs-built_in\">export\u003C\u002Fspan> ACCOUNT_ID=\u003Cspan class=\"hljs-string\">&quot;your-account-id&quot;\u003C\u002Fspan>\n\u003Cspan class=\"hljs-built_in\">export\u003C\u002Fspan> CLOUDFLARE_API_TOKEN=\u003Cspan class=\"hljs-string\">&quot;your-api-token&quot;\u003C\u002Fspan>\n\ncurl -s \u003Cspan class=\"hljs-string\">&quot;https:\u002F\u002Fapi.cloudflare.com\u002Fclient\u002Fv4\u002Faccounts\u002F\u003Cspan class=\"hljs-variable\">$ACCOUNT_ID\u003C\u002Fspan>\u002Faccess\u002Fpolicies&quot;\u003C\u002Fspan> \\\n  --header \u003Cspan class=\"hljs-string\">&quot;Authorization: Bearer \u003Cspan class=\"hljs-variable\">$CLOUDFLARE_API_TOKEN\u003C\u002Fspan>&quot;\u003C\u002Fspan> \\\n  | jq \u003Cspan class=\"hljs-string\">&#x27;.result[]\n        | select(.decision == &quot;allow&quot;)\n        | select([.include[]? | has(&quot;service_token&quot;) or has(&quot;any_valid_service_token&quot;)] | any)\n        | {id, name, decision}&#x27;\u003C\u002Fspan>\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp>Every policy this prints is a policy that strict mode will ignore for your tokens. Change its action to Service Auth in the dashboard, or split it into two policies: one Allow policy for people and one Service Auth policy for tokens. Policies attached directly to a single application are listed under that application in the dashboard. Check those too.\u003C\u002Fp>\u003Ch2>Step 2: make every caller send both headers on every request\u003C\u002Fh2>\u003Cp>A service token is two headers. Per the docs:\u003C\u002Fp>\u003Cpre class=\"code-block\" data-lang=\"http\">\u003Ccode class=\"hljs language-http\">\u003Cspan class=\"hljs-attribute\">CF-Access-Client-Id\u003C\u002Fspan>\u003Cspan class=\"hljs-punctuation\">: \u003C\u002Fspan>&lt;CLIENT_ID&gt;\n\u003Cspan class=\"hljs-attribute\">CF-Access-Client-Secret\u003C\u002Fspan>\u003Cspan class=\"hljs-punctuation\">: \u003C\u002Fspan>&lt;CLIENT_SECRET&gt;\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp>The docs also describe a single-header form for clients that can only set \u003Ccode>Authorization\u003C\u002Fcode>:\u003C\u002Fp>\u003Cpre class=\"code-block\" data-lang=\"http\">\u003Ccode class=\"hljs language-http\">\u003Cspan class=\"hljs-attribute\">Authorization\u003C\u002Fspan>\u003Cspan class=\"hljs-punctuation\">: \u003C\u002Fspan>{&quot;cf-access-client-id&quot;: &quot;&lt;CLIENT_ID&gt;&quot;, &quot;cf-access-client-secret&quot;: &quot;&lt;CLIENT_SECRET&gt;&quot;}\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp>Search your repos and CI config for cookie jars and saved sessions next to Access hostnames, for example \u003Ccode>curl -c\u003C\u002Fcode>\u002F\u003Ccode>-b\u003C\u002Fcode>, \u003Ccode>requests.Session()\u003C\u002Fcode> that only sets the headers on login, or a stored \u003Ccode>CF_Authorization\u003C\u002Fcode> value. Change them so the two headers go on every request.\u003C\u002Fp>\u003Cp>Before you flip the setting, run this check against each protected endpoint. It does not follow redirects, so a \u003Ccode>302\u003C\u002Fcode> stays visible:\u003C\u002Fp>\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">\u003Cspan class=\"hljs-meta\">#!\u002Fusr\u002Fbin\u002Fenv bash\u003C\u002Fspan>\n\u003Cspan class=\"hljs-comment\"># check-access.sh: call an Access-protected URL with a service token, no redirects.\u003C\u002Fspan>\n\u003Cspan class=\"hljs-built_in\">set\u003C\u002Fspan> -euo pipefail\n\nURL=\u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">${1:?usage: check-access.sh https:\u002F\u002Fapp.example.com\u002Fapi\u002Fhealth}\u003C\u002Fspan>&quot;\u003C\u002Fspan>\n\ncurl -s -o \u002Fdev\u002Fnull \\\n  -w \u003Cspan class=\"hljs-string\">&quot;status=%{http_code} redirect=%{redirect_url}\\n&quot;\u003C\u002Fspan> \\\n  --header \u003Cspan class=\"hljs-string\">&quot;CF-Access-Client-Id: \u003Cspan class=\"hljs-variable\">$CF_ACCESS_CLIENT_ID\u003C\u002Fspan>&quot;\u003C\u002Fspan> \\\n  --header \u003Cspan class=\"hljs-string\">&quot;CF-Access-Client-Secret: \u003Cspan class=\"hljs-variable\">$CF_ACCESS_CLIENT_SECRET\u003C\u002Fspan>&quot;\u003C\u002Fspan> \\\n  \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$URL\u003C\u002Fspan>&quot;\u003C\u002Fspan>\u003C\u002Fcode>\u003C\u002Fpre>\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">\u003Cspan class=\"hljs-built_in\">export\u003C\u002Fspan> CF_ACCESS_CLIENT_ID=\u003Cspan class=\"hljs-string\">&quot;xxxx.access&quot;\u003C\u002Fspan>\n\u003Cspan class=\"hljs-built_in\">export\u003C\u002Fspan> CF_ACCESS_CLIENT_SECRET=\u003Cspan class=\"hljs-string\">&quot;xxxx&quot;\u003C\u002Fspan>\nbash check-access.sh https:\u002F\u002Fapp.example.com\u002Fapi\u002Fhealth\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp>You want \u003Ccode>status=200\u003C\u002Fcode> (or whatever your origin normally returns) with an empty redirect. A \u003Ccode>302\u003C\u002Fcode> to a login page before the switch means the token is not being matched by any policy that admits it.\u003C\u002Fp>\u003Ch2>Step 3: switch it on\u003C\u002Fh2>\u003Cp>In the dashboard: \u003Cstrong>Zero Trust\u003C\u002Fstrong> &gt; \u003Cstrong>Access controls\u003C\u002Fstrong> &gt; \u003Cstrong>Access settings\u003C\u002Fstrong>, then under \u003Cem>Manage service tokens\u003C\u002Fem> turn on \u003Cstrong>Strict service token authentication\u003C\u002Fstrong> and confirm.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac4a8870956594c947bd1b1\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac4a8870956594c947bd1b6-0-3d819d31.png\" alt=\"Activating strict service token authentication in the dashboard.\" loading=\"lazy\">\u003Cfigcaption>Activating strict service token authentication in the dashboard.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\u003Cp>Or with the API, as given in the changelog:\u003C\u002Fp>\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">curl \u003Cspan class=\"hljs-string\">&quot;https:\u002F\u002Fapi.cloudflare.com\u002Fclient\u002Fv4\u002Faccounts\u002F\u003Cspan class=\"hljs-variable\">$ACCOUNT_ID\u003C\u002Fspan>\u002Faccess\u002Forganizations&quot;\u003C\u002Fspan> \\\n  --request PATCH \\\n  --header \u003Cspan class=\"hljs-string\">&quot;Authorization: Bearer \u003Cspan class=\"hljs-variable\">$CLOUDFLARE_API_TOKEN\u003C\u002Fspan>&quot;\u003C\u002Fspan> \\\n  --json \u003Cspan class=\"hljs-string\">&#x27;{&quot;strict_service_token_auth&quot;: true}&#x27;\u003C\u002Fspan>\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp>To roll back on an existing organization, send the same request with \u003Ccode>false\u003C\u002Fcode>. Organizations created on or after 5 October 2026 cannot roll back, so any new account you set up for a client or a side project starts in strict mode.\u003C\u002Fp>\u003Ch2>Step 4: rerun the checks and read the logs\u003C\u002Fh2>\u003Cp>Run \u003Ccode>check-access.sh\u003C\u002Fcode> again for each endpoint, then run your real jobs once. Expected results:\u003C\u002Fp>\u003Cul>\u003Cli>\u003Ccode>200\u003C\u002Fcode>: the token matched a Service Auth policy. Done.\u003C\u002Fli>\u003Cli>\u003Ccode>401\u003C\u002Fcode>: the token is missing, expired, disabled, or has a wrong secret.\u003C\u002Fli>\u003Cli>\u003Ccode>403\u003C\u002Fcode>: the token is valid but no Service Auth policy on that application admits it. This is usually an Allow policy you missed in step 1.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For the failures, open the Access authentication logs in the Zero Trust dashboard. Because recognised tokens now log their failures, you can see which token failed and why. That is quicker than guessing from a \u003Ccode>302\u003C\u002Fcode>.\u003C\u002Fp>\u003Ch2>Things that do not change\u003C\u002Fh2>\u003Cul>\u003Cli>People who sign in through your identity provider still use Allow policies and still get the cookie. Strict mode only changes how service-token requests are handled.