Key details

  1. Removed route operations are the CIDR-encoded create, update and delete paths under `/teamnet/routes/network/{ip_network_encoded}`.
  2. Replacement route operations use `/teamnet/routes` for creation and `/teamnet/routes/{route_id}` for update and delete.
  3. Tunnel and Mesh list/get responses no longer include the `connections` array.
  4. Connection details remain available through dedicated `/connections` endpoints.
  5. Cloudflare advises direct API users to capture route IDs, update scripts and CI/CD, and upgrade `cloudflared` if using its tunnel route commands.

What builders should take away

  1. Search direct Cloudflare API integrations for `/teamnet/routes/network/` and migrate them to route-ID operations.
  2. Check monitoring and inventory code for assumptions that `connections` is present on Tunnel or Mesh objects.
  3. If route automation uses `cloudflared tunnel route ip`, upgrade `cloudflared`; if it uses Terraform, keep the Cloudflare provider and route resource current.

What changed

On October 5, 2026, Cloudflare removes three CIDR-encoded Zero Trust Networks route endpoints and removes the `connections` array from Cloudflare Tunnel and Cloudflare Mesh list/get responses. Route creation now sends the network and tunnel ID in the request body; updates and deletes identify routes by `route_id`. Connection details move to dedicated per-tunnel or per-Mesh-node connections endpoints.

Why it matters

This is an API-shape break rather than a cosmetic deprecation. Builders with scripts, backend services or CI/CD that directly call the old CIDR route paths need to migrate, and dashboards or monitoring code that parses connection state from tunnel objects need an extra API call. Cloudflare says current `cloudflared` and Terraform users are insulated from the connections-field change, but direct consumers are not.

Route identity moves from the CIDR to a resource ID

The old API encoded the network directly into the request path. The replacement treats the route as a normal resource: create it with the network and tunnel ID in the body, retain its `route_id`, then use that ID for later updates or deletion. Automation that constructed URLs from CIDRs therefore needs more than a path rename.

Connection state becomes an explicit second lookup

Cloudflare is also shrinking Tunnel and Mesh list/get responses by removing their embedded `connections` arrays. Code that uses those responses for connector health, dashboards or inventory must query the dedicated connections endpoint when it needs that detail. Cloudflare says `cloudflared` and its Terraform provider do not depend on the removed field.

What to watch next

  • Post-cutoff reports of broken custom Tunnel or Zero Trust automation.
  • Whether Cloudflare publishes additional compatibility or migration guidance after the removal.

Still unclear

  • Cloudflare's changelog documents the October 5 removal but does not quantify how many direct API consumers still use the deprecated shapes.
  • The documentation describes the migration contract; it does not provide independent post-cutoff breakage data.

Sources

Direct reading behind this dossier.

1 sources

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment