What changed
On October 5, 2026, Cloudflare removes three CIDR-encoded Zero Trust Networks route endpoints and removes the `connections` array from Cloudflare Tunnel and Cloudflare Mesh list/get responses. Route creation now sends the network and tunnel ID in the request body; updates and deletes identify routes by `route_id`. Connection details move to dedicated per-tunnel or per-Mesh-node connections endpoints.
Why it matters
This is an API-shape break rather than a cosmetic deprecation. Builders with scripts, backend services or CI/CD that directly call the old CIDR route paths need to migrate, and dashboards or monitoring code that parses connection state from tunnel objects need an extra API call. Cloudflare says current `cloudflared` and Terraform users are insulated from the connections-field change, but direct consumers are not.
Route identity moves from the CIDR to a resource ID
The old API encoded the network directly into the request path. The replacement treats the route as a normal resource: create it with the network and tunnel ID in the body, retain its `route_id`, then use that ID for later updates or deletion. Automation that constructed URLs from CIDRs therefore needs more than a path rename.
Connection state becomes an explicit second lookup
Cloudflare is also shrinking Tunnel and Mesh list/get responses by removing their embedded `connections` arrays. Code that uses those responses for connector health, dashboards or inventory must query the dedicated connections endpoint when it needs that detail. Cloudflare says `cloudflared` and its Terraform provider do not depend on the removed field.