\u003C\u002Fli>\u003Cli>Tokens still expire on the schedule you chose when you created them. The docs say the client secret is shown only once, so a lost secret means a new token.\u003C\u002Fli>\u003Cli>Creating tokens works as before: \u003Cstrong>Zero Trust\u003C\u002Fstrong> &gt; \u003Cstrong>Access controls\u003C\u002Fstrong> &gt; \u003Cstrong>Service credentials\u003C\u002Fstrong> &gt; \u003Cstrong>Service Tokens\u003C\u002Fstrong>, or \u003Ccode>POST \u002Faccounts\u002F$ACCOUNT_ID\u002Faccess\u002Fservice_tokens\u003C\u002Fcode> with the \u003Cem>Access: Service Tokens Write\u003C\u002Fem> permission.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>When to do it\u003C\u002Fh2>\u003Cp>If your organization is older than 5 October, nothing forces the switch today. Still, a migration you choose is easier than finding out during an incident that a nightly job has been parsing a login page. Run steps 1 and 2 this week, switch on strict mode during a quiet hour, and keep the PATCH with \u003Ccode>false\u003C\u002Fcode> ready in case you need to roll back.\u003C\u002Fp>\u003Ch2>Sources\u003C\u002Fh2>\u003Cul>\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fchangelog\u002Fpost\u002F2026-10-02-strict-service-token-authentication\u002F\">Cloudflare changelog: Strict service token authentication (2 October 2026)\u003C\u002Fa>\u003C\u002Fli>\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fcloudflare-one\u002Faccess-controls\u002Fservice-credentials\u002Fservice-tokens\u002F\">Cloudflare docs: Service tokens, including strict service token authentication\u003C\u002Fa>\u003C\u002Fli>\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fcloudflare-one\u002Finsights\u002Flogs\u002Fdashboard-logs\u002Faccess-authentication-logs\u002F\">Cloudflare docs: Access authentication logs\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Ful>","Cloudflare Access now has a strict mode for service tokens: 401\u002F403 instead of a 302 to the login page, only Service Auth policies count, and no CF_Authorization cookie. New orgs get it forced on from 5 October. A 15-minute check and switch for existing orgs.",[9,10,11,12,13],"cloudflare","zero-trust","ci-cd","authentication","ai-assisted","if.codes","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac4a8860956594c947bd197-0-f768b25b.png","2026-10-06T08:30:13.154Z","Cloudflare Access strict service token auth: migrate scripts and CI","401\u002F403 instead of 302, Service Auth policies only, no CF_Authorization cookie. Find what breaks, switch it on, read the logs.",5,[21,33,44],{"slug":22,"title":23,"type":24,"summary":25,"tags":26,"author":14,"cover_url":30,"published_at":31,"updated_at":32},"cloudflare-traces-trace-rules-debug-one-customer","Why was that request blocked? Tracing one customer at 100% with Cloudflare Traces and Trace Rules","blog","Cloudflare Traces (open beta) shows a request's path through WAF rules, transforms, cache, Workers and origin as one trace. A recipe: low baseline sampling, a 100% Trace Rule for one host or debug header, traceparent to your origin, OTLP export to your own collector, and what December pricing means.",[9,27,28,29,13],"observability","opentelemetry","tracing","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac338052cb6b40613ac2b7c-0-2294d114.png","2026-10-05T06:22:19.055Z","2026-10-05T06:22:19.056Z",{"slug":34,"title":35,"type":24,"summary":36,"tags":37,"author":14,"cover_url":42,"published_at":43,"updated_at":43},"copyescape-cve-2026-17106-patch-docker-cp","CopyEscape (CVE-2026-17106): patch docker cp, and stop copying out of running containers","A race in docker cp lets a malicious container write files anywhere the copying process can write on the host. That matters for CI runners and AI-agent sandboxes that copy results out. Check your versions, patch, and change copy-out jobs to stop the container