Cloudflare introduced Application Profiles on September 29, 2026. The system observes paths, query parameters, headers, cookies, and request bodies to learn an application’s usual HTTP structure. It can then mark requests whose format differs from that profile. The approach looks at whether input fits an expected shape, including field types and allowed values. Source

Detection and enforcement

A request that fails validation gains metadata for security analysis. The detection alone does not block the request. An operator can review past traffic in Security Analytics and create a separate Security Rule if blocking is appropriate. Requests for operations without a learned profile are outside this classification, so the coverage depends on the paths the system has observed. Source

Who has access

Cloudflare says the closed beta is open to invited Enterprise customers who do not have API Security, while customers with API Security already have access. The announcement therefore describes a limited availability feature rather than a setting automatically enabled for every account. Administrators considering it should check their product access and the profiled routes. Source