first.",[38,39,40,41,13],"docker","security","cve","ci","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218ebfd770659725abe68-0-eee7c8f7.png","2026-10-04T23:51:14.689Z",{"slug":45,"title":46,"type":24,"summary":47,"tags":48,"author":14,"cover_url":51,"published_at":52,"updated_at":53},"protected-quick-tunnels-vs-tailscale-funnel","Share localhost with three named people: Cloudflare's Protected Quick Tunnels vs Tailscale Funnel","cloudflared 2026.9.3 adds --allowed-mail: your quick tunnel now sits behind an email one-time PIN, checked against an allow-list on your own machine, free and without a Cloudflare account. The commands, what it protects, and when Tailscale Serve or Funnel is the better fit.",[9,49,50,39,13],"tailscale","tunnels","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218d8fd770659725abe3a-0-40f8cb2e.png","2026-10-04T23:19:14.764Z","2026-10-04T23:19:14.765Z",[55,58,61,63,66,79,93,105,117,128,139,148,160,171,180,191,201,210,220],{"slug":4,"title":5,"type":24,"summary":7,"tags":56,"author":14,"cover_url":15,"published_at":16,"updated_at":57,"reading_minutes":19},[9,10,11,12,13],"2026-10-06T08:30:13.155Z",{"slug":22,"title":23,"type":24,"summary":25,"tags":59,"author":14,"cover_url":30,"published_at":31,"updated_at":32,"reading_minutes":60},[9,27,28,29,13],6,{"slug":34,"title":35,"type":24,"summary":36,"tags":62,"author":14,"cover_url":42,"published_at":43,"updated_at":43,"reading_minutes":19},[38,39,40,41,13],{"slug":45,"title":46,"type":24,"summary":47,"tags":64,"author":14,"cover_url":51,"published_at":52,"updated_at":53,"reading_minutes":65},[9,49,50,39,13],4,{"slug":67,"title":68,"type":24,"summary":69,"tags":70,"author":14,"cover_url":76,"published_at":77,"updated_at":78,"reading_minutes":60},"si-domains-super-intelligence-data",".si after 'Super Intelligence': did one UN speech move a ccTLD?","Trump renamed AI 'super intelligence' at the UN on 22 September 2026 and Slovenia's .si went from about 190,000 names to almost 276,000 in a month. Registry numbers, prices, and 87 WHOIS checks: the obvious AI names were gone years ago; the compounds went in days.",[71,72,73,74,75,13],"domains","si","tld","data","ai","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaee53e21d5cbd14d442d-0-d6243bc5.png","2026-10-04T22:36:14.598Z","2026-10-04T22:36:14.599Z",{"slug":80,"title":81,"type":24,"summary":82,"tags":83,"author":14,"cover_url":89,"published_at":90,"updated_at":91,"reading_minutes":92},"palantir-agent-stack-python","Steal Palantir's agent stack: typed tools, one LLM gateway, swappable models","An X thread boils Palantir's AIP docs down to four agent patterns. We check each one against the docs, then build them in one stdlib-only Python file: typed business-object tools, a gateway that masks PII, caches and retries, a model set in config, and schedule\u002Fevent\u002FAPI triggers.",[84,85,86,87,88,13],"ai-agents","llm","python","architecture","palantir","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88f9c951ea7137fa3872-0-48eb7eee.png","2026-10-01T23:05:10.531Z","2026-10-01T23:05:10.532Z",10,{"slug":94,"title":95,"type":24,"summary":96,"tags":97,"author":14,"cover_url":101,"published_at":102,"updated_at":103,"reading_minutes":104},"claude-code-effort-levels","Effort levels in Claude Code: when max effort pays off and when it just burns tokens","Anthropic's effort deep dive (Terminal-Bench 3.0 plus three builds) shows higher effort mostly buys verification and edge-case testing, not smarter code. A rule of thumb per task type, the commands to set effort, and a script to measure cost vs pass rate on your own repo.",[98,99,85,100,13],"claude-code","ai-coding","developer-tools","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88edc951ea7137fa3804-0-2716005a.png","2026-10-01T22:32:14.139Z","2026-10-02T04:44:58.001Z",9,{"slug":106,"title":107,"type":24,"summary":108,"tags":109,"author":14,"cover_url":113,"published_at":114,"updated_at":115,"reading_minutes":116},"agentic-inbox-cloudflare-setup","Self-host an AI email agent on Cloudflare Workers: agentic-inbox set up and costed","Cloudflare's open-source agentic-inbox runs a full email client on Workers, with one SQLite Durable Object per mailbox and a Kimi K2.5 agent that drafts replies. Covers the post-deploy steps people miss (Access, sending, routing, mailbox first) and the cost.",[9,110,84,111,112,13],"workers","email","self-hosting","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88dac951ea7137fa378b-0-5b0ec96d.png","2026-10-01T08:17:18.646Z","2026-10-05T05:56:11.919Z",8,{"slug":118,"title":119,"type":24,"summary":120,"tags":121,"author":14,"cover_url":125,"published_at":126,"updated_at":127,"reading_minutes":116},"audit-ai-agent-public-traces","Nearly a million leaked links: auditing what your AI agents leave on the public web","OpenAI's agent swarm left almost a million public shortener URLs holding credentials. Here's a tested shell + gitleaks audit to find the shortlinks, pastes and webhooks your own agents created, scan them for secrets and close the channels.",[39,122,123,124,85,13],"agents","secrets","gitleaks","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaad873e21d5cbd14d4397-0-0f4f51f7.png","2026-10-01T07:43:19.642Z","2026-10-01T08:44:43.041Z",{"slug":129,"title":130,"type":24,"summary":131,"tags":132,"author":14,"cover_url":136,"published_at":137,"updated_at":138,"reading_minutes":116},"mikrotrick-check-patch-mikrotik","MikroTrick: check and patch your MikroTik in 15 minutes","Two chained RouterOS bugs give anyone who can reach SSH full admin, no password needed, and attacks started before the patch. Find exposed SSH, check the version, grep for the published IoCs, patch and move management behind WireGuard.",[39,133,134,135,112,13],"mikrotik","routeros","ssh","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c0838b650cb96b3d10-0-6cd107e0.png","2026-10-01T07:02:15.03Z","2026-10-01T08:44:41.391Z",{"slug":140,"title":141,"type":24,"summary":142,"tags":143,"author":14,"cover_url":145,"published_at":146,"updated_at":147,"reading_minutes":116},"agent-sandbox-dns-egress-lockdown","Your agent sandbox leaks through DNS: lock down egress in 15 minutes","An OpenAI model escaped its sandbox by tunnelling questions through DNS. Here is a tested Docker Compose setup for coding agents: a DNS allowlist, a logging egress proxy and a kill switch that actually fires.",[39,38,122,144,112,13],"dns","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaca13e21d5cbd14d4306-0-cb93fe1b.png","2026-10-01T03:00:15.943Z","2026-10-01T08:44:43.165Z",{"slug":149,"title":150,"type":24,"summary":151,"tags":152,"author":14,"cover_url":156,"published_at":157,"updated_at":158,"reading_minutes":159},"who-blocks-ai-crawlers-robots-txt","Who blocks AI crawlers? robots.txt vs the network edge, with numbers","I scanned robots.txt on the top 300 sites: 33 of 138 block GPTBot, 14 block training but allow AI search. What each AI bot directive controls, why robots.txt is only a request, and a copy-paste policy plus nginx rule for small SaaS sites.",[75,153,154,9,155,13],"robots-txt","seo","saas","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c1838b650cb96b3d1b-0-11f94198.png","2026-09-30T21:00:20.673Z","2026-10-01T20:47:34.092Z",7,{"slug":161,"title":162,"type":24,"summary":163,"tags":164,"author":14,"cover_url":168,"published_at":169,"updated_at":170,"reading_minutes":65},"bullet-time-with-first-last-frame-video","Bullet time with first\u002Flast-frame video: orbiting a frozen moment from three stills","A freeze-frame camera orbit built from generated stills: one action shot, two camera-move angles, two first\u002Flast-frame clips between them, stitched and ping-ponged. The pipeline, the seams, and where the model re-imagines the water.",[75,165,166,167],"comfyui","video-generation","flowdsl","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abae46c45201648bfd477a7-0-6f4d036e.png","2026-09-28T22:42:41Z","2026-09-28T22:42:41.6Z",{"slug":172,"title":173,"type":24,"summary":174,"tags":175,"author":14,"cover_url":177,"published_at":178,"updated_at":179,"reading_minutes":159},"an-ai-media-pipeline-that-shows-its-work","An AI media pipeline that shows its work: ComfyUI presets, FlowDSL routing and the misses","How the images on my sites are generated: four ComfyUI presets behind one Go module, job rows as state, FlowDSL flows for routing, per-post media in the admin — and the bugs and model misses I hit shipping it. This post's own images were made the same way.",[75,167,165,176],"image-generation","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6aba8ba317ceba3543925be4-0-2f6b8a5c.png","2026-09-28T15:57:50Z","2026-10-01T20:47:34.327Z",{"slug":181,"title":182,"type":24,"summary":183,"tags":184,"author":14,"cover_url":187,"published_at":188,"updated_at":189,"reading_minutes":190},"openai-embeddings-python-mongodb","Transforming Text into Vectors: OpenAI Embeddings in Python","Learn how to generate text embeddings with the OpenAI API in Python to power semantic search, recommendations, and more. Includes practical examples with MongoDB integration and cost analysis.",[185,75,86,186],"openai","mongodb","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c2d-0-2e60b732.png","2024-11-23T00:00:00Z","2026-09-28T22:31:01.385Z",3,{"slug":192,"title":193,"type":24,"summary":194,"tags":195,"author":14,"cover_url":197,"published_at":198,"updated_at":199,"reading_minutes":200},"check-pricing-availability-ing-domains","Last Chance to Grab Short .ING Domains: The Extended List Part II","Welcome back to the second part of our exciting exploration into the .ING domain zone! This time, I've expanded our horizons to bring you an even larger selection of .ING domain names. List of over 24,000 domain names inside.",[71,196],"business","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c38-0-c55f4c8d.png","2023-12-14T00:00:00Z","2026-09-28T22:31:01.453Z",1,{"slug":202,"title":203,"type":24,"summary":204,"tags":205,"author":14,"cover_url":206,"published_at":207,"updated_at":208,"reading_minutes":209},"impressive-ing-domains","Unveiling the Impressive .ING Domains","Discover the vast potential of the new .ING domain zone in my latest blog post! I've used AI and a Python script to unearth a treasure trove of available domain names. From budget-friendly picks to exclusive premium domains, there's something for every ambition. Plus, a special list of unique, lesser-known domains awaits.",[71,196],"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c43-0-03be24b7.png","2023-12-11T00:00:00Z","2026-09-28T22:31:01.527Z",2,{"slug":211,"title":212,"type":24,"summary":213,"tags":214,"author":14,"cover_url":217,"published_at":218,"updated_at":219,"reading_minutes":190},"secured-web-server-in-5-minutes","Fortify Web Server Security in 5 Minutes with Tailscale","Tailscale revolutionizes secure networking with its user-friendly approach, effortlessly connecting devices across diverse networks.",[215,49,216],"firewall","webserver","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c4e-0-eae6f62d.png","2023-11-03T00:00:00Z","2026-09-28T22:31:01.597Z",{"slug":221,"title":222,"type":24,"summary":223,"tags":224,"author":14,"cover_url":227,"published_at":228,"updated_at":229,"reading_minutes":60},"lets-encrypt-free-ssl","How to Secure Your Website with Free SSL Certificates for a Lifetime","Let’s Encrypt certificates have revolutionized internet security by providing free, automated, and widely trusted SSL\u002FTLS certificates. The non-profit Certificate Authority (CA) has significantly contributed to a more secure web environment by simplifying the process of securing websites with HTTPS.",[225,226,216],"ssl","https","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c59-0-bf2a9a0a.png","2023-11-01T00:00:00Z","2026-09-28T22:39:13.555Z"]